US2015156194A1PendingUtilityA1

Certificate status delivery through a local endpoint

Assignee: SYMANTEC CORPPriority: Dec 4, 2013Filed: Dec 4, 2013Published: Jun 4, 2015
Est. expiryDec 4, 2033(~7.3 yrs left)· nominal 20-yr term from priority
H04L 63/0823H04L 67/568H04L 9/3268H04L 63/1483H04L 9/321
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Techniques are disclosed for locally distributing online certificate status protocol (OCSP) responses to a client computer. A certificate authority (CA) proactively sends OCSP responses to an agent application (e.g., an antivirus application configured to handle OCSP responses) residing in the client computer. The agent application stores the OCSP responses in a cache. Thereafter, when a browser application sends an OCSP request to the CA, the agent application intercepts the request and determines whether a corresponding OCSP response is locally cached. If so, the agent application sends the cached OCSP response to the browser application. If not, the agent application retrieves the corresponding OCSP response from the CA and sends the response to the browser application.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for distributing certificate status validity messages, the method comprising:
 pre-populating a cache accessible to an agent application with one or more certificate status validity messages received from a certificate authority;   intercepting, via the agent application, a certificate status validity request from a browser application for a digital certificate; and   determining whether the cache stores a certificate status validity message corresponding to the certificate status validity request; and   upon determining that the corresponding certificate status validity message is stored in the cache, sending the corresponding certificate status validity message to the browser application.   
     
     
         2 . The method of  claim 1 , wherein the certificate status validity request is an online certificate status protocol (OCSP) request, and wherein the certificate status validity message is an OCSP response. 
     
     
         3 . The method of  claim 1 , further comprising, upon determining that the corresponding certificate status validity message is not stored in the cache:
 requesting a new certificate status validity message corresponding to the certificate validity request from the certificate authority;   receiving, in response to the request, the new certificate status validity message from the certificate authority;   sending the new certificate status validity message to the browser application; and   storing the corresponding certificate status validity message in the cache.   
     
     
         4 . The method of  claim 1 , wherein the agent application is an antivirus application. 
     
     
         5 . The method of  claim 1 , wherein the digital certificate specifies a location of a cache in the client computer that includes stored certificate validity messages. 
     
     
         6 . The method of  claim 1 , further comprising, receiving updated certificate validity messages from the certificate authority. 
     
     
         7 . The method of  claim 1 , wherein the certificate status validity message is a certificate revocation list. 
     
     
         8 . A method for distributing certificate status validity messages to an agent application executing on a client computer, the method comprising:
 identifying, via a processor, a set of certificate validity messages to send to a client computer;   generating the set of certificate status validity messages;   sending the certificate validity messages to an agent application executing on the client computer, wherein the client computer stores the certificate status validity messages in a cache.   
     
     
         9 . The method of  claim 8 , wherein identifying the certificate validity messages comprises:
 identifying a distribution of digital certificates, wherein the distribution indicates the frequency at which certificate status validity messages have been requested by a plurality of clients; and   selecting the certificate validity messages based on the distribution.   
     
     
         10 . The method of  claim 8 , wherein the identified certificate validity messages include certificate validity messages requested by the client computer. 
     
     
         11 . The method of  claim 8 , wherein the certificate status validity request is an online certificate status protocol (OCSP) request, and wherein the certificate status validity message is an OCSP response. 
     
     
         12 . The method of  claim 8 , wherein the certificate status validity message is a certificate revocation list. 
     
     
         13 . The method of  claim 8 , wherein the agent application is an antivirus application. 
     
     
         14 . A computer-readable storage medium storing instructions, which, when executed on a processor, performs an operation for distributing certificate status validity messages to a client, the operation comprising:
 pre-populating a cache accessible to an agent application with one or more certificate status validity messages received from a certificate authority;   intercepting, via the agent application, a certificate status validity request from a browser application for a digital certificate; and   determining whether the cache stores a certificate status validity message corresponding to the certificate status validity request; and   upon determining that the corresponding certificate status validity message is stored in the cache, sending the corresponding certificate status validity message to the browser application.   
     
     
         15 . The computer-readable storage medium of  claim 14 , wherein the certificate status validity request is an online certificate status protocol (OCSP) request, and wherein the certificate status validity message is an OCSP response. 
     
     
         16 . The computer-readable storage medium of  claim 14 , wherein the operation further comprises, upon determining that the corresponding certificate status validity message is not stored in the cache:
 requesting a new certificate status validity message corresponding to the certificate validity request from the certificate authority;   receiving, in response to the request, the new certificate status validity message from the certificate authority;   sending the new certificate status validity message to the browser application; and   storing the corresponding certificate status validity message in the cache.   
     
     
         17 . The computer-readable storage medium of  claim 14 , wherein the agent application is an antivirus application. 
     
     
         18 . The computer-readable storage medium of  claim 14 , wherein the digital certificate specifies a location of a cache in the client computer that includes stored certificate validity messages. 
     
     
         19 . The computer-readable storage medium of  claim 14 , wherein the operation further comprises, receiving updated certificate validity messages from the certificate authority. 
     
     
         20 . The computer-readable storage medium of  claim 14 , wherein the certificate status validity message is a certificate revocation list.

Join the waitlist — get patent alerts

Track US2015156194A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.