发明名称 DYNAMIC CERTIFICATE GENERATION ON A CERTIFICATE AUTHORITY CLOUD
摘要 Techniques are disclosed for dynamically generating a digital certificate for a customer server. A customer server creates a certificate profile and receives an associated profile identifier from a certificate authority (CA). The customer server installs an agent application received from the CA. The agent application generates a public/private key pair and an identifier associated with the customer server. The agent application sends a signed request to the CA that includes the profile identifier, server identifier, and the public key corresponding to the key pair. Upon receiving the credentials, the CA generates a dynamically updatable certificate. Thereafter, if the customer changes information associated with the certificate (or if external conditions require a change to the certificate, such as a key compromise or change in security standards), the CA may generate an updated certificate based on the certificate profile changes and the public key.
申请公布号 US2015095995(A1) 申请公布日期 2015.04.02
申请号 US201314042294 申请日期 2013.09.30
申请人 Symantec Corporation 发明人 BHALERAO Kokil
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method for updating a digital certificate, the method comprising: monitoring a certificate profile of a first certificate to detect a change in the certificate profile, in response to a detected change, sending a request to a certificate authority (CA) to generate a second certificate, wherein the request includes a first public key, a server identifier, and a profile identifier, and wherein attributes of the second certificate reflect the detected change in the certificate profile; receiving the second certificate from the CA; and deploying the second certificate on a server in place of the first certificate.
地址 Mountain View CA US