US2006294381A1PendingUtilityA1
Method and apparatus for establishing a secure connection
Individually held — no corporate assignee on recordPriority: Jun 22, 2005Filed: Jun 22, 2005Published: Dec 28, 2006
Est. expiryJun 22, 2025(expired)· nominal 20-yr term from priority
H04L 9/3263H04L 63/0823H04L 63/06
45
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
One embodiment of the present invention provides a system that establishes a secure connection with a peer. During operation, the system obtains an identity for the peer. Next, the system looks up the identity for the peer in a local store, which contains identities for trusted peers. If this lookup fails, the system asks a user if the peer can be trusted. If the user indicates that the peer can be trusted, the system establishes a secure connection with the peer.
Claims
exact text as granted — not AI-modified1 . A method for establishing a secure connection with a peer, comprising:
obtaining an identity for the peer; looking up the identity for the peer in a local store, which contains identities for trusted peers; and if the lookup fails,
asking a user if the peer can be trusted, and
if the user indicates that the peer can be trusted,
establishing the secure connection with the peer.
2 . The method of claim 1 , wherein the identity for the peer can be represented by a digital certificate for the peer.
3 . The method of claim 2 , wherein establishing the secure connection with the peer involves:
starting with an unauthenticated connection with the peer; importing the digital certificate for the peer into the local store; and establishing the secure connection with the peer using the unauthenticated connection and the digital certificate for the peer.
4 . The method of claim 3 , wherein if the digital certificate for the peer is a self-signed digital certificate, the method further comprises performing an out-of-band exchange with the peer to confirm the validity of the self-signed digital certificate.
5 . The method of claim 1 , wherein obtaining the identity for the peer involves performing a service discovery operation to obtain the identity for the peer and also to obtain an unauthenticated connection with the peer.
6 . The method of claim 1 , wherein the secure connection is a Secure Sockets Layer (SSL) connection or a Transport Layer Security (TLS) connection.
7 . The method of claim 1 , wherein the local store is a Mac OS™ keychain.
8 . A computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method for establishing a secure connection with a peer, the method comprising:
obtaining an identity for the peer; looking up the identity for the peer in a local store, which contains identities for trusted peers; and if the lookup fails,
asking a user if the peer can be trusted, and
if the user indicates that the peer can be trusted,
establishing the secure connection with the peer.
9 . The computer-readable storage medium of claim 8 , wherein the identity for the peer can be represented by a digital certificate for the peer.
10 . The computer-readable storage medium of claim 9 , wherein establishing the secure connection with the peer involves:
starting with an unauthenticated connection with the peer; importing the digital certificate for the peer into the local store; and establishing the secure connection with the peer using the unauthenticated connection and the digital certificate for the peer.
11 . The computer-readable storage medium of claim 10 , wherein if the digital certificate for the peer is a self-signed digital certificate, the method further comprises performing an out-of-band exchange with the peer to confirm the validity of the self-signed digital certificate.
12 . The computer-readable storage medium of claim 8 , wherein obtaining the identity for the peer involves performing a service discovery operation to obtain the identity for the peer and also to obtain an unauthenticated connection with the peer.
13 . The computer-readable storage medium of claim 8 , wherein the secure connection is a Secure Sockets Layer (SSL) connection or a Transport Layer Security (TLS) connection.
14 . The computer-readable storage medium of claim 8 , wherein the local store is a Mac OS™ keychain.
15 . An apparatus for establishing a secure connection with a peer, comprising:
an identity-obtaining mechanism configured to obtain an identity for the peer; a lookup mechanism configured to look up the identity for the peer in a local store, which contains identities for trusted peers; and a connection-establishing mechanism, wherein if the lookup fails, the connection-establishing mechanism is configured to ask a user if the peer can be trusted; wherein if the user indicates that the peer can be trusted, the connection-establishing mechanism is configured to establish the secure connection with the peer.
16 . The apparatus of claim 15 , wherein the identity for the peer can be represented by a digital certificate for the peer.
17 . The apparatus of claim 16 , wherein the connection-establishing mechanism is configured to:
start with an unauthenticated connection with the peer; import the digital certificate for the peer into the local store; and to establish the secure connection with the peer using the unauthenticated connection and the digital certificate for the peer.
18 . The apparatus of claim 17 , wherein if the digital certificate for the peer is a self-signed digital certificate, the connection-establishing mechanism is configured to perform an out-of-band exchange with the peer to confirm the validity of the self-signed digital certificate.
19 . The apparatus of claim 15 , wherein the identity-obtaining mechanism is configured to perform a service discovery operation to obtain the identity for the peer and also to obtain an unauthenticated connection with the peer.
20 . The apparatus of claim 15 , wherein the secure connection is a Secure Sockets Layer (SSL) connection or a Transport Layer Security (TLS) connection.
21 . The apparatus of claim 15 , wherein the local store is a Mac OS™ keychain.
22 . A function library embedded on a computer-readable storage medium, wherein the function library includes a first function for establishing a secure connection with a peer, wherein the first function is configured to:
obtain an identity for the peer; look up the identity for the peer in a local store, which contains identities for trusted peers; and if the lookup fails, to
ask a user if the peer can be trusted, and
if the user indicates that the peer can be trusted, to establish the secure connection with the peer.
23 . The function library of claim 22 , wherein the function library includes a second function for creating a private/public key pair and a corresponding a digital certificate for a given node.
23 . The function library of claim 22 , wherein the function library includes a third function for importing a digital certificate for a peer into a local store.
25 . The function library of claim 22 , wherein the identity for the peer can be represented by a digital certificate for the peer.
26 . The function library of claim 25 , wherein while establishing the secure connection with the peer, the first function is configured to:
start with an unauthenticated connection with the peer; import the digital certificate for the peer into the local store; and to establish the secure connection with the peer using the unauthenticated connection and the digital certificate for the peer.
27 . The function library of claim 26 , wherein if the digital certificate for the peer is a self-signed digital certificate, the first function is configured to perform an out-of-band exchange with the peer to confirm the validity of the self-signed digital certificate.
28 . The function library of claim 22 , wherein while obtaining the identity for the peer, the first function is configured to perform a service discovery operation to obtain the identity for the peer and also to obtain an unauthenticated connection with the peer.Join the waitlist — get patent alerts
Track US2006294381A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.