首页> 外国专利> Mechanisms for certificate revocation status verification on constrained devices

Mechanisms for certificate revocation status verification on constrained devices

机译:受限设备上证书吊销状态验证的机制

摘要

A process is provided for communication security certificate revocation status verification by using the client device as a proxy in online status verification protocol. The process utilizes a nonce of an authentication protocol request message (nonce_A) to derive the nonce for the revocation status protocol request (nonce_S) to reduce the number of message exchanges needed between the client and the verifier devices, and a mechanism to send the nonce (nonce_S) prior to actual authentication protocol execution to ease the connectivity requirement of client device from on-demand connectivity to periodic connectivity. Similar functionality is achieved using a random seed established between the verifier and client. The verifier picks a seed for random number generation and sends that seed to the client. The client derives the nonce_S from the seed before status protocol execution, and the verifier derives the nonce_S from the seed before proxied status response verification.
机译:通过使用客户端设备作为在线状态验证协议中的代理,提供了用于通信安全证书吊销状态验证的过程。该过程利用身份验证协议请求消息的现时(nonce_A)得出撤销状态协议请求(nonce_S)的现时,以减少客户端与验证程序设备之间所需的消息交换数量,以及一种发送现时的机制(nonce_S)在实际执行身份验证协议之前,以减轻客户端设备从按需连接到定期连接的连接要求。使用在验证者和客户端之间建立的随机种子可以实现类似的功能。验证者为随机数生成选择一个种子,并将该种子发送给客户端。客户端从状态协议执行之前的种子中获取nonce_S,验证程序从代理状态响应验证之前的种子中获取nonce_S。

著录项

  • 公开/公告号US9756036B2

    专利类型

  • 公开/公告日2017-09-05

    原文格式PDF

  • 申请/专利权人 NOKIA TECHNOLOGIES OY;

    申请/专利号US201313910613

  • 发明设计人 KARI KOSTIAINEN;NADARAJAH ASOKAN;

    申请日2013-06-05

  • 分类号H04L29/06;H04L9/08;H04L9/32;

  • 国家 US

  • 入库时间 2022-08-21 13:42:20

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号