The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 20, 2018

Filed:

Jul. 15, 2015
Applicants:

Institute of Information Engineering, Chinese Academy of Sciences, Beijing, CN;

Data Assurance & Communication Security Center, Chinese Academy of Sciences, Beijing, CN;

Inventors:

Jingqiang Lin, Beijing, CN;

Bingyu Li, Beijing, CN;

Zhan Wang, Beijing, CN;

Jiwu Jing, Beijing, CN;

Congwu Li, Beijing, CN;

Luning Xia, Beijing, CN;

Qiongqiao Wang, Beijing, CN;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/08 (2006.01); H04L 9/30 (2006.01); H04L 9/32 (2006.01); G06F 21/33 (2013.01); G06F 9/455 (2018.01); H04L 29/06 (2006.01); H04L 9/00 (2006.01);
U.S. Cl.
CPC ...
H04L 9/3268 (2013.01); G06F 9/45545 (2013.01); G06F 9/45558 (2013.01); G06F 21/33 (2013.01); H04L 9/006 (2013.01); H04L 9/0891 (2013.01); H04L 63/0823 (2013.01); G06F 2009/45583 (2013.01); H04L 9/30 (2013.01);
Abstract

The present invention discloses a method and a system for checking revocation status of digital certificates in a virtualization environment. The method includes: 1) Setting up multiple virtual machines in a host computer; setting up a certificate revocation list manager within the virtual machine monitor of the host computer; 2) The certificates relying party in the virtual machines sends a service request for checking certificate revocation status to the certificate revocation list manager; 3) The certificate revocation list manager searches locally for the CRL file corresponding to the service request for checking certificate revocation status: a) If such a corresponding CRL file exists, the CRL file is returned to the certificate relying party in the virtual machines; or, the certificate revocation list manager checks whether the corresponding certificate serial number exists in the CRL file, then returns the result; b) if the corresponding CRL file does not exist, the corresponding CRL file is downloaded and verified according to the configuration file; then the CRL file is returned to the certificate relying party in the virtual machines; or, the certificate revocation list manager checks whether the corresponding certificate serial number exists in the CRL file, then returns the result. The present invention greatly improves the efficiency of checking revocation status of certificates.


Find Patent Forward Citations

Loading…