Invention Grant
- Patent Title: Server authentication using multiple authentication chains
-
Application No.: US15087486Application Date: 2016-03-31
-
Publication No.: US10171452B2Publication Date: 2019-01-01
- Inventor: Dimitrios Pendarakis , Enriquillo Valdez
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Jeffrey S. LaBaw; David H. Judson
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A client seeking to establish a cryptographically-secure channel to a server has an associated public key acceptance policy. The policy specifies a required number of certificates that must be associated with the server's public key, as well as one or more conditions associated with those certificates, that must be met before the client “accepts” the server's public key. The one or more conditions typically comprise a trust function that must be satisfied before a threshold level of trust of the client is met. A representative public key acceptance policy would be that certificate chains for the public key are valid and non-overlapping with different root CAs, and that some configurable number of those chains be present. The technique may be implemented within the context of an existing client-server SSL/TLS handshake.
Public/Granted literature
- US20170289137A1 Server authentication using multiple authentication chains Public/Granted day:2017-10-05
Information query