IP Library Granted Patent US 6,895,501
Granted Patent B1
US 6,895,501 · App. 09/524,272 · Granted May 17, 2005

Method and apparatus for distributing, interpreting, and storing heterogeneous certificates in a homogenous public key infrastructure

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,895,501
App. No.
09/524,272
Granted
May 17, 2005
Kind
B1
Abstract

A connection is established between a server and a web browser having access to a first, trusted public key. The server downloads a digitally signed archive to the browser, the archive including a second public key. The browser verifies the digitally signed archive using the first public key, and stores the second public key in response to the verification. The browser then uses the stored second public key to authenticate the server and establish a secure connection with the server. The second public key and its chain of trust need not be known by the browser beforehand, and the archive may include program fragments that store the key in an area where the browser (or an applet running under the browser) can access and use it. The archive may also include a program fragment that performs certificate validation for the client—enabling the client to handle certificate types it does not know about. Advantages include allowing the archive to be transmitted over any insecure connection since it is integrity protected and authenticated; and allowing the client to make a direct connection to the server without having to access certificate stores on the platform.

Claims (37)

1. A method for establishing a secure network connection between a web browser on a client and a service, said web browser having a virtual machine, said web browser having access to a first key, said client web browser and virtual machine being of the type that downloads and executes applets while protecting against at least some client resources from being updated based on said applet execution, said method comprising:

establishing an insecure network connection with said client web browser;

downloading, over said insecure connection, at least one digitally signed applet to the client web browser, said at least one applet including: (a) a second key, (b) code executable on the client virtual machine to cause the client to store the second key, and (c) code executable on the client virtual machine to use the stored second key to establish a secure network connection with said service;

before the client virtual machine executes the digitally signed applet, verifying the digitally signed applet at the client using the first key;

executing the downloaded applet code with the client virtual machine, thereby causing the client to store the second key corresponding to the service; and

further executing said at least one applet to cause said at least one applet to use the stored second key to authenticate the service and establish the secure network connection with the service.

2. The method of claim 1 wherein the applet further includes program code that controls the client to use the stored second key to verify a signature subsequently provided by the server.

3. The method of claim 1 wherein the executing step includes controlling the client virtual machine to store, at the client, the second key in the form of a digital certificate corresponding to the server, and the further executing step comprises receiving a digital signature from the server, and authenticating the received digital signature under control of the executing applet through use of the stored digital certificate corresponding to the server.

4. The method of claim 1 wherein the further executing step includes having the executing applet invoke a further applet to establish a secure connection.

5. The method of claim 1 wherein the applet comprises a signed Archive containing a digital certificate corresponding to the server, and a program fragment that stores the digital certificate in a predetermined location on the client that permits the client to later retrieve the stored digital certificate.

6. The method of claim 1 wherein the applet includes a second key payload and further includes first program code that controls the client to store the second key to a non-volatile memory.

7. The method of claim 6 wherein the non-volatile memory comprises a disk.

8. The method of claim 6 wherein the applet further includes second program code that controls the client to use the stored second key to verify a signature subsequently provided by the server.

9. A web browser on a client for establishing a secure network connection with a service over a network, said client web browser including a virtual machine, said client web browser and virtual machine being of the type that downloaded and execute applets while protecting against at least some resources of said client from being updated by said applet execution, said client comprising:

an applet receiver that receives at least one digitally signed applet from the service over an insecure network connection, said at least one applet including: (a) a key, (b) code executable on the client virtual machine to cause the client to store the key, and (c) code executable on the client virtual machine to establish a secure network connection with said service, said applet being executed by the client virtual machine to cause the client to store the key delivered with the applet, the stored key allowing authentication between the client and the service;

wherein the client web browser includes an applet verifier that, before executing the applet, verifies the digitally signed applet using a key different from the key delivered with the applet;

wherein the client virtual machine further includes an applet executor that executes the applet, thereby controlling the client to store the key delivered with the applet, said delivered key corresponding to the server, and uses the stored delivered key to authenticate the server and establish a secure network connection between the client and the server.

10. A method for establishing a secure network connection with a web browser on a client, said client web browser including a virtual machine and having access to a first key, said client web browser and virtual machine being of the type that download and execute applets while protecting at least some of client resources from being affected by said applet execution, the method comprising:

downloading, over an insecure network connection, at least one executable applet to the client virtual machine, said at least one applet including: (a) a second key corresponding to the server, (b) code executable on the client virtual machine to cause the client to store the further key corresponding to the server, and (c) code executable on the client virtual machine to establish a secure network connection with said server, the digitally signed applet being digitally signed such that the client virtual machine can verify the digitally signed applet using the first key, the at least one digitally signed applet including the further key and code executable by the client virtual machine that controls the client virtual machine to store the further key;

sending a digital credential to the client, said digital credential being verifiable by the client applet using the stored further key delivered with the at least one applet; and

establishing a secure network communication with the executing client applet based on said digital credential as verified by the client applet.

11. The method of claim 10 wherein the applet further includes further code that controls the client to use the stored further key to verify the digital credential.

12. The method of claim 10 further including sending a further applets to the client in response to an invocation of the further applet by the at least one applet.

13. The method of claim 10 wherein the applet comprises a signed Archive containing a digital certificate, and a program fragment that stores the digital certificate in a predetermined location on the client that permits the client to later retrieve the stored digital certificate.

14. The method of claim 10 wherein the applet code controls the client to store the further key to a non-volatile memory.

