IP Library Granted Patent US 9,654,298
Granted Patent B2
US 9,654,298 · App. 15/251,220 · Granted May 16, 2017

Signature # efficient real time credentials for OCSP and distributed OCSP

Inventors: David Engberg (San Francisco, CA); Phil Libin (San Francisco, CA); Silvio Micali (Brookline, MA)
Assignee: Assa Abloy AB
H04L9/3268H04L63/0823H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,654,298
App. No.
15/251,220
Granted
May 16, 2017
Kind
B2
Abstract

Providing information about digital certificate validity includes ascertaining digital certificate validity status for each of a plurality of digital certificates in a set of digital certificates, generating a plurality of artificially pre-computed messages about the validity status of at least a subset of the set of digital certificate of the plurality of digital certificates, where at least one of the messages indicates validity status of more than one digital certificate and digitally signing the artificially pre-computed messages to provide OCSP format responses that respond to OCSP queries about specific digital certificates in the set of digital certificates, where at least one digital signature is used in connection with an OCSP format response for more than one digital certificate. Generating and digitally signing may occur prior to any OCSP queries that are answered by any of the OCSP format responses. Ascertaining digital certificate validity status may include obtaining authenticated information about digital certificates.

Claims (25)

1. A method of providing information about digital certificate validity from a server having at least one computer processor, comprising:

the server using the at least one computer processor to receive, from an other server, digital signatures of artificially pre-computed messages to provide OCSP (Online Certificate Status Protocol) format responses that respond to OCSP queries about specific digital certificates in the set of digital certificates, wherein the other server uses at least one computer processor to generate the plurality of artificially pre-computed messages about the validity status of at least a subset of the set of digital certificates of the plurality of digital certificates after ascertaining digital certificate validity status for each of a plurality of digital certificates in a set of digital certificates;

the server using the at least one computer processor to receive a request for validity status of at least one digital certificate; and

the server using the at least one computer processor to respond to the request by providing at least one of the artificially pre-computed messages that have been digitally signed, wherein no secret keys are stored on the server and wherein generating and digitally signing pre-computed messages to provide OCSP format responses occur prior to any OCSP queries that are answered by any of the OCSP format responses.

2. The method, according to claim 1 , wherein ascertaining digital certificate validity status includes obtaining authenticated information about digital certificates.

3. The method, according to claim 2 , wherein the authenticated information about digital certificates is generated by an entity that also revokes certificates.

4. The method, according to claim 2 , wherein the authenticated information about digital certificates is a CRL (Certificate Revocation List).

5. The method, according to claim 1 , wherein responses are generated for at least all non-revoked digital certificates in the set of digital certificates.

6. The method, according to claim 1 , further comprising:

making available to the servers a special digital certificate containing a public verification key used to verify the digital signatures provided in connection with digitally signing the artificially pre-computed messages.

7. The method, according to claim 6 , wherein an entity that issues the special digital certificate also issues certificates of the set of digital certificates.

8. The method, according to claim 1 , wherein generating a plurality of artificially pre-computed messages and digitally signing the artificially pre-computed messages are performed at given time intervals.

9. The method, according to claim 8 , wherein the artificially pre-computed messages include time information corresponding to when the artificially pre-computed messages were generated.

10. A non-transitory computer-readable storage medium storing computer software that provides information about digital certificate validity, the computer software comprising:

executable code that, when executed on a computer processor of a server, receives, from an other server, digital signatures of artificially pre-computed messages to provide OCSP (Online Certificate Status Protocol) format responses that respond to OCSP queries about specific digital certificates in the set of digital certificates, wherein the other server uses at least one computer processor to generate the plurality of artificially pre-computed messages about the validity status of at least a subset of the set of digital certificates of the plurality of digital certificates after ascertaining digital certificate validity status for each of a plurality of digital certificates in a set of digital certificates;

executable code that, when executed on a computer processor, receives a request for validity status of at least one digital certificate; and

executable code that, when executed on a computer processor, responds to the request by providing at least one of the artificially pre-computed messages that have been digitally signed, wherein no secret keys are stored on the server and wherein generating and digitally signing pre-computed messages to provide OCSP format responses occur prior to any OCSP queries that are answered by any of the OCSP format responses.

11. The computer-readable storage medium, according to claim 10 , wherein ascertaining digital certificate validity status includes obtaining authenticated information about digital certificates.

12. The computer-readable storage medium, according to claim 11 , wherein the authenticated information about digital certificates is generated by an entity that also revokes certificates.

13. The computer-readable storage medium according to claim 11 , wherein the authenticated information about digital certificates is a CRL (Certificate Revocation List).

14. The computer-readable storage medium, according to claim 10 , wherein responses are generated for at least all non-revoked digital certificates in the set of digital certificates.

15. The computer-readable storage medium, according to claim 10 , further comprising:

executable code that makes available to the server a special digital certificate containing a public verification key used to verify the digital signatures provided in connection with digitally signing the artificially pre-computed messages.

16. The computer-readable storage medium, according to claim 15 , wherein an entity that issues the special digital certificate also issues certificates of the set of digital certificates.

17. The computer-readable storage medium, according to claim 10 , wherein the other server generates and signs the OCSP format responses at given time intervals.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2016
From: ENGBERG, DAVID; LIBIN, PHIL; MICALI, SILVIO
To: CORESTREET, LTD.
Reel/Frame 039582/0597 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2016
From: CORESTREET, LTD.
To: ASSA ABLOY AB
Reel/Frame 039582/0722 →
Continuity (5)
Continuation 14703176 · May 4, 2015
Continuation 11036220 · Jan 10, 2005
Provisional Application 60536817 · Jan 15, 2004
Provisional Application 60535666 · Jan 9, 2004
Related Publication 20160373432A1 · Dec 22, 2016