Just in time trust establishment and propagation
First Claim
1. A computer implemented method for propagating trust relationships between components across multiple domains in at least one online service system, the method comprising the steps of:
- establishing a trust relationship directly between a first master server of a first domain in an online service system and a second master server of a second domain in the online service system, wherein the trust relationship is established between public key infrastructures of different domains, and wherein the first master server manages components in the first domain and the second master server manages components in the second domain;
receiving a certificate, by a first computer system in the first domain in the online service system under management of the first master server, of a second computer system in the second domain in the online service system under management of the second master server;
attempting to validate the certificate, by the first computer system in the first domain;
determining, by the first computer system, that a trust relationship does not exist between the first computer system in the first domain and the second computer system in the second domain;
responsive to determining that a trust relationship does not exist between the first computer system in the first domain and the second computer system in the second domain, determining, by the first computer system, whether a trust relationship exists between the first master server of the first domain and the second master server of the second domain, based on an inquiry to a public key infrastructure system of the master server of the first domain;
propagating, by the first computer system, a trust status between the first domain and the second domain to the first computer system in the first domain; and
determining, by the first computer system, whether to validate the certificate of the second computer system responsive to the propagated trust status;
wherein propagating, by the first computer system, the trust status between the first domain and the second domain to the first computer system in the first domain further comprises;
receiving, by the first computer system, trust relationships of a public key infrastructure system of the first domain; and
extending, by the first computer system, the received trust relationships of the public key infrastructure system of the first domain to the first computer system in the first domain.
8 Assignments
0 Petitions
Accused Products
Abstract
Trust relationships in an online service system are established at a domain level, and propagated to components of domains as they attempt cross domain communication. In attempting to communicate across domains, a first component in a first domain attempts to validate a certificate of a second component in a second domain. Where the attempt to validate the certificate indicates that a trust relationship does not exist between the first component and the second domain, the first component determines whether a domain level trust relationship exists between the two domains. The first component propagates the trust status between the first and second domains to itself. If there is an existing trust relationship between the first and second domains, the first component validates the certificate of the second component in response. The second component executes the same process to complete the connection.
25 Citations
17 Claims
-
1. A computer implemented method for propagating trust relationships between components across multiple domains in at least one online service system, the method comprising the steps of:
-
establishing a trust relationship directly between a first master server of a first domain in an online service system and a second master server of a second domain in the online service system, wherein the trust relationship is established between public key infrastructures of different domains, and wherein the first master server manages components in the first domain and the second master server manages components in the second domain; receiving a certificate, by a first computer system in the first domain in the online service system under management of the first master server, of a second computer system in the second domain in the online service system under management of the second master server; attempting to validate the certificate, by the first computer system in the first domain; determining, by the first computer system, that a trust relationship does not exist between the first computer system in the first domain and the second computer system in the second domain; responsive to determining that a trust relationship does not exist between the first computer system in the first domain and the second computer system in the second domain, determining, by the first computer system, whether a trust relationship exists between the first master server of the first domain and the second master server of the second domain, based on an inquiry to a public key infrastructure system of the master server of the first domain; propagating, by the first computer system, a trust status between the first domain and the second domain to the first computer system in the first domain; and determining, by the first computer system, whether to validate the certificate of the second computer system responsive to the propagated trust status; wherein propagating, by the first computer system, the trust status between the first domain and the second domain to the first computer system in the first domain further comprises; receiving, by the first computer system, trust relationships of a public key infrastructure system of the first domain; and extending, by the first computer system, the received trust relationships of the public key infrastructure system of the first domain to the first computer system in the first domain. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. At least one non-transitory computer readable storage medium storing a computer program product for propagating trust relationships between components across multiple domains in at least one online service system, the computer program product comprising:
-
program code for establishing a trust relationship directly between a first master server of a first domain in an online service system and a second master server of a second domain in the online service system, wherein the trust relationship is established between public key infrastructures of different domains, and wherein the first master server manages components in the first domain and the second master server manages components in the second domain; program code for receiving a certificate, by a first computer system in the first domain in the online service system under management of the first master server, of a second computer system in the second domain in the online service system under management of the second master server; program code for attempting to validate the certificate, by the first computer system in the first domain; program code for determining, by the first computer system, that a trust relationship does not exist between the first computer system in the first domain and the second computer system in the second domain; program code for, responsive to determining that a trust relationship does not exist between the first master server of the first domain and the second master server of the second domain, based on an inquiry to a public key infrastructure system of the master server of the first domain; program code for propagating, by the first computer system, a trust status between the first domain and the second domain to the first computer system in the first domain; and program code for determining, by the first computer system, whether to validate the certificate of the second computer system responsive to the propagated trust status; wherein propagating, by the first computer system, the trust status between the first domain and the second domain to the first computer system in the first domain further comprises; receiving, by the first computer system, trust relationships of a public key infrastructure system of the first domain; and extending, by the first computer system, the received trust relationships of the public key infrastructure system of the first domain to the first computer system in the first domain. - View Dependent Claims (11, 12, 13, 14, 15, 16, 17)
-
Specification