IP Library Granted Patent US 7,644,284
Granted Patent B1
US 7,644,284 · App. 09/840,230 · Granted Jan 5, 2010

Specifying security protocols and policy constraints in distributed systems

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,644,284
App. No.
09/840,230
Granted
Jan 5, 2010
Kind
B1
Abstract

A recent secure authentication service enforcing revocation in distributed systems is provided. Authenticity entities impose freshness constraints, derived from initial policy assumptions and authentic statements made by trusted intermediaries, in authenticated statements made by intermediaries. If freshness constraints are not presented, authentication is questionable. The freshness constraints can be adjusted. The delay for revocation can be arbitrarily bounded. The freshness constraints within certificates results in a secure and highly available revocation service such that less trust is required of the service.

Claims (5)

1. A system that includes a security policy server, an identification authority server, a revocation authority server, a verification authority server, and a user computer, comprising:

a module within the identification authority server that, pursuant to a first policy that establishes identity of said user in a public network, which policy is received from said security policy server, and a first request from said user computer, prepares and sends to said user computer, via said public network to which said user computer, identification authority server, revocation authority server, and said verification authority server are connected and through which said identification authority server and said revocation authority server interact with said verification authority server and said user computer, an identification certificate that includes a freshness constraint represented by a time duration referenced to time of said first request by said user computer;

a module within said revocation authority server configured to store in a memory that is coupled to said revocation authority via said public network, a validity statement in response to a received second policy that is time-of-day sensitive, and to update said validity statement at specified intervals, said validity statement pertaining solely to said user and including an explicit verification status for said user as of a specified date and time;

means configured to provide, in response to a second request initiated by said user computer, said identification certificate and said validity statement retrieved from said memory, to said verification authority server, via said public network; and

a module within said verification authority server configured to verify that said second request is within said time duration and said validity statement permits serving said second request by said user computer.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 2, 2020
From: INTELLECTUAL VENTURES II LLC
To: INTELLECTUAL VENTURES ASSETS 158 LLC
Reel/Frame 051777/0107 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2020
From: INTELLECTUAL VENTURES ASSETS 158 LLC
To: HANGER SOLUTIONS, LLC
Reel/Frame 051486/0425 →