US20200280452A1

Secure session capability using public-key cryptography without access to the private key

Claim Score by NHIP

Read claim 21, the broadest

Abstract

A server establishes a secure session with a client device where a private key used in the handshake when establishing the secure session is stored in a different server. During the handshake procedure, the server receives a premaster secret that has been encrypted using a public key bound with a domain for which the client device is attempting to establish a secure session with. The server transmits the encrypted premaster secret to the different server for decryption along with other information necessary to compute a master secret. The different server decrypts the encrypted premaster secret, generates the master secret, and transmits the master secret to the server. The server receives the master secret and continues with the handshake procedure including generating one or more session keys that are used in the secure session for encrypting and decrypting communication between the client device and the server.

US20200280452A1, drawing sheet 1
Sheet 1 of 26

Term

8.5 yearsto projected expiry

Projected expiry 22 March 2035, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

22 claims: 4 independent, 18 dependent

  1. 21
    Broadest claimClaim Score 49, average(NHIP)A method, comprising:receiving, by a first server, a message including at least some of a negotiated set of cryptographic parameters from a second server, wherein the received at least some of the negotiated set of cryptographic parameters includes an encrypted premaster secret and a plurality of random values exchanged between a client device and the second server for establishing a secure session between the client device and the second server, wherein the second server does not have access to a private key to decrypt the encrypted premaster secret, and wherein the second server is separate from the first server;identifying the private key associated with a domain for which the client device is requesting the secure session;decrypting the encrypted premaster secret using the private key;generating a master secret using the decrypted premaster secret and the plurality of random values exchanged between the client device and the second server;and transmitting, to the second server, the generated master secret to the second server, the generated master secret for generating a set of one or more session keys to be used in the secure session for encrypting and decrypting communications between the client device and the second server.
  2. 28
    A non-transitory machine-readable storage medium that provides instructions that, when executed by a processor, cause said processor to perform operations comprising:receiving, by a first server, a message including at least some of a negotiated set of cryptographic parameters from a second server, wherein the received at least some of the negotiated set of cryptographic parameters includes an encrypted premaster secret and a plurality of random values exchanged between a client device and the second server for establishing a secure session between the client device and the second server, wherein the second server does not have access to a private key to decrypt the encrypted premaster secret, and wherein the second server is separate from the first server;identifying the private key associated with a domain for which the client device is requesting the secure session;decrypting the encrypted premaster secret using the private key;generating a master secret using the decrypted premaster secret and the plurality of random values exchanged between the client device and the second server;and transmitting, to the second server, the generated master secret to the second server, the generated master secret for generating a set of one or more session keys to be used in the secure session for encrypting and decrypting communications between the client device and the second server.
  3. 35
    An apparatus, comprising:a processor;a non-transitory machine-readable storage medium coupled with the processor that stores instructions that, when executed by the processor, causes said processor to perform the following: receive, by a first server, a message including at least some of a negotiated set of cryptographic parameters from a second server, wherein the received at least some of the negotiated set of cryptographic parameters includes an encrypted premaster secret and a plurality of random values exchanged between a client device and the second server for establishing a secure session between the client device and the second server, wherein the second server does not have access to a private key to decrypt the encrypted premaster secret, and wherein the second server is separate from the first server;identify the private key associated with a domain for which the client device is requesting the secure session;decrypt the encrypted premaster secret using the private key;generate a master secret using the decrypted premaster secret and the plurality of random values exchanged between the client device and the second server;and transmit, to the second server, the generated master secret to the second server, the generated master secret for generating a set of one or more session keys to be used in the secure session for encrypting and decrypting communications between the client device and the second server.