会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 5. 发明申请
    • METHOD AND APPARATUS FOR PROTECTING AGAINST A ROGUE CERTIFICATE
    • 用于保护ROGUE CERTIFICATE的方法和装置
    • WO2012094035A1
    • 2012-07-12
    • PCT/US2011/027662
    • 2011-03-09
    • QUALCOMM IncorporatedBROWN, Craig M.NORTHWAY, Craig W.PURSER, Jessica M.
    • BROWN, Craig M.NORTHWAY, Craig W.PURSER, Jessica M.
    • H04L9/32
    • H04L9/3265H04L63/0823H04L2209/80
    • Disclosed is a method for protecting against a rogue certificate. In the method, a web client receives a first certificate from a server during an initial session. The first certificate has a first certificate chain to an authority certificate signed by a certificate authority. The web client receives a second certificate during a subsequent session. The second certificate has a second certificate chain to a signed authority certificate. The web client assigns a signature security rating to each chain certificate in the first and second certificate chains. The web client compares the signature security rating of each corresponding chain certificate in the first and second certificate chains. The web client treats the second certificate as insecure if the signature security rating of a chain certificate in the second certificate chain is lowered from that of a corresponding chain certificate in the first certificate chain.
    • 公开了一种防止流氓证书的方法。 在该方法中,Web客户端在初始会话期间从服务器接收第一证书。 第一个证书具有由证书颁发机构签署的授权证书的第一个证书链。 Web客户端在后续会话期间接收第二个证书。 第二个证书具有签署的权限证书的第二个证书链。 Web客户端为第一和第二证书链中的每个链证书分配签名安全评级。 Web客户端比较第一和第二证书链中每个相应链证书的签名安全级别。 如果第二证书链中的链证书的签名安全级别与第一证书链中的相应链证书的签名安全级别相比较,则Web客户端将第二证书视为不安全。