IP Library Granted Patent US 9,083,535
Granted Patent B2
US 9,083,535 · App. 13/882,812 · Granted Jul 14, 2015

Method and apparatus for providing efficient management of certificate revocation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,083,535
App. No.
13/882,812
Granted
Jul 14, 2015
Kind
B2
Abstract

A method for providing efficient management of certificate revocation may comprise storing a list of identifiers of digital certificates including a revocation list defining a list of revoked certificates in an accumulator, storing a witness value in association with at least some entries in the revocation list in which the witness value provides proof of the membership or non-membership of an identifier in the revocation list, enabling generation of a new accumulator and a new witness value responsive to each insertion or deletion of an entry in the revocation list, and enabling batch updates to the revocation list using a reduced bitlength value generated based on to a ratio of a value generated based on elements added to the revocation list to a value generated based on elements deleted from the revocation list. A corresponding apparatus is also provided. A method for certificate authorities (CA) that use Bloom filters for certificate revocation list (CRL) compression that enables the CA to hash only the entry that is to be un-revoked so that a good compression rate may be provided while avoiding computation of the entire CRL for each un-revocation.

Claims (20)

1. A method comprising:

storing a list of identifiers of digital certificates including a revocation list defining a list of revoked certificates in an accumulator;

storing a witness value in association with at least some entries in the revocation list, the witness value providing proof of the membership or non-membership of an identifier in the revocation list;

enabling generation of a new accumulator and a new witness value responsive to each insertion or deletion of an entry in the revocation list; and

enabling batch updates to the revocation list using a reduced bitlength value generated based on to a ratio of a first value generated based on elements added to the revocation list to a second value generated based on elements deleted from the revocation list.

2. The method of claim 1 , wherein enabling batch updates comprises using the reduced bitlength value r replaced by y=r mod λ(n), where r=A/D and where a i defines elements to be added in a row, A=Πa i , and d i defines elements to be deleted in a row, D=Πd i , to add y as an entry to a set X to update witness values and λ(n) is the least common multiplier of (p 1 −1) a−1 1 , . . ., (p v −1) a−1 v , where p i are primes of a unique factorization of n.

3. The method of claim 1 , wherein storing the list, storing the witness value, enabling generation of the new accumulator and the new witness value, and enabling batch updates is performed at a certificate authority.

4. The method of claim 3 , wherein storing the list, storing the witness value, enabling generation of the new accumulator and the new witness value, and enabling batch updates is enabled to be performed at a semi-trusted delegate.

5. The method of claim 4 , wherein the certificate authority is enabled to monitor activity of the semi-trusted delegate with respect to at least generation of the new witness value and revoke the semi-trusted delegate based on irregularities associated with generation of the new witness value.

6. The method of claim 4 , wherein the semi-trusted delegate is enabled to generate witness values to provide proof of membership or non-membership using a zero-knowledge proof mechanism.

7. An apparatus comprising at least one processor and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the at least one processor, cause the apparatus at least to:

store a list of identifiers of digital certificates including a revocation list defining a list of revoked certificates in an accumulator;

store a witness value in association with at least some entries in the revocation list, the witness value providing proof of the membership or non-membership of an identifier in the revocation list;

enable generation of a new accumulator and a new witness value responsive to each insertion or deletion of an entry in the revocation list; and

enable batch updates to the revocation list using a reduced bitlength value generated based on to a ratio of a first value generated based on elements added to the revocation list to a second value generated based on elements deleted from the revocation list.

8. The apparatus of claim 7 , wherein the at least one memory and computer program code are configured to, with the at least one processor, cause the apparatus to enable batch updates by using the reduced bitlength value r replaced by y=r mod λ(n), where r=A/D and where a i defines elements to be added in a row, A=Πa i , and d i defines elements to be deleted in a row, D=Πd i to add y as an entry to a set X to update witness values and λ(n) is the least common multiplier of (p 1 −1) a−1 1 , . . . , (p v −1) a−1 v , where p i are the primes of the unique factorization of n.

9. The apparatus of claim 7 , wherein the apparatus is embodied at a certificate authority.

10. The apparatus of claim 9 , wherein the at least one memory and computer program code are configured to, with the at least one processor, cause the apparatus to store the list, store the witness value, enable generation of the new accumulator and the new witness value, and enable batch updates at a semi-trusted delegate.

11. The apparatus of claim 10 , wherein the certificate authority is enabled to monitor activity of the semi-trusted delegate with respect to at least generation of the new witness value and revoke the semi-trusted delegate based on irregularities associated with generation of the new witness value.

12. The apparatus of claim 10 , wherein the semi-trusted delegate is enabled to generate witness values to provide proof of membership or non-membership using a zero-knowledge proof mechanism.

Assignments (10)
PATENT SECURITY AGREEMENT Recorded Apr 22, 2023
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 063429/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2015
From: NOKIA CORPORATION
To: NOKIA TECHNOLOGIES OY
Reel/Frame 035468/0384 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2013
From: MASHATAN, ATEFEH; AAD, IMAD; CHAABOUNI, RAFIK; NIEMI, PENTTI VALTTERI; VAUDENAY, SERGE
To: NOKIA CORPORATION
Reel/Frame 030327/0547 →