Identity-based certificate management
First Claim
Patent Images
1. A method performed by a computer system for validating a digital certificate issued to a client system and associated with a specific client identity, the method comprising:
- receiving the digital certificate from the client system, the digital certificate including a user identifier and a certificate validity period identifier, the user identifier corresponding to the specific client identity;
generating a first query to a directory service having a plurality of entries each associated with different client identities, the first query including a request for a first entry associated with the specific client identity, the first entry including a directory validity time value for the specific client identity;
receiving the directory validity time value returned by the directory service in response to the first query; and
validating the digital certificate in response to determining that a certificate validity period specified by the certificate validity period identifier is later than the received directory validity time value.
10 Assignments
0 Petitions
Accused Products
Abstract
Methods for managing digital certificates, including issuance, validation, and revocation are disclosed. Various embodiments involve querying a directory service with entries that correspond to a particular client identity and have attributes including certificate issuance limits and certificate validity time values. The validity time values are adjustable to revoke selectively the certificates based upon time intervals set forth in validity identifiers included therein.
-
Citations
20 Claims
-
1. A method performed by a computer system for validating a digital certificate issued to a client system and associated with a specific client identity, the method comprising:
-
receiving the digital certificate from the client system, the digital certificate including a user identifier and a certificate validity period identifier, the user identifier corresponding to the specific client identity; generating a first query to a directory service having a plurality of entries each associated with different client identities, the first query including a request for a first entry associated with the specific client identity, the first entry including a directory validity time value for the specific client identity; receiving the directory validity time value returned by the directory service in response to the first query; and validating the digital certificate in response to determining that a certificate validity period specified by the certificate validity period identifier is later than the received directory validity time value. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20)
-
Specification