The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Sep. 08, 2020

Filed:

Apr. 23, 2019
Applicant:

Akamai Technologies, Inc., Cambridge, MA (US);

Inventors:

Charles E. Gero, Quincy, MA (US);

Jeremy N. Shapiro, Brookline, MA (US);

Dana J. Burd, Wakefield, MA (US);

Assignee:

Akamai Technologies, Inc., Cambridge, MA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/32 (2006.01); H04L 29/06 (2006.01); H04L 9/08 (2006.01); H04L 9/14 (2006.01); H04L 9/30 (2006.01);
U.S. Cl.
CPC ...
H04L 9/3263 (2013.01); H04L 9/0844 (2013.01); H04L 9/14 (2013.01); H04L 9/302 (2013.01); H04L 9/3013 (2013.01); H04L 9/3249 (2013.01); H04L 63/0442 (2013.01); H04L 63/061 (2013.01); H04L 63/166 (2013.01); H04L 2209/76 (2013.01);
Abstract

An infrastructure delivery platform provides a proxy service as an enhancement to the TLS/SSL protocol to off-load to an external server the generation of a digital signature, the digital signature being generated using a private key that would otherwise have to be maintained on a terminating server. Using this service, instead of digitally signing (using the private key) 'locally,' the terminating server proxies given public portions of ephemeral key exchange material to the external server and receives, in response, a signature validating the terminating server is authorized to continue with the key exchange. In this manner, a private key used to generate the digital signature (or, more generally, to facilitate the key exchange) does not need to be stored in association with the terminating server. Rather, that private key is stored only at the external server, and there is no requirement for the pre-master secret to travel (on the wire).


Find Patent Forward Citations

Loading…