Certificate validation and channel binding

US9497626B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9497626-B2
Application numberUS-201113296855-A
CountryUS
Kind codeB2
Filing dateNov 15, 2011
Priority dateNov 15, 2010
Publication dateNov 15, 2016
Grant dateNov 15, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A constrained network entity may determine, via an authentication procedure with a core network entity, the trustworthiness of an endpoint attempting to establish a secure channel with the constrained network entity. The constrained network entity may receive a certificate from the endpoint attempting to establish the secure channel and the constrained network entity may send the certificate asserted by the endpoint to a core network entity for validation. The core network entity may receive the certificate during a key exchange with the constrained network entity and the core network entity may indicate to the constrained network entity the validity of the certificate. The constrained network entity may determine whether to establish the secure channel with the endpoint based on the validity of the certificate.

First claim

Opening claim text (preview).

What is claimed: 1. A method comprising: receiving, at a constrained network entity, a certificate associated with a network entity, wherein the certificate is received for establishing a secure channel between the constrained network entity and the network entity; establishing, at the constrained network entity, a tentative secure channel with the network entity, wherein the tentative secure channel is established using, at least in part, a public key of the network entity; sending, by the constrained network entity to a core network entity, the received certificate associated with the network entity to determine the validity of the received certificate, whereby the constrained network entity uses the core network entity as a proxy to validate the certificate; performing authentication with the core network entity using, at least in part, the public key of the network entity; and receiving, at the constrained network entity from the core network entity, an indication of the validity of the certificate based on an analysis by the core network entity of the certificate, wherein prior to the received indication of validity of the certificate the validity of the certificate was unknown by the constrained network entity. 2. The method of claim 1 , wherein the secure channel is established between the network entity and the constrained network entity after successful authentication between the network entity and the constrained network entity. 3. The method of claim 1 , wherein the network entity is at least one of a terminal or an M2M network entity. 4. The method of claim 1 , wherein the network entity comprises a relay node. 5. The method of claim 1 , wherein the constrained network entity is at least one of a UICC or a USIM. 6. The method of claim 1 , wherein the indication of the validity of the certificate comprises a result of the authentication between the constrained network entity and the core network entity. 7. The method of claim 6 , wherein the result of the authentication comprises an authentication failure when the certificate is invalid. 8. The method of claim 6 , wherein the result of the authentication comprises a successful authentication when the certificate is valid. 9. The method of claim 1 , wherein the certificate is received during a public key exchange performed to establish the secure channel between the network entity and the constrained network entity. 10. The method recited in claim 1 , wherein the authentication is performed in accordance with an Authentication and Key Agreement (AKA) procedure. 11. A method performed by a core network entity of a communications network, the method comprising: receiving, from a constrained network entity, a certificate associated with a network entity with which the constrained network entity is attempting to establish a secure channel; serving as a proxy for the constrained network entity to determine a validity of the certificate associated with the network entity based on an analysis of the certificate; performing authentication with the constrained network entity using, at least in part, a public key of the network entity; and indicating, to the constrained network entity, the validity of the certificate to enable establishment of the secure channel between the constrained network entity and the network entity. 12. The method of claim 11 , wherein determining the validity of the certificate associated with the network entity further comprises: sending the certificate to a certificate authority to determine the validity of the certificate; and receiving, from the certificate authority, an indication of the validity of the certificate. 13. The method of claim 11 , wherein the constrained network entity uses an identity of the network entity to obtain a known valid certificate associated with the identity; and further comprising comparing the known valid certificate to the certificate associated with the network entity to determine the validity of the certificate associated with the network entity. 14. The method of claim 11 , further comprising sending a revocation status of the certificate to the constrained network entity to indicate that the certificate is invalid. 15. The method of claim 11 , wherein the network entity comprises a relay node and the constrained network comprises a UICC. 16. The method recited in claim 11 , wherein the authentication is performed in accordance with an Authentication and Key Agreement (AKA) procedure. 17. A constrained network entity configured to: receive a certificate associated with a network entity and a public key associated with the network entity, wherein the certificate and the public key are received for establishing a secure communication channel between the constrained network entity and the network entity; send, to a core network entity with which the constrained network entity has an established security association, the certificate, whereby the constrained network entity uses the core network entity as a proxy to validate the certificate; perform authentication with the core network entity using, at least in part, the public key of the network entity; and receive, from the core network entity, an indication of the validity of the certificate based on an analysis of the certificate by the core network entity, wherein prior to the received indication of validity of the certificate the validity of the certificate was unknown by the constrained network entity. 18. The constrained network entity of claim 17 , wherein the network entity is at least one of a terminal or an M2M network entity. 19. The constrained network entity of claim 17 , wherein the constrained network entity is a UICC or a USIM. 20. The constrained network entity of claim 17 , wherein authentication is performed in accordance with an Authentication and Key Agreement (AKA) procedure.

Assignees

Inventors

Classifications

  • for achieving mutual authentication (cryptographic mechanisms or cryptographic arrangements for mutual authentication H04L9/3273) · CPC title

  • Processing at user equipment or user record carrier · CPC title

  • involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements (network architectures or network communication protocols for supporting authentication of entities using certificates in a packet data network H04L63/0823) · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9497626B2 cover?
A constrained network entity may determine, via an authentication procedure with a core network entity, the trustworthiness of an endpoint attempting to establish a secure channel with the constrained network entity. The constrained network entity may receive a certificate from the endpoint attempting to establish the secure channel and the constrained network entity may send the certificate as…
Who is the assignee on this patent?
Case Lawrence, Shah Yogendra C, Cha Inhyok, and 1 more
What technology area does this patent fall under?
Primary CPC classification H04L63/0823. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Nov 15 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).