Patents Assigned to DIGICERT, INC.
  • Publication number: 20260244731
    Abstract: A method is provided for second-factor authentication in API environments that binds API access to a client device's physical location, leveraging authorized Wi-Fi networks as a proximity-based factor. The client device registers a list of Wi-Fi networks and, upon detecting at least one such network, generates an encrypted token. This token includes data such as time-limited nonces and device identifiers, ensuring replay protection and verifiable authenticity. The token is transmitted alongside a first-factor credential (e.g., an API key, OAuth token, or mutual TLS certificate) in an API request to the server. The server validates the token using a cryptographic key to confirm that the client device is indeed at the legitimate physical location. If successful, the request proceeds, potentially allowing sensitive operations such as certificate management by a CA. The method includes preventing Wi-Fi spoofing via local handshakes, updating the network list securely, and maintaining audit logs for compliance.
    Type: Application
    Filed: February 20, 2025
    Publication date: August 20, 2026
    Applicant: DigiCert, Inc.
    Inventors: Quentin Liu, Calista Liu
  • Patent number: 12712741
    Abstract: Systems and methods for controlling automated access to webpage content include receiving, by a web server, a request for a webpage from a client device; determining, by analyzing one or more request parameters or behavioral indicators, that the client device is a bot rather than a human-operated client; obtaining, from the bot, an x.509 certificate; validating the x.509 certificate to authenticate the bot's identity; retrieving metadata from the validated x.509 certificate, the metadata comprising at least one of: a bot type, authorized content categories, permitted request frequencies, or intended usage policies; comparing the retrieved metadata against predefined access rules stored by the web server; and serving the requested webpage content or a modified version thereof based on the comparison, thereby ensuring that the bot's access aligns with its authorized permissions.
    Type: Grant
    Filed: December 20, 2024
    Date of Patent: August 18, 2026
    Assignee: DigiCert, Inc.
    Inventor: Avesta Hojjati
  • Publication number: 20260227994
    Abstract: Systems and methods are provided for AI-driven predictive firmware update orchestration with self-healing capabilities for a fleet of Internet of Things (IoT) devices, embedded devices, resource-constrained devices, and the like. A device trust manager, according to one implementation, includes a risk assessment module employing machine learning models trained on historical update outcomes, configured to a) receive telemetry data and operational parameters from an IoT device fleet and b) generate a success probability score associated with deploying a firmware update to one or more IoT devices of the IoT device fleet. The device trust manager also includes a scheduling engine configured to determine an optimized update schedule based on the telemetry data, operational parameters, and success probability score, and an update deployment module configured to deploy the firmware update to the one or more IoT devices according to the optimized update schedule.
    Type: Application
    Filed: April 1, 2026
    Publication date: August 6, 2026
    Applicant: DigiCert, Inc.
    Inventor: Mahendra Shelke
  • Publication number: 20260228358
    Abstract: Systems and methods for providing training data from a digital trust management system are disclosed herein, including storing data associated with one or more operations within a secure repository of the digital trust management system, the data comprises a plurality of data elements, receiving, at the digital trust management system, a request to provide at least a portion of the stored data to an AI model for training, providing an interface configured to facilitate controlled access to the stored data by the AI model, prior to transmitting the requested data outside the digital trust management system, applying one or more filtering rules to the requested data based on sensitivity classifications of the data elements, and providing only non-sensitive data elements, as determined by the filtering, to the AI model for training, while excluding and retaining sensitive data elements within the confines of the digital trust management system.
    Type: Application
    Filed: March 20, 2025
    Publication date: August 6, 2026
    Applicant: DigiCert, Inc.
    Inventor: Samir Kumar Rakshit
  • Patent number: 12701117
    Abstract: Systems and methods for validating email recipients are provided. A method, according to one implementation, includes a step of obtaining a recipient email address entered in an address field of an email message that is being composed by a sender. The method also includes a step of checking validity of the recipient email address and a domain associated with the recipient email address, to identify one or more possible issues in the recipient email address before the email message is sent. The present disclosure can be implemented by an email coordinator service. Advantageously, an email does not leave the sender's possession until there is a validation of the recipient's address and domain.
