×

Server authentication using multiple authentication chains

  • US 10,171,452 B2
  • Filed: 03/31/2016
  • Issued: 01/01/2019
  • Est. Priority Date: 03/31/2016
  • Status: Active Grant
First Claim
Patent Images

1. A method to authenticate a server to a client, the server having an associated public key, comprising:

  • associating “

    n”

    distinct certificates to the server'"'"'s public key, each of the “

    n”

    distinct certificates being issued by a distinct certificate authority (CA), wherein each of the distinct certificates has a certification chain with a different root certificate authority, wherein the certificate chains for the “

    n”

    distinct certificates are valid and non-overlapping with respect to their intermediate and root CAs;

    responsive to the client initiating a request for a secure channel to the server during a cryptographic handshake, providing the client the “

    n”

    distinct certificates; and

    responsive to receipt from the client of an indication that the public key satisfies a client public key acceptance policy, establishing completing the cryptographic handshake to establish the secure channel between the client and the server;

    the client public key acceptance policy specifying a required number of valid, non-overlapping certificate chains that must be present to satisfy a client threshold level of trust to thereby improve security of the cryptographic handshake.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×