US20060294366A1

Method and system for establishing a secure connection based on an attribute certificate having user credentials

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A method and system is presented for supporting the establishment of a secure communication session within a data processing system. A certificate request command is sent from a server to a client. A certificate command is received at the server from the client in response to the certificate request command, and the certificate command is accompanied by a public key certificate and an attribute certificate that is digitally signed by a private key that is bound to the public key certificate. A secure communication session is established in response to successfully verifying the public key certificate. The attribute certificate contains credential information for an authentication operation or an authorization operation that is performed after establishment of the secure communication session.

US20060294366A1, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Projected expiry passed 23 June 2025, 1.3 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

33 claims: 6 independent, 27 dependent

  1. 1
    Broadest claimClaim Score 62, broad(NHIP)A method for supporting establishment of a secure communication session within a data processing system, the method comprising:sending a certificate request command from a server to a client;receiving a certificate command at the server from the client in response to the certificate request command, wherein the certificate command is accompanied by a public key certificate and an attribute certificate that is digitally signed by a private key that is bound to the public key certificate, and wherein the attribute certificate contains credential information for an authentication operation or an authorization operation that is performed after establishment of the secure communication session;and establishing the secure communication session in response to successfully verifying the public key certificate.
  2. 9
    A method for supporting establishment of a secure communication session within a data processing system, the method comprising:receiving a certificate request command at a client from a server;sending a certificate command from the client to the server in response to the certificate request command, wherein the certificate command is accompanied by a public key certificate and an attribute certificate that is digitally signed by a private key that is bound to the public key certificate, and wherein the attribute certificate contains credential information for an authentication operation or an authorization operation that is performed after establishment of the secure communication session;and receiving at the client from the server a notification that a secure communication session has been successfully established.
  3. 12
    A computer program product on a computer readable medium for use within a data processing system for supporting establishment of a secure communication session, the computer program product comprising:means for sending a certificate request command from a server to a client;means for receiving a certificate command at the server from the client in response to the certificate request command, wherein the certificate command is accompanied by a public key certificate and an attribute certificate that is digitally signed by a private key that is bound to the public key certificate, and wherein the attribute certificate contains credential information for an authentication operation or an authorization operation that is performed after establishment of the secure communication session;and means for establishing the secure communication session in response to successfully verifying the public key certificate.
  4. 20
    A computer program product on a computer readable medium for use within a data processing system for supporting establishment of a secure communication session, the computer program product comprising:means for receiving a certificate request command at a client from a server;means for sending a certificate command from the client to the server in response to the certificate request command, wherein the certificate command is accompanied by a public key certificate and an attribute certificate that is digitally signed by a private key that is bound to the public key certificate, and wherein the attribute certificate contains credential information for an authentication operation or an authorization operation that is performed after establishment of the secure communication session;and means for receiving at the client from the server a notification that a secure communication session has been successfully established.
  5. 23
    An apparatus for supporting establishment of a secure communication session within a data processing system, the apparatus comprising:means for sending a certificate request command from a server to a client;means for receiving a certificate command at the server from the client in response to the certificate request command, wherein the certificate command is accompanied by a public key certificate and an attribute certificate that is digitally signed by a private key that is bound to the public key certificate, and wherein the attribute certificate contains credential information for an authentication operation or an authorization operation that is performed after establishment of the secure communication session;and means for establishing the secure communication session in response to successfully verifying the public key certificate.
  6. 31
    An apparatus for supporting establishment of a secure communication session within a data processing system, the apparatus comprising:means for receiving a certificate request command at a client from a server;means for sending a certificate command from the client to the server in response to the certificate request command, wherein the certificate command is accompanied by a public key certificate and an attribute certificate that is digitally signed by a private key that is bound to the public key certificate, and wherein the attribute certificate contains credential information for an authentication operation or an authorization operation that is performed after establishment of the secure communication session;and means for receiving at the client from the server a notification that a secure communication session has been successfully established.