×

Secure session capability using public-key cryptography without access to the private key

  • US 9,553,856 B2
  • Filed: 06/25/2014
  • Issued: 01/24/2017
  • Est. Priority Date: 03/07/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method in a first server for establishing a secure session with a client device where a private key used for the secure session is stored in a second server, the method comprising the first server performing the following:

  • receiving a message from the client device that initiates a procedure to establish a secure session between the client device and the first server;

    transmitting a digital certificate to the client device that includes a public key;

    generating a set of cryptographic parameters;

    transmitting, to the second server, a message that includes the set of cryptographic parameters, wherein the second server has a private key that corresponds to the public key;

    receiving from the second server, a message that includes the set of cryptographic parameters that have been signed using the private key;

    transmitting, to the client device, the set of cryptographic parameters that have been signed using the private key;

    receiving, from the client device, a value generated by the client device based in part on the set of cryptographic parameters;

    generating, using the received value and at least some of the set of cryptographic parameters, a premaster secret;

    generating a master secret using the premaster secret; and

    generating, using the generated master secret, a set of one or more session keys to be used in the secure session for encrypting and decrypting communication between the client device and the first server.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×