US20110161663A1

Intelligent caching for ocsp service optimization

Claim Score by NHIP

Read claim 1, the broadest

Abstract

An online certificate status checking protocol (OCSP) system is provided for use with a first device, an end device and a certificate authority. The first device can provide a certificate. The end device can provide an OCSP request based on the certificate and process an OCSP response. The certificate authority can provide a CRL update. The certificate has a validity period. The OCSP system includes an OCSP responder, and OCSP proxy and a cache. The OCSP responder can provide the OCSP response. The OCSP proxy can receive the OCSP request from the end device, can send the OCSP request to the OCSP responder, can receive the OCSP response from the OCSP responder and can send the OCSP response to the end device. The cache can store information based on the OCSP response. The OCSP proxy can further store, in the cache, information based on the OCSP response and can send a proactive OCSP request to the OCSP responder based on a predetermined policy. The OCSP responder can further send a proactive OCSP response to the OCSP proxy in response to the proactive OCSP request. The OCSP proxy can further update the information in the cache based on the proactive OCSP response. The OCSP proxy can additionally provide, using the updated information in the cache, a second OCSP response to the end device in response to a subsequent request from the end device related to information of the certificate.

US20110161663A1, drawing sheet 1
Sheet 1 of 5

Term

Projected expiry 29 December 2029.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

20 claims: 3 independent, 17 dependent

  1. 1
    Broadest claimClaim Score 15, narrow(NHIP)An online certificate status checking protocol system for use with a first device, an end device and a certificate authority, the first device being operable to provide a certificate, the end device being operable to provide an online certificate status checking protocol request based on the certificate and process an online certificate status checking protocol response, the certificate authority being operable to provide a certificate revocation list update, the certificate having a validity period, said online certificate status checking protocol system comprising:an online certificate status checking protocol responder operable to provide the online certificate status checking protocol response, an online certificate status checking protocol proxy operable to receive the online certificate status checking protocol request from the end device, to send the online certificate status checking protocol request to said online certificate status checking protocol responder, to receive the online certificate status checking protocol response from said online certificate status checking protocol responder and to send the online certificate status checking protocol response to the end device;and a cache operable to store information based on the online certificate status checking protocol response, wherein said online certificate status checking protocol proxy is further operable to store, in said cache, information based on the online certificate status checking protocol response, wherein said online certificate status checking protocol proxy is further operable to send a proactive online certificate status checking protocol request to said online certificate status checking protocol responder based on a predetermined policy, wherein said online certificate status checking protocol responder is further operable to send a proactive online certificate status checking protocol response to said online certificate status checking protocol proxy in response to the proactive online certificate status checking protocol request, wherein said online certificate status checking protocol proxy is further operable to update the information in said cache based on the proactive online certificate status checking protocol response, and wherein said online certificate status checking protocol proxy is further operable to provide, using the updated information in said cache, a second online certificate status checking protocol response to the end device in response to a subsequent request from the end device related to information of the certificate.
  2. 8
    A method of using a system including a first device, an end device and a certificate authority, the first device being operable to provide a certificate, the end device being operable to provide an online certificate status checking protocol request based on the certificate and process an online certificate status checking protocol response, the certificate authority being operable to provide a certificate revocation list update, the certificate having a validity period, said method comprising:receiving, by way of an online certificate status checking protocol proxy, the online certificate status checking protocol request from the end device;providing, by way of the online certificate status checking protocol proxy, the online certificate status checking protocol request;receiving, by way of an online certificate status checking protocol responder, the online certificate status checking protocol request;providing, by way of the online certificate status checking protocol responder, an online certificate status checking protocol response;receiving, by way of the online certificate status checking protocol proxy, the online certificate status checking protocol response from the online certificate status protocol responder;sending, by way of the online certificate status checking protocol proxy, the online certificate status checking protocol response to the end device;storing, within a cache, information based on the online certificate status checking protocol response;storing, within the cache, information based on the online certificate status checking protocol request;sending, by way of the online certificate status checking protocol proxy, a proactive online certificate status checking protocol request to the online certificate status checking protocol responder based on a predetermined policy;sending, by way of the online certificate status checking protocol responder, a proactive online certificate status checking protocol response to the online certificate status checking protocol proxy in response to the proactive online certificate status checking protocol request;updating the information in the cache based on the proactive online certificate status checking protocol response;and providing, by way of the online certificate status checking protocol proxy using the updated information in the cache, a second online certificate status checking protocol response to the end device in response to a subsequent request from the end device related to information of the certificate.
  3. 15
    Computer-readable media for use in an online certificate status checking protocol computer in a system including a first device, an end device, an online certificate status checking protocol responder and a certificate authority, the first device being operable to provide a certificate, the end device being operable to provide an online certificate status checking protocol request based on the certificate and process an online certificate status checking protocol response, the online certificate status checking protocol responder being operable to provide the online certificate status checking protocol response, the certificate authority being operable to provide a certificate revocation list update, the certificate having a validity period, said computer-readable media having computer-readable instructions stored thereon, the computer-readable instructions being capable of instructing the online certificate status checking protocol computer to perform the method comprising:receiving, by way of an online certificate status checking protocol proxy, the online certificate status checking protocol request from the end device;providing, by way of the online certificate status checking protocol proxy, the online certificate status checking protocol request;receiving, by way of an online certificate status checking protocol responder, the online certificate status checking protocol request;providing, by way of the online certificate status checking protocol responder, an online certificate status checking protocol response;receiving, by way of the online certificate status checking protocol proxy, the online certificate status checking protocol response from the online certificate status protocol responder;sending, by way of the online certificate status checking protocol proxy, the online certificate status checking protocol response to the end device;storing, within a cache, information based on the online certificate status checking protocol response;storing, within the cache, information based on the online certificate status checking protocol request;sending, by way of the online certificate status checking protocol proxy, a proactive online certificate status checking protocol request to the online certificate status checking protocol responder based on a predetermined policy;sending, by way of the online certificate status checking protocol responder, a proactive online certificate status checking protocol response to the online certificate status checking protocol proxy in response to the proactive online certificate status checking protocol request;updating the information in the cache based on the proactive online certificate status checking protocol response;and providing, by way of the online certificate status checking protocol proxy using the updated information in the cache, a second online certificate status checking protocol response to the end device in response to a subsequent request from the end device related to information of the certificate.