Invention Grant
- Patent Title: Forward secrecy in transport layer security (TLS) using ephemeral keys
-
Application No.: US17503049Application Date: 2021-10-15
-
Publication No.: US11985239B2Publication Date: 2024-05-14
- Inventor: Michael W. Gray , Narayana Aditya Madineni , Matthew Green , Simon D. McMahon , Leigh S. McLean , Stephen J. McKenzie , Luvita Burgess , Peter T. Waltenberg
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Edward J. Wixted, III
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/08 ; H04L9/30 ; H04L9/32 ; H04L9/40

Abstract:
Transport Layer Security (TLS) connection establishment between a client and a server for a new session is enabled using an ephemeral (temporary) key pair. In response to a request, the server generates a temporary certificate by signing an ephemeral public key using the server's private key. A certificate chain comprising at least the temporary certificate that includes the ephemeral public key, together with a server certificate, is output to the client by the server, which acts as a subordinate Certificate Authority. The client validates the certificates, generates a session key and outputs the session key wrapped by the ephemeral public key. To complete the connection establishment, the server applies the ephemeral private key to recover the session key derived at the client for the new session. The client and server thereafter use the session key to encrypt and decrypt data over the link. The ephemeral key pair is not reused.
Public/Granted literature
- US20220038278A1 Forward secrecy in Transport Layer Security (TLS) using ephemeral keys Public/Granted day:2022-02-03
Information query