IP Library Granted Patent US 8,826,006
Granted Patent B2
US 8,826,006 · App. 12/262,761 · Granted Sep 2, 2014

Method and device for enabling a trust relationship using an unexpired public key infrastructure (PKI) certificate

Inventors: Liang Guo (Brighton, MA); Whay Chiou Lee (Cambridge, MA); Anthony R. Metke (Naperville, IL)
Assignee: Motorola Solutions, Inc.
H04L9/3268H04L9/321H04L9/006H04L9/0891
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,826,006
App. No.
12/262,761
Granted
Sep 2, 2014
Kind
B2
Abstract

A method and device are useful for enabling a trust relationship using an unexpired public key infrastructure (PKI) certificate, where a current status of the PKI certificate is unavailable. The method includes determining at a relying party that a certificate status update for the PKI certificate is unavailable (step 905 ). Next, in response to the certificate status update being unavailable, a tolerable certificate status age (TCSA) for the PKI certificate is determined at the relying party based on one or more attributes associated with a certificate holder of the PKI certificate (step 910 ). Using the PKI certificate, a trust relationship is enabled between the relying party and the certificate holder after determining the TCSA and before an expiration of the TCSA (step 915 ).

Claims (46)

1. A method for enabling a trust relationship using an unexpired public key infrastructure (PKI) certificate where a current status of the PKI certificate is unavailable, the method comprising:

determining at a relying party device that a certificate status update for the PKI certificate is unavailable;

determining at the relying party device, in response to the certificate status update being unavailable, a tolerable certificate status age (TCSA) for the PKI certificate based on one or more attributes associated with a certificate holder of the PKI certificate, wherein the TCSA is an interval during which an unexpired certificate can be conditionally trusted despite a lack of a timely certificate status update and further wherein the TCSA conforms to the following equation:

TCSA =( T _Current− T _BeginUncertainty)+ T (attributes),

wherein T_Current denotes a current time when the certificate holder is attempting to authenticate with the relying party,

T_BeginUncertainty denotes a beginning of an interval in which the relying party is unable to detect a revocation of the PKI certificate, and

T(attributes) conforms to the following bounds:

0≦ T (attributes)≦Max TCSA −( T _Current− T _BeginUncertainty)

wherein MaxTCSA is greater than or equal to TCSA; and

enabling, using the PKI certificate, a trust relationship between the relying party and the certificate holder after calculating the TCSA and before an expiration of the TCSA.

2. The method of claim 1 , T(Attributes)=α(attributes)×ΔTCSA,

wherein

α(attributes) is a minimum of metrics assigned to individual applicable attributes or a product of the metrics, and

ΔTCSA is equal to (MaxTCSA−(T_Current−T_BeginUncertainty)).

3. The method of claim 1 , wherein the one or more attributes associated with the certificate holder are selected from the following: one or more personnel attributes, one or more system attributes, and one or more environmental attributes.

4. The method of claim 3 , wherein the personnel attributes are identified in the PKI certificate and are selected from the following: a security level, a security tenure, a total employment seniority, a rank, and a trustworthiness metric.

5. The method of claim 3 , wherein the system attributes include whether a device associated with the PKI certificate includes licensed hardware or software.

6. The method of claim 5 , wherein the licensed hardware comprises a secure storage facility for a private key associated with the PKI certificate.

7. The method of claim 5 , wherein the licensed software comprises encryption software.

8. The method of claim 3 , wherein the environmental attributes are selected from the following: a network status, one or more detected alarms, and one or more local policy variables.

9. The method of claim 1 , wherein the attributes associated with the certificate holder are defined in the PKI certificate.

10. The method of claim 1 , wherein the relying party device determines that a certificate status update for the PKI certificate is unavailable based on a failure to receive a response to a status request.

11. The method of claim 1 , wherein a maximum age of the TCSA is determined by a MaxOutdate variable.

12. A device for enabling a trust relationship using an unexpired public key infrastructure (PKI) certificate where a current status of the PKI certificate is unavailable, comprising:

a processor; and

a programmable memory coupled to the processor for storing:

computer readable program code components for determining at a relying party that a certificate status update for the PKI certificate is unavailable;

computer readable program code components for determining at the relying party, in response to the certificate status update being unavailable, a tolerable certificate status age (TCSA) for the PKI certificate based on one or more attributes associated with a certificate holder of the PKI certificate, wherein the TCSA is an interval during which an unexpired certificate can be conditionally trusted despite a lack of a timely certificate status update and further wherein the TCSA conforms to the following equation:

TCSA=( T _Current− T _BeginUncertainty)+T(attributes),

wherein T_Current denotes a current time when the certificate holder is attempting to authenticate with the relying party,

T_BeginUncertainty denotes a beginning of an interval in which the relying party is unable to detect a revocation of the PKI certificate, and

T(attributes) conforms to the following bounds:

0≦ T (attributes)≦Max TCSA −( T _Current− T _BeginUncertainty),

wherein MaxTCSA is greater than or equal to TSCA; and

computer readable program code components for enabling, using the PKI certificate, a trust relationship between the relying party and the certificate holder after calculating the TCSA and before an expiration of the TCSA.

13. The device of claim 12 , wherein T(Attributes)=α(attributes)×ΔTCSA,

wherein

α(attributes) is a minimum of metrics assigned to individual applicable attributes or a product of the metrics, and

ΔTCSA is equal to (MaxTCSA−(T_Current−T_BeginUncertainty)).

14. The device of claim 12 , wherein the one or more attributes associated with the certificate holder are selected from the following: one or more personnel attributes, one or more system attributes, and one or more environmental attributes.

15. The device of claim 14 , wherein the personnel attributes are identified in the PKI certificate and are selected from the following: a security level, a security tenure, a total employment seniority, a rank, and a trustworthiness metric.

16. The device of claim 14 , wherein the system attributes include whether a device associated with the PKI certificate includes licensed hardware or software.

17. The device of claim 16 , wherein the licensed hardware comprises a secure storage facility for a private key associated with the PKI certificate.

18. The device of claim 16 , wherein the licensed software comprises encryption software.

19. The device of claim 14 , wherein the environmental attributes are selected from the following: a network status, one or more detected alarms, and one or more local policy variables.

20. The device of claim 12 , wherein the attributes associated with the certificate holder are defined in the PKI certificate.

Assignments (10)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 049905/0504 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); ARRIS TECHNOLOGY, INC.; ARRIS SOLUTIONS, INC.; COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; RUCKUS WIRELESS, LLC (F/K/A RUCKUS WIRELESS, INC.)
Reel/Frame 071477/0255 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
PATENT SECURITY AGREEMENT Recorded Jul 3, 2019
From: ARRIS ENTERPRISES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 049820/0495 →
ABL SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049892/0396 →
TERM LOAN SECURITY AGREEMENT Recorded Jul 3, 2019
From: COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC; ARRIS ENTERPRISES LLC; ARRIS TECHNOLOGY, INC.; RUCKUS WIRELESS, INC.; ARRIS SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 049905/0504 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2017
From: MOTOROLA SOLUTIONS, INC.
To: ARRIS ENTERPRISES LLC
Reel/Frame 044806/0900 →
CHANGE OF NAME Recorded Apr 6, 2011
From: MOTOROLA, INC
To: MOTOROLA SOLUTIONS, INC.
Reel/Frame 026079/0880 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2008
From: GUO, LIANG; LEE, WHAY CHIOU; METKE, ANTHONY R.
To: MOTOROLA, INC.
Reel/Frame 021770/0214 →
Continuity (1)
Related Publication 20100115266A1 · May 6, 2010