IP Library Granted Patent US 7,321,970
Granted Patent B2
US 7,321,970 · App. 10/748,760 · Granted Jan 22, 2008

Method and system for authentication using infrastructureless certificates

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,321,970
App. No.
10/748,760
Granted
Jan 22, 2008
Kind
B2
Abstract

Methods and systems are directed to authenticating a client over a network. The client generates a certificate and sends it to a server through a trusted mechanism. The server is configured to store the received certificate. When the client requests authentication over the network, it provides the certificate again, along with a parameter associated with a secure session. The server verifies the parameter associated with the secure session and determines if the certificate is substantially the same as the stored certificate. The server authenticates the client over the network, if the certificate is determined to be stored. In another embodiment, the client transmits the certificate that is generated by a third party Certificate Authority (CA) based, in part, on the client's public key.

Claims (27)

1. A method for authenticating a client over a network, comprising: generating a first certificate; sending the first certificate to a server, wherein the server is configured to store the first certificate; requesting a second certificate if authentication over the network is requested; sending the second certificate to the server over the network; comparing the second certificate to the first certificate at the server, and if the second certificate and the first certificate are substantially the same, authenticating the client.

2. The method of claim 1 , wherein the server is further configured to generate the first certificate.

3. The method of claim 1 , wherein sending the first certificate further comprises using a trusted mechanism selected from at least one of a manual entry of certificate, a secure channel, and a private channel.

4. The method of claim 3 , wherein the trusted mechanism further comprises at least one of the client authenticating to the server, and the client proving ownership of the certificate to the server.

5. The method of claim 1 , wherein the client is further configured to generate the first certificate.

6. The method of claim 1 , wherein a third party Certificate Authority (CA) is configured to generate the first certificate.

7. A method for authenticating a client over a network, comprising: receiving a certificate from the client over a trusted mechanism; storing the certificate at a server; requesting another certificate if authentication is requested; comparing the other certificate to the stored certificate, and if the other certificate and the stored certificate are substantially the same, authenticating the client.

8. The method of claim 7 , wherein the trusted mechanism further comprises at least one of a manual entry of certificate, a secure channel, and a private channel.

9. The method of claim 8 , wherein the trusted mechanism further comprises at least one of the client authenticating to the server, and the client proving ownership of the certificate to the server.

10. The method of claim 7 , wherein the server is further configured to store and to compare the certificate.

11. The method of claim 7 , wherein the certificate is stored in at least one of a hard disk, a tape disk, and a mass storage device.

12. A method for authenticating a network device over a network, comprising: generating a certificate; sending the certificate to an other network device, wherein the other network device enables storage of the certificate; resending the certificate to the other network device; comparing the resent certificate to the stored certificate; and if the resent certificate and the stored certificate are determined to be substantially the same, receiving authentication.

13. The method of claim 12 , wherein generating the certificate is performed by the other network device.

14. The method of claim 12 , wherein the network device is configured to generate the first certificate.

15. The method of claim 12 , wherein a third party Certificate Authority (CA) is configured to generate the first certificate.

16. An apparatus for authenticating a client over a network, comprising: a first component configured to receive a first certificate and a second certificate; and a second component, coupled to the first component, that is configured to perform actions including: determining if the first certificate and the second certificate are substantially the same; and if it is determined that the first certificate and the second certificate are substantially the same, authenticating the client associated with the first certificate and the second certificate.

17. The apparatus of claim 16 , wherein the apparatus operates as at least one of a server, a gateway, and a server array.

18. The apparatus of claim 16 , wherein the first component is further configured to store the first certificate.

19. The apparatus of claim 16 further comprising a third component, coupled to the first component, and configured to generate the first certificate based, in part, on information provided by the client.

20. An apparatus for receiving authentication over a network, comprising: a first component configured to generate a certificate; a second component, coupled to the first component, configured to send the certificate to a server; and a third component, coupled to the second component, configured to resend the certificate to the server over the network, wherein resending the certificate enables the server to authenticate a client based, in part, on a comparison of the sent certificate and the resent certificate to determine if the sent certificate and the resent certificate are substantially the same.

21. The apparatus of claim 20 , wherein the apparatus operates as at least one of a client, a portable computer, and a personal digital assistant.

22. The apparatus of claim 20 , wherein the certificate is sent to the server using a trusted mechanism selected from at least one of a manual entry of certificate, a secure channel, and a private channel.

23. The apparatus of claim 22 , wherein the trusted mechanism further comprises at least one of the client authenticating to the server, and the client proving ownership of the certificate to the server.

24. A system for authenticating a client over a network, comprising: a client, configured to perform actions, comprising: generating a first certificate; sending the first certificate to a server to be stored; and sending a second certificate if authentication over the network is requested; and a server, in communication with the client, configured to perform actions, comprising: storing the first certificate at the server if the first certificate is received for a first time; comparing the second certificate to the first certificate; and authenticating the client over the network, if the first certificate and the second certificate are substantially the same.

25. The system of claim 24 , wherein authenticating the client over the network further comprises establishing a secure session.

26. A system for authenticating a client over a network, comprising: a client, further comprising: means for generating a first certificate; means for sending the first certificate to a server to be stored; and means for sending a second certificate if authentication over the network is requested; and a server, in communication with the client, further comprising: means for storing the first certificate at the server if the first certificate is received for the first time; means for comparing the second certificate to the first certificate; and means for authenticating the client, if the first certificate and the second certificate are substantially the same.

27. The system of claim 26 , wherein the means for storing comprises at least one of a hard disk, a tape disk, and a mass storage device.

Assignments (8)
SECURITY INTEREST Recorded Jun 1, 2021
From: WSOU INVESTMENTS, LLC
To: OT WSOU TERRIER HOLDINGS, LLC
Reel/Frame 056990/0081 →
RELEASE OF SECURITY INTEREST Recorded May 21, 2019
From: OCO OPPORTUNITIES MASTER FUND, L.P. (F/K/A OMEGA CREDIT OPPORTUNITIES MASTER FUND LP
To: WSOU INVESTMENTS, LLC
Reel/Frame 049246/0405 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 25, 2017
From: NOKIA SOLUTIONS AND NETWORKS BV
To: WSOU INVESTMENTS, LLC
Reel/Frame 043953/0938 →
SECURITY INTEREST Recorded Sep 21, 2017
From: WSOU INVESTMENTS, LLC
To: OMEGA CREDIT OPPORTUNITIES MASTER FUND, LP
Reel/Frame 043966/0574 →
CHANGE OF NAME Recorded Nov 19, 2014
From: NOKIA SIEMENS NETWORKS OY
To: NOKIA SOLUTIONS AND NETWORKS OY
Reel/Frame 034294/0603 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2008
From: NOKIA CORPORATION
To: NOKIA SIEMENS NETWORKS OY
Reel/Frame 020550/0521 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2008
From: NOKIA INC
To: NOKIA CORPORATION
Reel/Frame 020540/0061 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2004
From: WATKINS, CRAIG R.; BARRETT, JEREMEY; CAIN, ADAM
To: NOKIA, INC.
Reel/Frame 015399/0384 →