15. The method of claim 14 wherein the non-volatile memory comprises a disk.

16. A server for establishing a secure network connection with a web browser on a client over a network, said client having resources including the web browser and a virtual machine, said client web browser and virtual machine being of the type that download and execute applets while protecting at least some of said client resources from being affected by said applet execution, said server comprising:

an applet transmitter that transmits at least one digitally signed applet to the client over an insecure network connection, the at least one applet being digitally signed using a first key the client possesses independently of the applet, said at least one applet including: (a) a second key corresponding to the server, (b) code executable on the client virtual machine to cause the client to store the second key, and (c) code executable on the client virtual machine to establish a secure network connection with said server, the applet being executable by the client virtual machine to control the client to store the second key corresponding to the server;

a digital credential transmitter that transmits a digital credential to the client executing the applet, the digital credential being authenticatable by the client using the second key; and

a secure network connector that establishes a secure network connection with the client under control of the executing applet and based at least in part on the digital credential being authenticated by the second key delivered over the insecure network connection.

17. A method for establishing a secure network connection between a server and a web browser on a client having access to a firstkey and also having a virtual machine, said web browser and virtual machine downloading and executing applets while protecting resources from being updated by said applet execution, said method comprising:

downloading, to the browser over an insecure network connection, at least one digitally signed applet, the applet including: (a) a second key associated with the server, (b) code executable on the client virtual machine to cause the client to store the second key, and (c) code executable on the client virtual machine to establish a secure network connection with said server;

verifying the digitally signed applet at the browser using the first key;

executing the applet with the virtual machine to cause the client to store the second key;

using the stored second key to authenticate a further credential delivered by the server; and

based on said authentication of the said further credential, establishing, under control of the executing applet, a secure network connection between the web browser and the server.

18. A method as in claim 17 wherein the applet comprises an archive.

Assignments (25)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028253/0086 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: ATTACHMATE CORPORATION
Reel/Frame 034443/0558 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028253/0098 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: ATTACHMATE CORPORATION
Reel/Frame 034443/0621 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: ATTACHMATE CORPORATION
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028253/0086 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: ATTACHMATE CORPORATION
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028253/0098 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026268/0096) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: ATTACHMATE CORPORATION
Reel/Frame 028253/0059 →
RELEASE OF SECURITY INTEREST IN PATENTS SECOND LIEN (RELEASES RF 026275/0105) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: ATTACHMATE CORPORATION
Reel/Frame 028253/0042 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: ATTACHMATE CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0105 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: ATTACHMATE CORPORATION
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026268/0096 →
RELEASE OF PATENTS AT REEL/FRAME NOS. 17870/0329 AND 020929 0225 Recorded May 2, 2011
From: CREDIT SUISSE, CAYMAN ISLANDS BRANCH, AS SECOND LIEN COLLATERAL AGENT
To: ATTACHMATE CORPORATION
Reel/Frame 026213/0762 →
RELEASE OF PATENTS AT REEL/FRAME NOS. 017858/0915 AND 020929/0228 Recorded May 2, 2011
From: CREDIT SUISSE, CAYMAN ISLANDS BRANCH, AS FIRST LIEN COLLATERAL AGENT
To: ATTACHMATE CORPORATION
Reel/Frame 026213/0265 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded Jul 4, 2006
From: ATTACHMATE CORPORATION
To: CREDIT SUISSE, CAYMAN ISLANDS BRANCH, AS SECOND LIEN COLLATERAL AGENT
Reel/Frame 017870/0329 →
RELEASE OF SECURITY INTEREST Recorded Jun 30, 2006
From: WELLS FARGO FOOTHILL, INC.
To: ATTACHMATE CORPORATION, ATTACHMATE ACQUISITION CORPORATION, WRQ, INC., WIZARD HOLDING CORPORATION
Reel/Frame 017870/0001 →
GRANT OF PATENT SECURITY INTEREST (FIRST LIEN) Recorded Jun 30, 2006
From: ATTACHMATE CORPORATION
To: CREDIT SUISSE, CAYMAN ISLANDS BRANCH, AS FIRST LIEN COLLATERAL AGENT
Reel/Frame 017858/0915 →
RELEASE OF SECURITY INTEREST Recorded Jun 30, 2006
From: D. B. ZWIRN
To: ATTACHMATE CORPORATION, ATTACHMATE ACQUISITION CORPORATION, WRQ, INC., WIZARD HOLDING CORPORATION
Reel/Frame 017858/0923 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 15, 2005
From: WRQ, INC.
To: ATTACHMATE CORPORATION
Reel/Frame 017215/0729 →
SECURITY AGREEMENT Recorded May 26, 2005
From: WRQ, INC.; ATTACHMATE ACQUISITION CORP.; ATTACHMATE CORPORATION
To: WELLS FARGO FOOTHILL, INC., AS AGENT
Reel/Frame 016059/0775 →
SECURITY INTEREST Recorded Jan 4, 2005
From: WRQ, INC.; WIZARD HOLDING CORPORATION, A DELAWARE CORPORATION; WRQ INTERNATIONAL, INC., A WASHINGTON CORPORATION
To: D.B. ZWIRN SPECIAL OPPORTUNITIES FUND, L.P.
Reel/Frame 015529/0804 →
SECURITY AGREEMENT Recorded Dec 29, 2004
From: WRQ, INC.; WIZARD MERGER CORPORATION
To: WELLS FARGO FOOTHILL, INC.
Reel/Frame 015499/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2000
From: SALOWEY, JOSEPH A.
To: WRQ, INC.
Reel/Frame 010819/0928 →