Invention Grant
US07975139B2 Use and generation of a session key in a secure socket layer connection
有权
在安全套接字层连接中使用和生成会话密钥
- Patent Title: Use and generation of a session key in a secure socket layer connection
- Patent Title (中): 在安全套接字层连接中使用和生成会话密钥
-
Application No.: US10135163Application Date: 2002-04-30
-
Publication No.: US07975139B2Publication Date: 2011-07-05
- Inventor: Frank Coulier
- Applicant: Frank Coulier
- Applicant Address: US IL Oakbrook Terrace
- Assignee: Vasco Data Security, Inc.
- Current Assignee: Vasco Data Security, Inc.
- Current Assignee Address: US IL Oakbrook Terrace
- Agency: Manatt, Phelps & Phillips LLP
- Main IPC: H04L9/32
- IPC: H04L9/32

Abstract:
The invention describes a method and system for verifying the link between a public key and a server's identity as claimed in the server's certificate without relying on the trustworthiness of the root certificate of the server's certificate chain. The system establishes a secure socket layer type connection between a client and a server, wherein the server transmits information including the server's public key to the client while establishing the connection. Next, a first information is sent from the client to the server. The client and the server create an identical authentication key using a shared secret known to the server and the client. Next, the server transmits a first encrypted message to the client, wherein the first encrypted message includes the server's public key encrypted with the authentication key. Then, the client decrypts the first encrypted message and verifies the correctness of that message including comparing the public key included in the decrypted first encrypted message to the public key transmitted during the set-up of the secure socket layer type connection to authenticate the client and to establish the trustworthiness of the server's public key and thereby the entire SSL connection. The client then transmits a second encrypted message to the server, wherein the second encrypted message is the first information encrypted with the authentication key. Finally, the server then decrypts the second encrypted message and verifies the correctness of the decrypted second encrypted message to authenticate the client.
Public/Granted literature
- US20020166048A1 Use and generation of a session key in a secure socket layer connection Public/Granted day:2002-11-07
Information query