×

Just in time trust establishment and propagation

  • US 8,904,169 B2
  • Filed: 09/15/2009
  • Issued: 12/02/2014
  • Est. Priority Date: 09/15/2009
  • Status: Active Grant
First Claim
Patent Images

1. A computer implemented method for propagating trust relationships between components across multiple domains in at least one online service system, the method comprising the steps of:

  • establishing a trust relationship directly between a first master server of a first domain in an online service system and a second master server of a second domain in the online service system, wherein the trust relationship is established between public key infrastructures of different domains, and wherein the first master server manages components in the first domain and the second master server manages components in the second domain;

    receiving a certificate, by a first computer system in the first domain in the online service system under management of the first master server, of a second computer system in the second domain in the online service system under management of the second master server;

    attempting to validate the certificate, by the first computer system in the first domain;

    determining, by the first computer system, that a trust relationship does not exist between the first computer system in the first domain and the second computer system in the second domain;

    responsive to determining that a trust relationship does not exist between the first computer system in the first domain and the second computer system in the second domain, determining, by the first computer system, whether a trust relationship exists between the first master server of the first domain and the second master server of the second domain, based on an inquiry to a public key infrastructure system of the master server of the first domain;

    propagating, by the first computer system, a trust status between the first domain and the second domain to the first computer system in the first domain; and

    determining, by the first computer system, whether to validate the certificate of the second computer system responsive to the propagated trust status;

    wherein propagating, by the first computer system, the trust status between the first domain and the second domain to the first computer system in the first domain further comprises;

    receiving, by the first computer system, trust relationships of a public key infrastructure system of the first domain; and

    extending, by the first computer system, the received trust relationships of the public key infrastructure system of the first domain to the first computer system in the first domain.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×