Invention Grant
- Patent Title: Partitioning certificate revocation lists
-
Application No.: US15851562Application Date: 2017-12-21
-
Publication No.: US10911246B2Publication Date: 2021-02-02
- Inventor: Hari Veladanda , Hoa Ly , Ning Chai
- Applicant: DigiCert, Inc.
- Applicant Address: US UT Lehi
- Assignee: DigiCert, Inc.
- Current Assignee: DigiCert, Inc.
- Current Assignee Address: US UT Lehi
- Agency: Knobbe, Martens, Olson & Bear, LLP
- Main IPC: H04L9/32
- IPC: H04L9/32 ; H04L29/06

Abstract:
Certificates issued by a CA are distributed across multiple CRLs. Each certificate issued by the CA is assigned to a specific CRL, and the address of that CRL is written to the appropriate field of the certificate, such that an authenticating application can subsequently determine if the certificate is revoked. When the CA revokes a specific one of the issued certificates, it determines to which CRL the revoked certificate is assigned, and updates the specific CRL accordingly. In some embodiments, a single one of the multiple CRLs is active for assignment of certificates at any given time, and each certificate issued by the CA is assigned to the currently active CRL. In other embodiments, assignments of issued certificates are distributed between different ones of a pre-determined number of multiple CRLs by applying a statistical distribution formula to each issued certificate to determine a corresponding target CRL.
Public/Granted literature
- US20180123805A1 PARTITIONING CERTIFICATE REVOCATION LISTS Public/Granted day:2018-05-03
Information query