IP Library › Granted Patent US 9,038,159
Granted Patent B2
US 9,038,159 · App. 13/691,949 · Granted May 19, 2015

Authentication system

Inventors: Karmaveer R. Koonjbearry (Flower Mound, TX); Velamur Srinivasan Sudharsan (Flower Mound, TX)
Assignee: Verizon Patent and Licensing Inc.
H04L63/0823H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,038,159
App. No.
13/691,949
Granted
May 19, 2015
Kind
B2
Abstract

A user device is configured to request a secure web page from a web page server. The user device is further configured to receive a certificate from the web page server, the certificate including a serial number. The user device is further configured to receive different certificates from a plurality of certificate authentication servers. The user device is further configured to compare the different certificates to the certificate received from the web page server; determine that the certificate is valid; and send information to the web page server based on determining that the certificate is valid.

Claims (92)

1. A device comprising:

one or more processors to:

request a secure web page from a web page server;

receive a certificate from the web page server based on requesting the secure web page,

the certificate including a serial number;

send the serial number to a plurality of certificate authentication servers,

the plurality of certificate authentication servers being different certificate authentication servers;

receive different certificates from the plurality of certificate authentication servers based on sending the serial number to the plurality of certificate authentication servers;

compare the different certificates to the certificate received from the web page server;

determine that the certificate is valid when at least one of the different certificates, from the plurality of certificate authentication servers, matches the certificate received from the web page server; and

send information to the web page server based on determining that the certificate is valid.

2. The device of claim 1 , where the certificate received from the web page server includes ownership information, and

where the one or more processors, when receiving the different certificates from the plurality of certificate authentication servers, are further to:

receive at least one of the different certificates that includes the ownership information.

3. The device of claim 1 , where the certificate received from the web page server includes valid time period information, and

where the one or more processors, when receiving the different certificates from the plurality of certificate authentication servers, are further to:

receive at least one of the different certificates that includes the valid time period information.

4. The device of claim 1 , where the certificate received from the web page server further includes at least one of first ownership information, or a first valid time period, and

where at least one certificate, of the different certificates, corresponds to a dummy certificate,

the dummy certificate including the serial number and at least one of second ownership information or a second valid time period,

the second ownership information being different than the first ownership information, and

the second valid time period being different than the first valid time period.

5. The device of claim 1 , where the one or more processors are further to:

create a secret key based on determining that the certificate is valid;

send the secret key to the web page server;

receive a message from the web page server that is encrypted with the secret key; and

use the secret key to decrypt the message received from the web page server.

6. The device of claim 1 , where the one or more processors, when requesting the secure web page from the web page server, are further to:

request the secure web page using secure socket layer protocol.

7. The device of claim 1 , where the one or more processors are further to:

request a second secure web page from a second web page server,

the second web page server being different than the web page server;

receive a second certificate from the second web page server, based on requesting the second secure web page,

the second certificate being associated with a second serial number;

send the second serial number to the plurality of certificate authentication servers;

receive additional certificates from the plurality of certificate authentication servers, based on sending the second serial number to the plurality of certificate authentication servers;

compare the additional certificates with the second certificate;

determine that the second certificate is invalid when the additional certificates do not match the second certificate received from the second web page server; and

display a warning message based on determining that the second certificate is invalid.

8. The device of claim 7 , where the warning message includes an option to continue communication with the second web page server.

9. The device of claim 7 , where the one or more processors are further to:

terminate communications with the second web page server based on determining that the second certificate is invalid.

10. A method comprising:

requesting, by a user device, a secure web page from a web page server;

receiving, by the user device, a certificate from the web page server based on requesting the secure web page,

the certificate including a serial number;

sending, by the user device, the serial number to a plurality of certificate authentication servers,

the plurality of certificate authentication servers being different certificate authentication servers;

receiving, by the user device, different certificates from the plurality of certificate authentication servers based on sending the serial number to each of the plurality of certificate authentication servers;

determining, by the user device, that the certificate is valid when at least one of the different certificates, from the plurality of certificate authentication servers, matches the certificate received from the web page server; and

sending, by the user device, a message to the web page server based on the certificate being valid.

11. The method of claim 10 , where sending the serial number to the plurality of certificate authentication servers includes:

sending the serial number to the plurality of certificate authentication servers based on information, stored by the user device, regarding the plurality of certificate authentication servers.

12. The method of claim 10 , where receiving the different certificates from the plurality of certificate authentication servers includes:

receiving one or more dummy certificates from one or more of the plurality of certificate authentication servers,

the one or more dummy certificates having information that does not match information in the certificate received from the web page server.

13. The method of claim 10 , where the certificate, received from the web page server, includes an identifier of at least one certificate authentication server of the plurality of certificate authentication servers.

14. The method of claim 10 , further comprising:

creating a secret key based on determining that the certificate is valid; and

sending at least one message, to the web page server, that is encrypted with the secret key.

15. A non-transitory computer-readable medium for storing instructions, the instructions comprising:

a plurality of instructions, that when executed by one or more processors of a user device, cause the one or more processors to:

request a secure web page from a web page server;

receive a certificate from the web page server based on requesting the certificate,

the certificate including first information;

send the first information to a plurality of certificate authentication servers,

the plurality of certificate authentication servers being different certificate authentication servers;

receive different certificates from the plurality of certificate authentication servers based on sending the first information to the plurality of certificate authentication servers;

compare the different certificates to the certificate received from the web page server;

determine that the certificate is valid when at least one of the different certificates, from the plurality of certificate authentication servers, matches the certificate received from the web page server; and

send information to the web page server based on determining that the certificate is valid.

16. The non-transitory computer-readable medium of claim 15 , where the one or more instructions, that cause the one or more processors to receive the different certificates from the plurality of certificate authentication servers, further cause the one or more processors to:

receive at least one dummy certificate,

the dummy certificate including the first information and additional information,

the additional information being different than information in the certificate received from the web page server.

17. The non-transitory computer-readable medium of claim 15 , where the one or more instructions, that cause the one or more processors to receive the different certificates from the plurality of certificate authentication servers, further cause the one or more processors to:

receive at least one of the different certificates that includes valid time period information that matches valid time period information of the certificate.

18. The non-transitory computer-readable medium of claim 15 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

create a secret key based on determining that the certificate is valid; and

send at least one message, to the web page server, that is encrypted with the secret key.

19. The non-transitory computer-readable medium of claim 15 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

request a second certificate from a second web page server,

the second certificate being different than the certificate received from the web page server, and

the second web page server being different than the web page server;

receive the second certificate from the second web page server, based on requesting the second certificate, the second certificate including second information;

send the second information to the plurality of certificate authentication servers;

receive additional certificates from the plurality of certificate authentication servers;

compare the additional certificates with the second certificate;

determine that the second certificate is invalid when the different certificates from the plurality of certificate authenticate servers do not match the certificate received from the web page server; and

display a warning message based on determining that the second certificate is invalid.

20. The non-transitory computer-readable medium of claim 19 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

terminate communications with the second web page server based on determining that the second certificate is invalid.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2012
From: KOONJBEARRY, KARMAVEER R.; SUDHARSAN, VELAMUR SRINIVASAN
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 029390/0531 →
Continuity (1)
Related Publication 20140157394A1 · Jun 5, 2014