IP Library Patent Application 11729735
Patent Application
App. No. 11/729,735

Certificate management system

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/729,735
Abstract

A system and method for generating and storing a large number of public key certificates that enables a revocation status to be determined while providing a smaller amount of storage than is typically required.

Claims (31)

1 . A system comprising:

a certificate authority system for issuing certificates, each certificate including valid duration information indicating a period when the certificates are valid and individual identification information, the system including

first memory for storing information about digital certificates in rows, wherein each of a plurality of rows has a range of identification numbers with common valid duration information, such that one row has a first range of identification information with common validity duration information and a second row has a second range of identification, different from the first range of information, having common valid duration information different from the valid duration information for the first row,

second memory including information indicating, for a subset of the certificates, that such certificates is not valid and an associated date.

2 . The system of claim 1 , wherein the first memory includes at least 100,000 certificates.

3 . The system of claim 1 , wherein the first memory includes at least 1,000,000 certificates.

4 . The system of claim 1 , wherein the first memory includes at least 10,000,000 certificates.

5 . The system of claim 1 , wherein the duration information includes a valid start date and an end date.

6 . The system of claim 1 , wherein the duration information includes a start date and a valid period.

7 . The system of claim 1 , wherein the first memory and second memory are separate tables in a single physical memory.

8 . The system of claim 1 , wherein the identification information includes serial numbers issued consecutively.

9 . The system of claim 8 , further comprising a decoder for receiving and decoding a coded serial number, the decoder producing a decoded serial number, wherein the decoded serial numbers can be arranged consecutively based on when the certificates with those serial numbers were issued, wherein the coded serial number obscures when one certificates was issued relative to another.

10 . The system of claim 1 , further comprising processing logic, responsive to a request with identification information, for looking up the identification information in the first memory and second memory and returning information on whether the certificate is valid.

11 . The system of claim 10 , wherein the processing logic includes a decoder for receiving and decoding identification information, the decoder producing a decoded serial number, wherein the decoded serial numbers can be arranged consecutively based on when the certificates with those serial numbers were issued, wherein the coded serial number obscures when one certificates was issued relative to another.

12 . A method for validating a digital certificate comprising:

receiving data identifying a certificate;

storing information about digital certificates in memory, including:

first memory for storing information about digital certificates in rows, wherein each of a plurality of rows has a range of identification numbers with common valid duration information, such that one row has a first range of identification information with common validity duration information and a second row has a second range of identification, different from the first range of information, having common valid duration information different from the valid duration information for the first row, and

second memory including information indicating, for a subset of the certificates, that such certificates is not valid and an associated date;

looking up the certificate based on the data in a first memory;

looking up the certificate based on the data in a second memory;

based on the looking up processes, identifying to a requester whether the certificate is valid or not valid.

13 . The method of claim 11 , wherein the received data is in coded form, the method further including decoding the received data to derive a sequential serial number.

14 . The method of claim 11 , wherein the storing includes storing information related to least 1,000,000 certificates in first memory.

15 . The method of claim 11 , wherein the storing includes storing information related to at least 10,000,000 certificates in first memory.

16 . The method of claim 11 , wherein the storing includes storing with duration information including a valid start date and an end date.

17 . The method of claim 11 , wherein the storing includes storing with duration information including a start date and a valid period.

18 . The method of claim 11 , wherein the storing includes storing in a database, the first memory and the second memory being part of the same database.

19 . The method of claim 11 , wherein the looking up in second memory is performed before looking up in first memory.

20 . The method of claim 11 , wherein the looking up in first memory is performed before looking up in second memory.

21 . A computer readable medium having instructions that, when executed, perform the method of claim 11 .

Assignments (2)
CHANGE OF NAME Recorded Jun 18, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 053306/0878 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2007
From: LINDEMANN, ROLF
To: TC TRUST CENTER, GMBH
Reel/Frame 019174/0925 →