Patent · US Expired

Method and apparatus for managing trusted certificates

US6304974A · kind A · utility

80Cited by
4References
31Claims
0Family size

Assignee

Inventor

Key dates

Filing dateNov 6, 1998
Grant dateOct 16, 2001
Priority date
Expiry dateNov 6, 2018

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/0861
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

The present invention provides a system for managing trusted certificates for authenticating communications for clients belonging to an enterprise. The system assembles a list of trusted certificates containing public keys for authenticating communications signed by associated private keys. This assembly process may include verifying the authenticity of trusted certificates in the list. The system then constructs a fingerprint for the list. The list is then communicated to a client through a first communication mechanism, and the fingerprint is communicated to the client through a second communication mechanism. Next, the client verifies that the fingerprint received through the second communication mechanism was constructed from the list of trusted certificates received through the first communication mechanism. This establishes a high degree of confidence that the list of trusted certificates is authentic. The client can then confidently use trusted certificates from the list to authenticate subsequent communications. Trusted certificates in the list are associated with certificate authorities that issue certificates for entities communicating across the network. Each of these tr…

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.