CA2492986C

System and method for a remote access service enabling trust and interoperability when retrieving certificate status from multiple certification authority reporting components

Abstract

Certificate Status Service that is configurable, directed, and able to retrieve status from any approved Certification Authority (CA) is disclosed. The CSS may be used by a Trusted Custodial Utility (TCU) and comparable systems or applications whose roles are validating the right of an individual to perform a requisite action, the authenticity of submitted electronic information objects, and the status of authentication certificates used in digital signature verification and user authentication processes. The validity check on authentication certificates is performed by querying an issuing CA. Traditionally, to create a trusted Public Key Infrastructure (PKI) needed to validate certificates, complex relationships are formed by cross- certification among CAs or by use of PKI bridges. The PKI and CA interoperability problem is addressed from a different point of view, with a focus on establishing a trust environment suitable for the creation, execution, maintenance, transfer, retrieval and destruction of electronic original information objects that may also be transferable records (ownership may change hands). A TCU is concerned only with a known set of "approved CAs" although they may support a multitude of business environments, and within that set of CAs, only with those certificates that are associated with TCU user accounts. Building PKI/CA trusted relationships is not required as the CSS achieves a trusted environment by querying only approved CAs and maintaining caches of valid certificates' status.

CA2492986C, drawing sheet 1
Sheet 1 of 9

Term

Term ended

Expired 17 July 2023, 3.2 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

32 claims: 2 independent, 30 dependent

  1. 1
    CA 02492986 2010-04-06 The embodiments of the invention in which an exclusive property or privilege is claimed are defined as follows:1. A method of providing a Certificate Status Service (“CSS”) for checking validities of certificates issued by respective issuing Certification Authorities (“CAs”), comprising the steps of: receiving status queries for one or more certificates from requesting entities;if the issuing CAs are not found on the CSS’s list of approved CAs or the certificates have expired, returning invalid certificate statuses for those certificates;if the current certificate statuses are found in a CSS’s cache memory, returning the found certificates’ statuses;if any certificate statuses have not yet been determined, fetching all certificate status reporting means and communications information on the location of status reporting component and processing of retrieved certificate statuses from a configuration store of the CSS that are needed for retrieving the status of each certificate whose status has not yet been determined from the respective issuing CAs;configuring connectors based on the communications information for communicating with the issuing CAs;communicating with the issuing CAs according to the configured connectors;retrieving the status of all queried certificates;processing the certificate statuses according to certificate status reporting methods implemented by the CSS including one of Certificate Revocation Lists (CRLs) that are retrieved at specified publication intervals, Delta Certificate Revocation Lists, (ACRLs) that are retrieved upon notification, and a real-time certificate status retrieval protocol;recording retrieved certificate statuses in the CSS’s cache memory;returning the retrieved certificate statuses to the requesting entities;wherein the issuing CAs and connector parameters, which enable the CSS to interwork with any CAs and CA domains even though the CSS and issuing CAs may operate using dissimilar certificate practices and policies, are designated on a list of approved CAs in the configuration store. CA 02492986 2010-04-06
  2. 16
    A method of executing a transaction between a first party and a second party by transferring control of an authenticated information object having a verifiable evidence trail, the method comprising the steps of retrieving an authenticated information object from a trusted repository, wherein the authenticated information object includes a first digital signature block comprising a digital signature of a first party and a first certificate relating at least to an identity and a cryptographic key to the first party, a date and time indicator, and a second digital signature block comprising a second digital signature of the trusted repository and a second certificate relating at least an identity and a cryptographic key to the trusted repository;the first digital signature block was validated by the trusted repository;and the authenticated information object is stored as an electronic original information object under the control of the trusted repository;executing the retrieved authenticated information object by the second party by including in the retrieved authenticated information object a third digital signature block comprising at least a third digital signature and a third certificate of the second party;and forwarding the executed retrieved authenticated information object to a trusted custodial utility (“TCU”), wherein the TCU verifies digital signatures and validates certificates associated with the digital signatures included in information objects by at least retrieving status of the certificates from a Certificate Status Service (“CSS”) provided according to claim 1;the TCU rejects a digital signature block if the respective digital signature is not verified or the status of the respective certificate is expired or is revoked;and if at least one signature block in the information object is not rejected, the TCU appends the TCU’s digital signature block and a date and time indicator to the information object and takes control of the object on behalf of the first party.