CA2551819C

Signature-efficient real time credentials for ocsp and distributed ocsp

Abstract

Providing information about digital certificate validity includes ascertaining digital certificate validity status for each of a plurality of digital certificates in a set of digital certificates, generating a plurality of artificially pre-computed messages about the validity status of at least a subset of the set of digital certificate of the plurality of digital certificates, where at least one of the messages indicates validity status of more than one digital certificate and digitally signing the artificially pre-computed messages to provide OCSP format responses that respond to OCSP queries about specific digital certificates in the set of digital certificates, where at least one digital signature is used in connection with an OCSP format response for more than one digital certificate. Generating and digitally signing may occur prior to any OCSP queries that are answered by any of the OCSP format responses. Ascertaining digital certificate validity status may include obtaining authenticated information about digital certificates.

CA2551819C, drawing sheet 1
Sheet 1 of 20

Term

Term ended

Expired 10 January 2025, 1.7 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

45 claims: 6 independent, 39 dependent

  1. 1
    CA 02551819 2014-02-04 WO 2005/071877 PCT/US2005/000721 What is claimed is;1. A method of providing information about digital certificate validity, comprising;ascertaining validity status for each of a plurality of digital certificates in a set of digital certificates;generating a plurality of artificially pre-computed messages about the validity status of at least a subset of the set of digital certificates of the plurality of digital certificates, wherein the subset is a part of the plurality of digital certificates in the set of digital certificates;and digitally signing each of the artificially pre-computed messages to provide OCSP (Online Certificate Status Protocol) format responses that respond to OCSP queries about specific digital certificates in the set of digital certificates, wherein at least one OCSP format response includes one digital signature used to sign an artificially precomputed message that indicates the validity status of more than one digital certificate.
  2. 12
    A non-transitory computer readable storage medium storing computer software, executable by at least one processor, that provides information about digital certificate validity, the computer software comprising:executable code that ascertains validity status for each of a plurality of digital certificates in a set of digital certificates;executable code that generates a plurality of artificially pre-computed messages about the validi ty status of at least a subset of the set of digital certificate of the plurality of digital certificates, wherein the subset is a part of the plurality of digital certificates in the set of digital certificates;and 4758452.1 CA 02551819 2014-02-04 WO 2005/071877 PCT/US2005/000721 executable code that digitally signs each of the artificially pre-computed messages to provide OCSP (Online Certificate Status Protocol) format responses that respond to OCSP queries about specific digital certificates in the set of digital certificates, wherein at least one OCSP format response includes one digital signature used to sign an artificially pre-computed message that indicates the validity status of more than one digital certificate.
  3. 21
    A method of providing information about digital certificate validity, comprising:obtaining a plurality of signing key/verification key pairs, wherein each signing key provides a digital signature and a corresponding one of the verification keys verifies the digital signature and wherein digitally signing together a plurality of data elements using the signing keys is computationally more efficient than digitally signing each of the data elements individually;ascertaining digital certificate validity status for each certificate in a set of digital certificates;generating a plurality of artificially pre-computed messages about the validity status of at least a subset of the set of digital certificates;and digitally signing together the plurality of artificially pre-computed messages in a batch using signing keys from the pairs, wherein digitally signing together the plurality of artificially pre-computed messages in the batch uses fewer computations than digitally signing each of the plurality of artificially pre-computed messages individually, and wherein each of the plurality of digitally-signed, artificially pre-computed messages includes a digital signature. 4758452.1 CA 02551819 2014-02-04 WO 2005/071877 PCTÆJS2005/Û00721
  4. 33
    A non-transitory computer readable storage medium storing computer software that provides information about digital certificate validity, the computer software comprising:executable code that obtains a plurality of signing key/verification key pairs, wherein each signing key provides a digital signature and a corresponding one of the verification keys verifies the digital signature and wherein digitally signing together a plurality of data elements using the signing keys is computationally more efficient than digitally signing each of the data elements individually;executable code that ascertains digital certificate validity status for each certificate in a set of digital certificates;executable code that generates a plurality of artificially pre-computed messages about the validity status of at least a subset of the set of digital certificates;and executable code that digitally signs together the plurality of artificially pre-computed messages in a batch using signing keys from the pairs, wherein digitally signing together the plurality of artificially pre-computed messages in the batch uses fewer computations than digitally signing each of the plurality of artificially pre-computed messages individually, and wherein each of the plurality of digitally-signed, artificially pre-computed messages includes a digital signature.
  5. 42
    A method of providing information about digital certificate validity, comprising:ascertaining digital certificate validity status for each certificate in a set of digital certificates;4758452.1 CA 02551819 2014-02-04 WO 2005/071877 PCT/US2005/000721 periodically generating a plurality of digitally signed artificially pre-computed messages about the validity status of at least a subset of the set of digital certificates, wherein the digitally signed artificially pre-computed messages are generated independently of a request inquiring about the validity status of the digital certificate;and periodically forwarding the digitally signed artificially pre-computed messages to a plurality of responders that service requests by relying parties inquiring about the validity status of digital certificates in the set of digital certificates, wherein messages about some certificates are forwarded at a different frequency than messages about other certificates, and wherein the digitally signed artificially pre-computed messages are forwarded to and stored on the plurality of responders independently of the requests by the relying parties inquiring about the validity status of the digital certificates.
  6. 44
    A non-transitory computer readable storage medium storing computer software, executable by at least one processor, that provides information about digital certificate validity, the computer software comprising:executable code that ascertains digital certificate validity status for each certificate in a set of digital certificates;executable code that periodically generates a plurality of digitally signed artificially pre-computed messages about the validity status of at least a subset of the set of digital certificates, wherein the digitally signed artificially pre-computed messages are generated independently of a request inquiring about the validity status of the digital certificate;and executable code that periodically forwards the digitally signed artificially pre-computed messages to a plurality of responders that service requests by relying parties inquiring about the validity status of digital certificates in the set of digital certificates, wherein messages about some certificates are forwarded at a different frequency than messages about other certificates, and wherein the digitally signed artificially pre-computed 4758452.1 CA 02551819 2014-02-04 WO 2005/071877 PCT/US2005/000721 messages are forwarded to and stored on the plurality of responders independently of the requests by the relying parties inquiring about the validity status of the digital certificates.