发明名称 SPLITTING CERTIFICATE STATUS RESPONSES EVENLY ACROSS MULTIPLE DISTRIBUTED CERTIFICATE STATUS RESPONDERS
摘要 Techniques are disclosed for evenly distributing certificate status validity messages across multiple response servers. A certificate authority (CA) may partition subsets of online certificate status protocol (OCSP) responses to each be handled by OCSP response servers. The partitions are based on serial numbers of the underlying digital certificates of the OCSP responses. For example, to determine which OCSP response server is assigned to distribute a particular OCSP response, a modulo operation may be performed between the last octet value of the underlying certificate serial number and the total number of available OCSP response servers of the CA. The result yields a partition number that may be used to identify the corresponding OCSP response server.
申请公布号 US2015244533(A1) 申请公布日期 2015.08.27
申请号 US201414186591 申请日期 2014.02.21
申请人 SYMANTEC CORPORATION 发明人 LY Hoa;VELADANDA Hari
分类号 H04L9/32 主分类号 H04L9/32
代理机构 代理人
主权项 1. A method for responding to requests to determine a validity status of a digital certificate, the method comprising: receiving, by a first response server, a request to provide a status of a digital certificate; evaluating the request to identify a response server, of a plurality of response servers, assigned to process the request; upon determining the identified response server is the first response server, sending a certificate status validity message corresponding to the request to a requesting client; and otherwise, forwarding the request to the identified response server.
地址 Mountain View CA US