    Type: Grant
    Filed: August 24, 2023
    Date of Patent: August 4, 2026
    Assignee: DigiCert, Inc.
    Inventor: Avesta Hojjati
  • Patent number: 12701016
    Abstract: Systems and methods for applying a digitally signed QR code to a vehicle are provided. In one implementation, a method includes the step of receiving, from a requesting entity, a Certificate Signing Request (CSR) and object-related information associated with an object. The method further includes the step of issuing a digital certificate to authenticate the object and/or the requesting entity. Also, the method includes the step of digitally signing a machine-detectable code configured to reference a database associated with the digital certificate and the object-related information. The method also includes the step of sending the digitally signed machine-detectable code to the requesting entity.
    Type: Grant
    Filed: November 20, 2023
    Date of Patent: August 4, 2026
    Assignee: DigiCert, Inc.
    Inventors: Samir Kumar Rakshit, Avesta Hojjati
  • Patent number: 12694257
    Abstract: Systems and methods are provided for establishing a trust framework with respect to smart wearable devices. In one implementation, a smart wearable device includes memory configured to store one or more certificates issued by a Certificate Authority (CA), wherein the one or more certificates enable a user of the smart wearable device to digitally verify his or her identity for performing a security-based action. The smart wearable device further includes a Near Field Communication (NFC) device configured to wirelessly link with a security terminal to perform the security-based action when the identity of the user is verified.
    Type: Grant
    Filed: June 17, 2024
    Date of Patent: July 28, 2026
    Assignee: DigiCert, Inc.
    Inventors: Supratik Mondal, Avesta Hojjati
  • Publication number: 20260213940
    Abstract: Systems and methods for generating cryptographic keys in a multi-stage process are provided. A method, in an embodiment, includes generating a plurality of partial cryptographic components adapted for at least one public-key cryptographic algorithm, wherein each partial cryptographic component is generated using a process specific to its respective algorithm; storing the partial cryptographic components in one or more secure pools accessible to a key assembly module; retrieving, by the key assembly module, one or more selected partial cryptographic components from the secure pools based on a requested key type or security parameter; and assembling a public-private key pair from the retrieved partial cryptographic components, wherein assembling the public-private key pair comprises performing reduced cryptographic computations compared to generating all components in a single, monolithic process.
    Type: Application
    Filed: January 21, 2025
    Publication date: July 23, 2026
    Applicant: DigiCert, Inc.
    Inventors: Atul Gupta, Avesta Hojjati
  • Publication number: 20260214078
    Abstract: Systems and methods are provided for securely managing sensitive information, such as patient data or medical data. According to one implementation, a method includes a step of receiving sensitive information from one or more electronic medical devices over one or more secure, encrypted communication channels in a home network, wherein the one or more electronic medical devices are pre-authenticated using secure credentials. The method also includes a step of re-encrypting the sensitive information received from the one or more electronic medical devices to create secured data packets. Next, the method includes a step of transmitting the secured data packets over the Internet to a remote healthcare server.
    Type: Application
    Filed: January 21, 2025
    Publication date: July 23, 2026
    Applicant: DigiCert, Inc.
    Inventors: Avesta Hojjati, Atul Gupta
  • Publication number: 20260214086
    Abstract: Systems and methods are provided for validating certificates of a certificate chain and validating Intermediate Certificate Authorities (ICAs). According to one implementations, a centralized certificate validation server is configured to receive a certificate status request from a resource-constrained device, wherein the certificate status request inquires as to whether security measures are in place to allow the resource-constrained device to securely perform an intended communication with a selected Intermediate Certificate Authority (ICA). The centralized certificate validation server is further configured to check a list of valid certificates and trusted ICAs with respect to a domain in which the resource-constrained device is deployed. Also, based on checking the list, the centralized certificate validation server is configured to respond to the resource-constrained device as to whether the resource-constrained device can continue with the intended communication with the selected ICA.
