IP Library › Granted Patent US 11,283,630
Granted Patent B2
US 11,283,630 · App. 16/674,954 · Granted Mar 22, 2022

Server/server certificates exchange flow

Inventors: Erez Alexander Theodorou (Petah Tikva, IL); Amalia Avraham (Petah Tikva, IL); Eran Tzabari (Tel Aviv, IL)
Assignee: International Business Machines Corporation
H04L9/3268H04L63/08H04L63/168
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,283,630
App. No.
16/674,954
Granted
Mar 22, 2022
Kind
B2
Abstract

Embodiments herein describe providing a certificate signed by a local CA to an unauthenticated server rather than obtaining a certificated signed by a third-party CA. A server that already has a certificate that was signed by a third-party CA may want to establish secure connection with an unauthenticated server which does not have a signed certificate. The unauthenticated server needs a certificate signed by a CA trusted by the server that already has a signed certificate (referred to herein as the authenticated server). To do so, the unauthenticated server sends login credentials to the authenticated server so that this server knows it can trust the unauthenticated server. In turn, the authenticated server can send its signed certificate to the unauthenticated server so it can verify the authenticated server. Once verified, the authenticated server generates a signed certificate for the unauthenticated server using a local CA.

Claims (35)

1. A method, comprising:

transmitting a signed certificate of an authenticated server from the authenticated server to an unauthenticated server, wherein the signed certificate is generated by a first certificate authority (CA) that is operated by an entity that is different from an entity that operates the authenticated server;

after the unauthenticated server verifies the signed certificate of the authenticated server, receiving, at the authenticated server, a login credential from the unauthenticated server;

in response to the authenticated server verifying the login credential, generating a new certificate for the unauthenticated server using a local CA that is operated by the entity that operates the authenticated server; and

transmitting the new certificate to the unauthenticated server.

2. The method of claim 1 , wherein at least one of: (i) the local CA executes on the authenticated server or (ii) the local CA executes on a separate computing system and is shared by a plurality of authenticated servers operated by the same entity.

3. The method of claim 1 , wherein the signed certificate was signed by a third-party CA before receiving the login credential from the unauthenticated server.

4. The method of claim 1 , further comprising receiving a request from the unauthenticated server to generate the new certificate, wherein the request indicates that the unauthenticated server has determined that the signed certificate was signed by a trusted CA.

5. The method of claim 1 , further comprising after transmitting the new certificate to the unauthenticated server, establishing a secure connection to the unauthenticated server by exchanging the signed certificate and the new certificate.

6. The method of claim 5 , wherein establishing the secure connection comprises performing a secure sockets layer (SSL) handshake, wherein the secure connection is a SSL connection.

7. A computing system, comprising:

a local certificate authority (CA); and

an authenticated server, wherein the authenticated server is configured to:

receive a signed certificate from an unauthenticated server, wherein the signed certificate is generated by a first certificate authority (CA) that is operated by an entity that is different from an entity that operates the authenticated server;

after verifying the signed certificate, receive a login credential from the unauthenticated server;

receive a new certificate for the unauthenticated server, wherein the new certificate is generated by the local CA in response to the authenticated server verifying the login credential, wherein the local CA is operated by the entity that operates the authenticated server; and

transmit the new certificate to the unauthenticated server.

8. The computing system of claim 7 , wherein at least one of: (i) the local CA executes on the authenticated server or (ii) the local CA executes on an a separate server in the computing system and is shared by a plurality of authenticated servers operated by the same entity.

9. The computing system of claim 7 , wherein the signed certificate was signed by a third-party CA that verifies an identify of the authenticated server.

10. The computing system of claim 7 , wherein the authenticated server is further configured to receive a request from the unauthenticated server to generate the new certificate, wherein the request indicates that the unauthenticated server has determined that the signed certificate was signed by a trusted CA.

11. An unauthenticated server, comprising:

a processor; and

memory, wherein the memory stores one or more programs that, when executed by the processor, perform an operation, the operation comprises:

verifying a signed certificate from an authenticated server, wherein the signed certificate is generated by a first certificate authority (CA) that is operated by an entity that is different from an entity that operates the authenticated server;

after verifying the signed certificate, transmitting a login credential to an authenticated server;

after the authenticated server verifies the login credential, requesting a new certificate from the authenticated server; and

receiving the new certificate, wherein the new certificate is signed by a local CA that is operated by the entity that operates the authenticated server.

12. The unauthenticated server of claim 11 , wherein the signed certificate was signed by a third-party CA before the authenticated server transmitted the login credential to the authenticated server.

13. The unauthenticated server of claim 11 , wherein the operation further comprises terminating a connection with the authenticated server after receiving the new certificate.

14. The unauthenticated server of claim 11 , wherein the operation further comprises:

installing the new certificate; and

restarting a service hosted by the unauthenticated server.

15. The unauthenticated server of claim 11 , wherein verifying the signed certificate comprises comparing a CA corresponding to the signed certificate to a list of trusted CAs stored in the unauthenticated server.

16. The unauthenticated server of claim 11 , the operation further comprises after receiving the new certificate, establishing a secure connection to the authenticated server by exchanging the signed certificate and the new certificate.

17. The unauthenticated server of claim 16 , wherein establishing the secure connection further comprises performing a SSL handshake, wherein the secure connection is a SSL connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2019
From: THEODOROU, EREZ ALEXANDER; AVRAHAM, AMALIA; TZABARI, ERAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 050922/0900 →
Continuity (1)
Related Publication 20210135884A1 · May 6, 2021