- 专利标题: Secure session capability using public-key cryptography without access to the private key
-
申请号: US15271190申请日: 2016-09-20
-
公开(公告)号: US10009183B2公开(公告)日: 2018-06-26
- 发明人: Sébastien Andreas Henry Pahl , Matthieu Philippe François Tourne , Piotr Sikora , Ray Raymond Bejjani , Dane Orion Knecht , Matthew Browning Prince , John Graham-Cumming , Lee Hahn Holloway , Nicholas Thomas Sullivan , Albertus Strasheim
- 申请人: CLOUDFLARE, INC.
- 申请人地址: US CA San Francisco
- 专利权人: CLOUDFLARE, INC.
- 当前专利权人: CLOUDFLARE, INC.
- 当前专利权人地址: US CA San Francisco
- 代理机构: Nicholson De Vos Webster & Elliott LLP
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L9/32 ; H04L9/08 ; H04L9/14 ; H04L9/30 ; H04L29/08
摘要:
A server establishes a secure session with a client device where a private key used in the handshake when establishing the secure session is stored in a different server. During the handshake procedure, the server receives a premaster secret that has been encrypted using a public key bound with a domain for which the client device is attempting to establish a secure session with. The server transmits the encrypted premaster secret to the different server for decryption along with other information necessary to compute a master secret. The different server decrypts the encrypted premaster secret, generates the master secret, and transmits the master secret to the server. The server receives the master secret and continues with the handshake procedure including generating one or more session keys that are used in the secure session for encrypting and decrypting communication between the client device and the server.
公开/授权文献
信息查询