Signature-efficient real time credentials for OCSP and distributed OCSP
Abstract
Providing information about digital certificate validity includes ascertaining digital certificate validity status for each of a plurality of digital certificates in a set of digital certificates, generating a plurality of artificially pre-computed messages about the validity status of at least a subset of the set of digital certificate of the plurality of digital certificates, where at least one of the messages indicates validity status of more than one digital certificate and digitally signing the artificially pre-computed messages to provide OCSP format responses that respond to OCSP queries about specific digital certificates in the set of digital certificates, where at least one digital signature is used in connection with an OCSP format response for more than one digital certificate. Generating and digitally signing may occur prior to any OCSP queries that are answered by any of the OCSP format responses. Ascertaining digital certificate validity status may include obtaining authenticated information about digital certificates.
Claims
exact text as granted — not AI-modified1 . A method of providing information about digital certificate validity, comprising:
ascertaining digital certificate validity status for each of a plurality of digital certificates in a set of digital certificates; generating a plurality of artificially pre-computed messages about the validity status of at least a subset of the set of digital certificate of the plurality of digital certificates, wherein at least one of the messages indicates validity status of more than one digital certificate; and digitally signing the artificially pre-computed messages to provide OCSP format responses that respond to OCSP queries about specific digital certificates in the set of digital certificates, wherein at least one digital signature is used in connection with an OCSP format response for more than one digital certificate.
2 . A method, according to claim 1 , wherein generating and digitally signing occur prior to any OCSP queries that are answered by any of the OCSP format responses.
3 . A method, according to claim 1 , wherein ascertaining digital certificate validity status includes obtaining authenticated information about digital certificates.
4 . A method, according to claim 3 , wherein the authenticated information about digital certificates is generated by an entity that also revokes certificates.
5 . A method, according to claim 3 , wherein the authenticated information about digital certificates is a CRL.
6 . A method, according to claim 1 , wherein generating a plurality of artificially pre-computed responses includes generating responses for at least all non-revoked digital certificates in the set of digital certificates.
7 . A method, according to claim 1 , further comprising:
after digitally signing the artificially pre-computed messages, forwarding the result thereof to a plurality of responders that service requests by relying parties inquiring about the validity status of digital certificates in the set of digital certificates.
8 . A method, according to claim 7 , further comprising:
making available to the responders a special digital certificate containing a public verification key used to verify the digital signatures provided in connection with digitally signing the artificially pre-computed responses.
9 . A method, according to claim 8 , wherein an entity that issues the special digital certificate also issues certificates of the set of digital certificates.
10 . A method, according to claim 1 , wherein generating a plurality of artificially pre-computed responses and digitally signing the artificially pre-computed responses are performed periodically.
11 . A method, according to claim 10 , wherein the artificially pre-computed responses include time information corresponding to when the artificially pre-computed responses were generated.
12 . Computer software, stored in a computer readable medium, that provides information about digital certificate validity, comprising:
executable code that ascertains digital certificate validity status for each of a plurality of digital certificates in a set of digital certificates; executable code that generates a plurality of artificially pre-computed messages about the validity status of at least a subset of the set of digital certificate of the plurality of digital certificates, wherein at least one of the messages indicates validity status of more than one digital certificate; and executable code that digitally signs the artificially pre-computed messages to provide OCSP format responses that respond to OCSP queries about specific digital certificates in the set of digital certificates, wherein at least one digital signature is used in connection with an OCSP format response for more than one digital certificate.
13 . Computer software, according to claim 12 , wherein executable code that ascertains digital certificate validity status includes executable code that obtains authenticated information about digital certificates.
14 . Computer software, according to claim 13 , wherein the authenticated information about digital certificates is generated by an entity that also revokes certificates.
15 . Computer software, according to claim 13 , wherein the authenticated information about digital certificates is a CRL.
16 . Computer software, according to claim 12 , wherein executable code that generates a plurality of artificially pre-computed responses includes executable code that generates responses for at least all non-revoked digital certificates in the set of digital certificates.
17 . Computer software, according to claim 12 , further comprising:
executable code that forwards digitally signed the artificially pre-computed messages to a plurality of responders that service requests by relying parties inquiring about the validity status of digital certificates in the set of digital certificates.
18 . Computer software, according to claim 17 , further comprising:
executable code that makes available to the responders a special digital certificate containing a public verification key used to verify the digital signatures provided in connection with digitally signing the artificially pre-computed responses.
19 . Computer software, according to claim 18 , wherein an entity that issues the special digital certificate also issues certificates of the set of digital certificates.
20 . Computer software, according to claim 12 , wherein executable code that generates a plurality of artificially pre-computed responses and digitally signs the artificially pre-computed responses generates and signs the responses periodically.Join the waitlist — get patent alerts
Track US2005154878A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.