US20070150737A1

Certificate registration after issuance for secure communication

Claim Score by NHIP

Read claim 20, the broadest

Abstract

Techniques for registering certificates after the issuance of the certificates are provided. A service provider securely registers a client's identity and its certificate without depending on or using an existing basis of trust, such as that provided by domain-joined clients or a security directory (e.g., MICROSOFT's ACTIVE DIRECTORY). The service provider provides services, such as, by way of example and not a limitation, email services, web application services, application services, etc., based on identifiers (e.g., service IDs) issued to registered clients. The service provider subsequently uses the issued identifier to authenticate a client requesting a service or services, and to authorize the client to receive the requested service or services.

US20070150737A1, drawing sheet 1
Sheet 1 of 9

Term

Term ended

Projected expiry passed 22 December 2025, 0.8 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

20 claims: 3 independent, 17 dependent

  1. 1
    A method in a computer system for registering a certificate after issuance of the certificate, the method comprising:receiving a certificate registration request from a client, the certificate registration request comprising a certificate that is to be registered and a signature;determining that the certificate is a valid certificate;determining that the client is an authentic client;and based upon a unique token associated with the certificate, either newly registering the certificate or renewing a registration.
  2. 14
    A computer-readable medium containing instructions for a server to register certificates after issuance of the certificates, by a method comprising:receiving a certificate registration request from a client, the certificate registration request comprising a certificate that is to be registered and a signature;determining that the certificate is a valid certificate;determining that the client is an authentic client;determining that a subject name associated with the certificate is not associated with a registration record for a registered certificate;determining that a service ID is not passed with the certificate registration request;generating a service ID;associating the generated service ID with the subject name associated with the certificate;registering the certificate;and sending a successful registration response to the client, the successful registration response including the service ID.
  3. 20
    Broadest claimClaim Score 88, very broad(NHIP)A method in a computer system for providing services, the method comprising:receiving a request for a service, the request comprising a service ID and a signature;retrieving a public key using the received service ID;validating the signature using the retrieved public key;and providing the requested service.