IP Library Granted Patent US 7,707,406
Granted Patent B2
US 7,707,406 · App. 10/703,104 · Granted Apr 27, 2010

Certificate renewal in a certificate authority infrastructure

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,707,406
App. No.
10/703,104
Granted
Apr 27, 2010
Kind
B2
Abstract

A system using digital certificates having overlapping validity intervals. The overlapping certificates can be used in a hierarchical certificate authorities network in order to obtain benefits such as to increase the usage of all the certificates in the certificate chain; reduce/eliminate the certificate updates/downloads to a large population; only replace the minimum number of certificates in the trust hierarchy to re-establish the certificate chain; reduce the complexity of maintaining certificate nesting in certificate generation process; reduce the risk of service interruption; and control the extent of older technology in circulation and to reduce the risk associated with older products being more susceptible to attack. The certificate renewal process of a preferred embodiment is described.

Claims (30)

1. A method for providing a certificate in a digital security system, the method utilizing at least one computer configured to perform the steps of:

issuing a first certificate from a first certificate authority (CA), wherein the first certificate has a first renewal period;

issuing a second certificate from a second CA by using at least a portion of information in the first certificate, said second certificate having a validity period, said first renewal period and said validity period overlapping one another;

issuing a third certificate unique to a given device by using at least a portion of information in the second certificate; and

creating a new certificate at the first CA to be used in subsequent issuing steps of the first and second CAs in place of the first certificate,

wherein a validity chain of the second certificate remains valid after the step of creating the new certificate has been performed,

said third certificate being stored in said given device.

2. The method of claim 1 , wherein the first CA includes a process at a first location and wherein the second CA includes a process at a location separate from the first location.

3. The method of claim 2 , wherein the second process receives a Root CA certificate from a root-level process.

4. The method of claim 3 , wherein the root-level process issued self-authenticated certificates.

5. The method of claim 1 , wherein said given device includes a set-top box for receiving encrypted digital content.

6. The method of claim 1 , wherein the certificates are in accordance with Standard X.509.

7. The method of claim 1 , further comprising renewing the first certificate.

8. The method of claim 7 , wherein the validity periods of the first and second certificates each have a predetermined interval and start time.

9. The method of claim 8 , wherein the start times of renewed certificates are two years apart.

10. The method of claim 1 , wherein renewal periods are chosen to minimize network traffic.

11. The method of claim 1 , wherein renewal periods are chosen to maximize certificate lifetime.

12. The method of claim 11 , wherein the duration of a certificate is 20 years.

13. The method of claim 1 , wherein a certificate includes a first cryptographic key, the method further comprising providing a rekey certificate with a second cryptographic key, different from the first cryptographic key.

14. The method of claim 13 , wherein the rekey certificate is provided after a predetermined interval after the certificate with the first cryptographic key is provided.

15. The method of claim 14 , wherein the predetermined interval is 30 years.

16. An apparatus for providing a certificate in a digital security system, the apparatus comprising:

at least one computer;

a first certificate authority (CA), implemented on the at least one computer, which issues a first certificate, wherein the first certificate has a first renewal period; and

a second CA, implemented on the at least one computer, which issues a second certificate by using at least a portion of information in the first certificate, said second certificate having a validity period, said first renewal period and said validity period overlapping one another, said second CA further issuing a third certificate unique to a given device by using at least a portion of information in the second certificate; said third certificate being stored in said given device;

wherein a new certificate is issued by the first CA to be used in subsequent issuing operations of the first CA and the second CA in place of the first certificate, and

wherein the validity period of the second certificate overlaps with a renewal period of the new certificate.

17. The apparatus of claim 16 , wherein renewal are chosen to minimize network traffic.

18. The apparatus of claim 16 , wherein renewal periods are chosen to maximize certificate lifetime.

19. The method of claim 1 , wherein renewal periods are chosen to minimize the number of renewals over a period of time.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2014
From: MOTOROLA MOBILITY LLC
To: GOOGLE TECHNOLOGY HOLDINGS LLC
Reel/Frame 034517/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2013
From: GENERAL INSTRUMENT CORPORATION
To: GENERAL INSTRUMENT HOLDINGS, INC.
Reel/Frame 030764/0575 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2013
From: GENERAL INSTRUMENT HOLDINGS, INC.
To: MOTOROLA MOBILITY LLC
Reel/Frame 030866/0113 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2004
From: QIX, XIN
To: GENERAL INSTRUMENT CORPORATION
Reel/Frame 015285/0610 →