Patent · US Active

Establishing PKI chain of trust in air gapped cloud

US12143506B2 · kind B2 · utility

0Cited by
6References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJan 26, 2022
Grant dateNov 12, 2024
Priority date
Expiry dateJan 2, 2043

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L9/3268
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Technology is shown for establishing a chain of trust for an unknown root certificate in an isolated network that is verified using a chain of trust external to the network. A bootstrap executable and a leaf certificate rooted in the external chain of trust are configured with an OID. The leaf certificate is received in the isolated network and used to sign a new root certificate created in the isolated network to create a blob that is stored in a pre-determined location. The bootstrap executable is executed to instantiate a client machine, which retrieves the blob and verifies its signature using the leaf certificate. The client machine verifies that the OID values from the blob and bootstrap executable match. If the signature and OID checks are successful, then the new root certificate is distributed within the isolated network and installed in a PKI certificate chain of trust.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.