US2006294381A1PendingUtilityA1

Method and apparatus for establishing a secure connection

Individually held — no corporate assignee on recordPriority: Jun 22, 2005Filed: Jun 22, 2005Published: Dec 28, 2006
Est. expiryJun 22, 2025(expired)· nominal 20-yr term from priority
H04L 9/3263H04L 63/0823H04L 63/06
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

One embodiment of the present invention provides a system that establishes a secure connection with a peer. During operation, the system obtains an identity for the peer. Next, the system looks up the identity for the peer in a local store, which contains identities for trusted peers. If this lookup fails, the system asks a user if the peer can be trusted. If the user indicates that the peer can be trusted, the system establishes a secure connection with the peer.

Claims

exact text as granted — not AI-modified
1 . A method for establishing a secure connection with a peer, comprising: 
 obtaining an identity for the peer;    looking up the identity for the peer in a local store, which contains identities for trusted peers; and    if the lookup fails, 
 asking a user if the peer can be trusted, and  
 if the user indicates that the peer can be trusted,  
   establishing the secure connection with the peer.    
     
     
         2 . The method of  claim 1 , wherein the identity for the peer can be represented by a digital certificate for the peer.  
     
     
         3 . The method of  claim 2 , wherein establishing the secure connection with the peer involves: 
 starting with an unauthenticated connection with the peer;    importing the digital certificate for the peer into the local store; and    establishing the secure connection with the peer using the unauthenticated connection and the digital certificate for the peer.    
     
     
         4 . The method of  claim 3 , wherein if the digital certificate for the peer is a self-signed digital certificate, the method further comprises performing an out-of-band exchange with the peer to confirm the validity of the self-signed digital certificate.  
     
     
         5 . The method of  claim 1 , wherein obtaining the identity for the peer involves performing a service discovery operation to obtain the identity for the peer and also to obtain an unauthenticated connection with the peer.  
     
     
         6 . The method of  claim 1 , wherein the secure connection is a Secure Sockets Layer (SSL) connection or a Transport Layer Security (TLS) connection.  
     
     
         7 . The method of  claim 1 , wherein the local store is a Mac OS™ keychain.  
     
     
         8 . A computer-readable storage medium storing instructions that when executed by a computer cause the computer to perform a method for establishing a secure connection with a peer, the method comprising: 
 obtaining an identity for the peer;    looking up the identity for the peer in a local store, which contains identities for trusted peers; and    if the lookup fails, 
 asking a user if the peer can be trusted, and  
 if the user indicates that the peer can be trusted,  
   establishing the secure connection with the peer.    
     
     
         9 . The computer-readable storage medium of  claim 8 , wherein the identity for the peer can be represented by a digital certificate for the peer.  
     
     
         10 . The computer-readable storage medium of  claim 9 , wherein establishing the secure connection with the peer involves: 
 starting with an unauthenticated connection with the peer;    importing the digital certificate for the peer into the local store; and    establishing the secure connection with the peer using the unauthenticated connection and the digital certificate for the peer.    
     
     
         11 . The computer-readable storage medium of  claim 10 , wherein if the digital certificate for the peer is a self-signed digital certificate, the method further comprises performing an out-of-band exchange with the peer to confirm the validity of the self-signed digital certificate.  
     
     
         12 . The computer-readable storage medium of  claim 8 , wherein obtaining the identity for the peer involves performing a service discovery operation to obtain the identity for the peer and also to obtain an unauthenticated connection with the peer.  
     
     
         13 . The computer-readable storage medium of  claim 8 , wherein the secure connection is a Secure Sockets Layer (SSL) connection or a Transport Layer Security (TLS) connection.  
     
     
         14 . The computer-readable storage medium of  claim 8 , wherein the local store is a Mac OS™ keychain.  
     
     
         15 . An apparatus for establishing a secure connection with a peer, comprising: 
 an identity-obtaining mechanism configured to obtain an identity for the peer;    a lookup mechanism configured to look up the identity for the peer in a local store, which contains identities for trusted peers; and    a connection-establishing mechanism, wherein if the lookup fails, the connection-establishing mechanism is configured to ask a user if the peer can be trusted;    wherein if the user indicates that the peer can be trusted, the connection-establishing mechanism is configured to establish the secure connection with the peer.    
     
     
         16 . The apparatus of  claim 15 , wherein the identity for the peer can be represented by a digital certificate for the peer.  
     
     
         17 . The apparatus of  claim 16 , wherein the connection-establishing mechanism is configured to: 
 start with an unauthenticated connection with the peer;    import the digital certificate for the peer into the local store; and to establish the secure connection with the peer using the unauthenticated connection and the digital certificate for the peer.    
     
     
         18 . The apparatus of  claim 17 , wherein if the digital certificate for the peer is a self-signed digital certificate, the connection-establishing mechanism is configured to perform an out-of-band exchange with the peer to confirm the validity of the self-signed digital certificate.  
     
     
         19 . The apparatus of  claim 15 , wherein the identity-obtaining mechanism is configured to perform a service discovery operation to obtain the identity for the peer and also to obtain an unauthenticated connection with the peer.  
     
     
         20 . The apparatus of  claim 15 , wherein the secure connection is a Secure Sockets Layer (SSL) connection or a Transport Layer Security (TLS) connection.  
     
     
         21 . The apparatus of  claim 15 , wherein the local store is a Mac OS™ keychain.  
     
     
         22 . A function library embedded on a computer-readable storage medium, wherein the function library includes a first function for establishing a secure connection with a peer, wherein the first function is configured to: 
 obtain an identity for the peer;    look up the identity for the peer in a local store, which contains identities for trusted peers; and    if the lookup fails, to 
 ask a user if the peer can be trusted, and  
 if the user indicates that the peer can be trusted, to establish the secure connection with the peer.  
   
     
     
         23 . The function library of  claim 22 , wherein the function library includes a second function for creating a private/public key pair and a corresponding a digital certificate for a given node.  
     
     
         23 . The function library of  claim 22 , wherein the function library includes a third function for importing a digital certificate for a peer into a local store.  
     
     
         25 . The function library of  claim 22 , wherein the identity for the peer can be represented by a digital certificate for the peer.  
     
     
         26 . The function library of  claim 25 , wherein while establishing the secure connection with the peer, the first function is configured to: 
 start with an unauthenticated connection with the peer;    import the digital certificate for the peer into the local store; and to    establish the secure connection with the peer using the unauthenticated connection and the digital certificate for the peer.    
     
     
         27 . The function library of  claim 26 , wherein if the digital certificate for the peer is a self-signed digital certificate, the first function is configured to perform an out-of-band exchange with the peer to confirm the validity of the self-signed digital certificate.  
     
     
         28 . The function library of  claim 22 , wherein while obtaining the identity for the peer, the first function is configured to perform a service discovery operation to obtain the identity for the peer and also to obtain an unauthenticated connection with the peer.

Join the waitlist — get patent alerts

Track US2006294381A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.