Patent · US Active

Exchange of digital certificates in a client-proxy-server network configuration

US9565180B2 · kind B2 · utility

21Cited by
2References
11Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 28, 2012
Grant dateFeb 7, 2017
Priority date
Expiry dateJan 22, 2034

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2209/76
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Various techniques are described to authenticate the identity of a proxy in a client-proxy-server configuration. The configuration may have a client-side and a server-side SSL session. In the server-side session, if the proxy has access to the private keys of the client, the proxy may select a client certificate from a collection of client certificates and send the selected certificate to the server to satisfy a client authentication request of the server. If the proxy does not have access to the private keys, the proxy may instead send an emulated client certificate to the server. Further, the client certificate received from the client may be embedded within the emulated client certificate so as to allow the server to directly authenticate the client, in addition to the proxy. An emulated client certificate chain may be formed instead of an emulated client certificate. Similar techniques may be applied to the client-side session.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.