BRPI0505083B1

System and method for verifying digital signatures on certificates

Abstract

system and method for verifying digital signatures on certificates a system and method for verifying a digital signature on a certificate, which can be used in the processing of encrypted messages. in one version, when the digital signature is successfully verified in a signature verification operation, the public key used to verify that digital signature is stored in temporary memory. when a subsequent attempt to verify the digital signature is made, the public key to be used to verify the digital signature is compared with the key in provisional memory. if the keys match, the digital signature can be successfully verified without requiring a signature verification operation in which some data is decrypted using the public key.

BRPI0505083B1, drawing sheet 1
Sheet 1 of 29

Term

Term ended

Expired 27 October 2025, 0.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

4 claims: 4 independent, 0 dependent

  1. 1
    CLAIMS REIVINDICAÇÕES 1. Method (420b) for verifying a digital signature on a certificate for use on a computing device (100, 262a, 288), the method comprising the steps of:1. Método (420b) de verificação de uma assinatura digital em um certificado para uso em um dispositivo de computação (100, 262a, 288), o método compreendendo as etapas de: efetuar (450) uma primeira operação de verificação de assinatura na assinatura digital utilizando uma primeira chave pública associada a um emissor de certificado;perform (450) a first signature verification operation on the digital signature using a first public key associated with a certificate issuer;determinar se a assinatura digital é verificada com sucesso na primeira operação de verificação da assinatura;determine whether the digital signature is successfully verified in the first signature verification operation;armazenar (470b) a primeira chave pública e um resultado da verificação da assinatura digital em um armazém da memória;store (470b) the first public key and a result of the digital signature verification in a memory store;receber (430) uma solicitação para efetuar uma segunda operação de verificação de assinatura na assinatura digital utilizando uma segunda chave pública associada a um emissor do certificado;e comparar (440b) a segunda chave pública com a primeira chave pública armazenada no armazém da memória para determinar se as primeira e segunda chaves públicas casam, o método caracterizado pelo fato de que: receiving (430) a request to perform a second signature verification operation on the digital signature using a second public key associated with a certificate issuer;and compare (440b) the second public key with the first public key stored in the memory store to determine whether the first and second public keys match, the method characterized by the fact that: o resultado da verificação da assinatura digital compreende um resultado indicando se ou não a assinatura digital é verificada com sucesso;the result of the digital signature verification comprises a result indicating whether or not the digital signature is successfully verified;o método compreendendo ainda as etapas de: the method further comprising the steps of: if the first and second public keys match, determine (472) whether or not the stored result indicates that the previous verification attempt with this key was successful;and if the previous verification attempt with this key se as primeira e segunda chaves públicas casam, determinar (472) se o resultado armazenado indica ou não que a tentativa de verificação anterior com esta chave foi com sucesso;e se a tentativa de verificação anterior com esta chave Petition 870190008824, of 01/28/2019, p. 11/14 Petição 870190008824, de 28/01/2019, pág. 11/14
  2. 2
    2/4 foi com sucesso, indicar (480) a verificação bem sucedida da assinatura digital em resposta à solicitação, ou se a tentativa de verificação anterior com esta chave não foi com sucesso, indicar (490) a verificação mal sucedida da assinatura digital em resposta à solicitação, em que a segunda operação de verificação da assinatura não precisa ser efetuada. 2/4 was successful, indicate (480) the successful verification of the digital signature in response to the request, or if the previous verification attempt with this key was not successful, indicate (490) the unsuccessful verification of the digital signature in response to the request, in which the second signature verification operation does not need to be performed. 2. Método (420b), de acordo com a reivindicação 1, caracterizado pelo fato do dispositivo de computação ser um dispositivo móvel (100). two. Method (420b), according to claim 1, characterized in that the computing device is a mobile device (100).
  3. 3
    Computer readable medium comprising instructions for execution on a computing device (100, 262a, 288), characterized by the fact that the instructions, when executed, cause the said computing device (100, 262a, 288) to perform the steps in:3. Meio legível por computador compreendendo instruções para execução em um dispositivo de computação (100, 262a, 288) , caracterizado pelo fato de que as instruções, quando executadas, fazem com que o referido dispositivo de computação (100, 262a, 288) efetue as etapas de: efetuar (450) uma primeira operação de verificação de assinatura na assinatura digital utilizando uma primeira chave pública associada a um emissor de certificado;perform (450) a first signature verification operation on the digital signature using a first public key associated with a certificate issuer;determinar se a assinatura digital é verificada com sucesso na primeira operação de verificação da assinatura;determine whether the digital signature is successfully verified in the first signature verification operation;armazenar (470b) a primeira chave pública e um resultado da verificação da assinatura digital em um armazém da memória, o resultado indicando se ou não a assinatura digital é verificada com sucesso;store (470b) the first public key and a result of the verification of the digital signature in a memory store, the result indicating whether or not the digital signature is successfully verified;receber (430) uma solicitação para efetuar uma segunda operação de verificação de assinatura na assinatura digital utilizando uma segunda chave pública associada a um emissor do certificado;e comparar (440b) a segunda chave pública com a primeira chave pública armazenada no armazém da memória para receiving (430) a request to perform a second signature verification operation on the digital signature using a second public key associated with a certificate issuer;and compare (440b) the second public key with the first public key stored in the memory store for Petition 870190008824, of 01/28/2019, p. 12/14 Petição 870190008824, de 28/01/2019, pág. 12/14 3/4 determinar se as primeira e segunda chaves públicas casam, se as primeira e segunda chaves públicas casam, determinar (472) se o resultado armazenado indica ou não que a tentativa de verificação anterior com esta chave foi com sucesso;e se a tentativa de verificação anterior com esta chave foi com sucesso, indicar (480) a verificação bem sucedida da assinatura digital em resposta à solicitação, ou se a tentativa de verificação anterior com esta chave não foi com sucesso, indicar (490) a verificação mal sucedida da assinatura digital em resposta à solicitação, em que a segunda operação de verificação da assinatura não precisa ser efetuada. 3/4 determine whether the first and second public keys match, whether the first and second public keys match, determine (472) whether or not the stored result indicates that the previous verification attempt with this key was successful;and if the previous verification attempt with this key was successful, indicate (480) the successful verification of the digital signature in response to the request, or if the previous verification attempt with this key was unsuccessful, indicate (490) the unsuccessful digital signature verification in response to the request, where the second signature verification operation does not need to be performed.
  4. 4
    System (200, 250) for verifying a digital signature on a certificate comprising at least one computing device (100, 262a, 288), characterized by the fact that the computing device is adapted to execute instructions that cause the said computing device perform the steps of:4. Sistema (200, 250) para verificação de uma assinatura digital em um certificado compreendendo pelo menos um dispositivo de computação (100, 262a, 288), caracterizado pelo fato de que o dispositivo de computação é adaptado para executar instruções que fazem com que o referido dispositivo de computação efetue as etapas de: efetuar (450) uma primeira operação de verificação de assinatura na assinatura digital utilizando uma primeira chave pública associada a um emissor de certificado;perform (450) a first signature verification operation on the digital signature using a first public key associated with a certificate issuer;determinar se a assinatura digital é verificada com sucesso na primeira operação de verificação da assinatura;determine whether the digital signature is successfully verified in the first signature verification operation;armazenar (470b) a primeira chave pública e um resultado da verificação da assinatura digital em um armazém da memória, o resultado indicando se ou não a assinatura digital é verificada com sucesso;store (470b) the first public key and a result of the verification of the digital signature in a memory store, the result indicating whether or not the digital signature is successfully verified;receber (430) uma solicitação para efetuar uma segunda operação de verificação de assinatura na assinatura digital receive (430) a request to perform a second signature verification operation on the digital signature Petition 870190008824, of 01/28/2019, p. 13/14 Petição 870190008824, de 28/01/2019, pág. 13/14 4/4 using a second public key associated with a certificate issuer;and compare (440b) the second public key with the first public key stored in the memory store to determine whether the first and second public keys match, whether the first and second public keys match, determine (472) whether the stored result indicates or not that the previous verification attempt with this key was successful;and 4/4 utilizando uma segunda chave pública associada a um emissor do certificado;e comparar (440b) a segunda chave pública com a primeira chave pública armazenada no armazém da memória para 5 determinar se as primeira e segunda chaves públicas casam, se as primeira e segunda chaves públicas casam, determinar (472) se o resultado armazenado indica ou não que a tentativa de verificação anterior com esta chave foi com sucesso;e 10 if the previous verification attempt with this key was successful, indicate (480) the successful verification of the digital signature in response to the request, or if the previous verification attempt with this key was unsuccessful, indicate (490) the verification the digital signature has barely succeeded in response to the request, in which the second signature verification operation does not need to be performed. 10 se a tentativa de verificação anterior com esta chave foi com sucesso, indicar (480) a verificação bem sucedida da assinatura digital em resposta à solicitação, ou se a tentativa de verificação anterior com esta chave não foi com sucesso, indicar (490) a verificação mal 15 sucedida da assinatura digital em resposta à solicitação, em que a segunda operação de verificação da assinatura não precisa ser efetuada.