Patent · US Expired

Enabling stateless server-based pre-shared secrets

US7346773B2 · kind B2 · utility

30Cited by
7References
29Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJan 12, 2004
Grant dateMar 18, 2008
Priority date
Expiry dateAug 18, 2025

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L67/14
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method is disclosed for enabling stateless server-based pre-shared secrets. Based on a local key that is not known to a client, a server encrypts the client's state information. The client's state information may include, for example, the client's authentication credentials, the client's authorization characteristics, and a shared secret key that the client uses to derive session keys. By any of a variety of mechanisms, the encrypted client state information is provided to the client. The server may free memory that stored the client's state information. When the server needs the client's state information, the client sends, to the server, the encrypted state information that the client stored. The server decrypts the client state information using the local key. Because each client stores that client's own state information in encrypted form, the server does not need to store any client's state information permanently.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.