    Type: Application
    Filed: January 21, 2025
    Publication date: July 23, 2026
    Applicant: DigiCert, Inc.
    Inventors: Atul Gupta, Avesta Hojjati
  • Patent number: 12683781
    Abstract: Systems and methods for managing a quantum vault for storing a secret include, responsive to a determination of a first level of quantum computing processing capability, defining a first encryption algorithm for the quantum vault such that the first encryption algorithm is sufficient to protect against the first level of quantum computing, such that a first layer of the quantum vault is configured with the first encryption algorithm; and monitoring the quantum computing processing capability; and responsive to a determination of a second level of the quantum computing processing capability where the first encryption algorithm is no longer sufficient to protect against, defining a second encryption algorithm for the quantum vault such that the second encryption algorithm is sufficient to protect against the second level of quantum computing processing capability, and such that the second encryption algorithm is configured as an outermost layer over the first encryption algorithm.
    Type: Grant
    Filed: March 18, 2024
    Date of Patent: July 14, 2026
    Assignee: DigiCert, Inc.
    Inventor: Avesta Hojjati
  • Patent number: 12684000
    Abstract: Systems and methods are provided for creating simulations and attack vectors related to events surrounding embedded and/or Internet of Things (IoT) devices using injectable grammar. According to one implementation, a server, arranged in a network environment, includes a processing device and a memory device configured to store a management program having logic. The logic enables the processing device to perform a step of incorporating a grammar template into the management program. The management program includes a grammar template that simulates events associated with the embedded devices, and is configured to manage the definition of the associated events. The logic further enables the processing device to perform a step of executing the grammar template in the network environment, yet outside of a sandbox environment, to simulate the events associated with the embedded devices.
    Type: Grant
    Filed: August 15, 2023
    Date of Patent: July 14, 2026
    Assignee: DigiCert, Inc.
    Inventors: Mahendra Shelke, Jaydeep Raval
  • Publication number: 20260197187
    Abstract: Systems and methods manage public-key hygiene across certificate authorities (CAs) using privacy-preserving queries to a certificate transparency (CT) log. A CA receives a certificate signing request (CSR), extracts a public key, and applies a predetermined cryptographic transform, such as homomorphic, to generate a privacy-preserving representation of the public key. The CA checks a CT log database updated by multiple CAs to determine whether the public key has been previously used to obtain a certificate. If no prior use is detected, the CA may issue a certificate and update the CT log with the privacy-preserving representation or a hash thereof to denote usage. If prior use is detected, the CA may reject the CSR, request resubmission with a different public key, or require explicit authorization to proceed. The CT log may store only encrypted public keys or both plaintext and encrypted entries to support public and private hierarchies.
    Type: Application
    Filed: March 2, 2026
    Publication date: July 9, 2026
    Applicant: DigiCert, Inc.
    Inventor: Avesta Hojjati
  • Patent number: 12676760
    Abstract: Systems and methods for validating documents, organization, and individuals are provided, utilizing both automated and manually controlled validation checks. In one implementation, a method includes a step of receiving a request to perform a validation analysis with respect to an organization, wherein the validation analysis includes Machine-Learning (ML) procedures for checking multiple validation metrics. In response to gathering multiple documents relevant for performing the validation analysis, the method further includes a step of extracting data from each of the multiple documents relevant for checking the multiple validation metrics. Also, the method includes a step of accepting manual assistance from a validation specialist when needed for performing the validation analysis.
    Type: Grant
    Filed: June 3, 2024
    Date of Patent: July 7, 2026
    Assignee: DigiCert, Inc.
    Inventors: Daniel Birnel, Tyler Simpson, Ren Peterson, Avesta Hojjati
  • Publication number: 20260180812
    Abstract: Systems and methods for controlling automated access to webpage content include receiving, by a web server, a request for a webpage from a client device; determining, by analyzing one or more request parameters or behavioral indicators, that the client device is a bot rather than a human-operated client; obtaining, from the bot, an x.509 certificate; validating the x.509 certificate to authenticate the bot's identity; retrieving metadata from the validated x.509 certificate, the metadata comprising at least one of: a bot type, authorized content categories, permitted request frequencies, or intended usage policies; comparing the retrieved metadata against predefined access rules stored by the web server; and serving the requested webpage content or a modified version thereof based on the comparison, thereby ensuring that the bot's access aligns with its authorized permissions.
