AU2003259136A1

System and method for the transmission, storage and retrieval of authenticated documents

Abstract

Certificate Status Service that is configurable, directed, and able to retrieve status from any approved Certification Authority (CA) is disclosed. The CSS may be used by a Trusted Custodial Utility (TCU) and comparable systems or applications whose roles are validating the right of an individual to perform a requisite action, the authenticity of submitted electronic information objects, and the status of authentication certificates used in digital signature verification and user authentication processes. The validity check on authentication certificates is performed by querying an issuing CA. Traditionally, to create a trusted Public Key Infrastructure (PKI) needed to validate certificates, complex relationships are formed by cross- certification among CAs or by use of PKI bridges. The PKI and CA interoperability problem is addressed from a different point of view, with a focus on establishing a trust environment suitable for the creation, execution, maintenance, transfer, retrieval and destruction of electronic original information objects that may also be transferable records (ownership may change hands). A TCU is concerned only with a known set of "approved CAs" although they may support a multitude of business environments, and within that set of CAs, only with those certificates that are associated with TCU user accounts. Building PKI/CA trusted relationships is not required as the CSS achieves a trusted environment by querying only approved CAs and maintaining caches of valid certificates' status.

Term

Term ended

Projected expiry passed 17 July 2023, 3.2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

8 claims: 6 independent, 2 dependent

  1. 1
    What is claimed is:1. A method of providing a Certificate Status Service (CSS) for checking validities of authentication certificates issued by respective issuing Certification Authorities (CAs), comprising the steps of: 5 identifying information needed for retrieving a status of an authentication certificate from an issuing CA that issued the authentication certificate;configuring a connector based on the identified information for communicating with the issuing CA;communicating with the issuing CA according to the configured connector when 10 the status of the authentication certificate is queried;and retrieving the status of the authentication certificate;wherein the issuing CA and the connector are designated on a list of approved CAs in a configuration store.
  2. 4
    4/8 Signature Block Syntax Example Free form example of data elements making up a digital signature where the signature is applied to multiple message fragments and a date/time stamp. This example is not meant to be taken literally, but is meant to be illustrative of the type of syntax that may be used. · «Signature Method Algorithm = RSA (1024bit)/> «ReferenceContent> «ReferencetoFragmentl> «HashAlgorithm = SHA-1> A62E... · «ReferencetoFragment2> «HashAlgorithm = SHA-1> FOBC... «Authenticated Data> ...«/Date> ...«/Time> «/Authenticated Data> «HashAlgorithm = SHA-1> «CumulativeHashValue>6E31... «/ReferenceContent> «/Signedlnfo> 602C...«/SignatureValue> «Unauthenticated Data> < «/Unauthenticated Data> «KeyInfo> «Sequence of X.509 Data Elements> <X509Serial # <X509Issuer name «. . <X509Subject name <. . «X5 0 9Certif icate>MIIE...«/X5 09 Cert if icate> «/Keylnfo> The is the applied to HashValues one or more fragment or the total content and any Authenticated Data. Figure 4 WO 2004/010271 PCT/US2003/022191
  3. 5
    5/8 Hierarchical Member PKI r I Figure 5 WO 2004/010271 PCT/US2003/022191
  4. 6
    6/8 Λ Organization Agent Figure 6 WO 2004/010271 PCT/US2003/022191
  5. 7
    7/8 οΛ· Organization Agent Figure 7 WO 2004/010271 PCT/US2003/022191
  6. 8
    8/8 Automotive CA (OCSP) Financial CA (OCSP) Bank CA (CRL) certificate status —r-Internet· Certificate Status Service 805 Contract sent to Application Server Vault 801 Contract originated or retrieved 803 Dealer executes contract with lessee Tablet PC with signing pad 807 Contract retrieved 809 Contract signed at remote location Tablet PC with signing pad Figure 8 823 CSS queries Issuing CA 827 CSS reports certificate status 819 Application Server queries CSS 813 Contract received 811 Contract returned 821 CSS 821 CSS checks cache checks cache Oata Store Oata Store 833 Alert dealer of digital signature failure 815 Validates digital signature(s) 817 Checks validity period 831 Designates new version as authoritative copy Application Server 829 save in Electronic Vault Electronic Vault