    Type: Application
    Filed: December 20, 2024
    Publication date: June 25, 2026
    Applicant: DigiCert, Inc.
    Inventor: Avesta Hojjati
  • Publication number: 20260169731
    Abstract: Systems and methods for monitoring and managing cryptographic libraries within a version control system include steps of subsequent to integrating a monitoring agent with the version control system as a hook or plugin that triggers upon one or more version control events including commits, pushes, or merges, continuously observing code changes in real-time as source code is committed to the version control system; analyzing newly added or modified files within the committed code to detect cryptographic libraries and associated cryptographic functions; and generating alerts upon detection of introduced, deprecated, or vulnerable cryptographic components.
    Type: Application
    Filed: December 17, 2024
    Publication date: June 18, 2026
    Applicant: DigiCert, Inc.
    Inventor: Avesta Hojjati
  • Patent number: 12647404
    Abstract: Systems and methods for coordination and management of keys and instructions for multiple encryption include, responsive to receiving encrypted data that has been encrypted via a plurality of layers of encryption, accessing a coordinator to determine instructions for multiple encryption; and decrypting the encrypted data based on the instructions and utilizing a plurality of keys with a key for each of the plurality of layers of encryption.
    Type: Grant
    Filed: September 20, 2023
    Date of Patent: June 2, 2026
    Assignee: DigiCert, Inc.
    Inventor: Tanner Young
  • Publication number: 20260149708
    Abstract: Systems and methods are provided for validating client information prior to certificate issuance. A method, according to one implementation, includes a step of providing an initiation option to a validation agent in response to the validation agent selecting a portion of a document retrieved from a reliable web source, the initiation option allowing the validation agent to initiate an automated validation procedure. In response to the validation agent selecting the initiation option, the method includes a step of performing the automated validation procedure, wherein the automated validation procedure includes a) a comparing sub-step in which the portion of the document selected by the validation agent is compared with client information included in a certificate request, and b) a compliance sub-step in which it is determined whether or not a comparison, based on the comparing sub-step, complies with a validation guideline.
    Type: Application
    Filed: November 22, 2024
    Publication date: May 28, 2026
    Applicant: DigiCert, Inc.
    Inventors: Ayne Lyons, Flavio Martins, Aditya Chandel, Vadym Merzlikin
  • Publication number: 20260149602
    Abstract: Systems and methods are provided for validating client information prior to certificate issuance. A method, according to one implementation, includes a step of obtaining enrollment information submitted from an organization to a trust entity, the enrollment information including details of the organization. In response to a web browser of the trust entity being navigated to a webpage associated with the organization, the method further includes a step of extracting identifying data from the webpage. Based on a comparison between the identifying data and the details of the organization, the method also includes a step of providing feedback to a validation agent of the trust entity regarding a validation status of the organization.
    Type: Application
    Filed: November 22, 2024
    Publication date: May 28, 2026
    Applicant: DigiCert, Inc.
    Inventor: Flavio Martins
  • Publication number: 20260147936
    Abstract: Systems and methods are provided for validating client information prior to certificate issuance. A method, according to one implementation, includes a step of displaying client information submitted by a client on a home screen of a user interface being operated by a validation agent responsible for executing a validation job for the client. Also, the method includes a step of displaying a validation sources tab on the home screen. In response to selection of the validation sources tab, the method also includes displaying links to vetted web sources from which data can be obtained to assist the validation agent with executing the validation job.
    Type: Application
    Filed: November 22, 2024
    Publication date: May 28, 2026
    Applicant: DigiCert, Inc.
    Inventors: Ayne Lyons, Flavio Martins, Aditya Chandel, Vadym Merzlikin