CA2772136C

System and method for providing credentials

Abstract

A method and system for providing and issuing credentials wherein the first credential conforms to a first specified format and incorporates supplemental information to permit a requester or recipient of the first credential to create and utilize a second credential that conforms to a second specified format wherein the second specified format is different from the first specified format

CA2772136C, drawing sheet 1
Sheet 1 of 9

Term

4 yearsleft in the term

Expires 9 September 2030.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

26 claims: 9 independent, 17 dependent

  1. 1
    CA 02772136 2016-07-20 What is claimed is:1. A method performed by an information processing system for providing credentials, the method comprising: receiving, from a first correspondent that is external to the information processing system, a request to issue a first certificate securely identifying the first correspondent, wherein the first certificate is to conform to a first specified credential format supported by the first correspondent, and wherein the request is absent any certificates;generating, based on receiving the request, the first certificate in the first specified credential format;incorporating supplementary information comprising a second certificate into the first certificate, the second certificate conforming to a second specified credential format that is different from the first specified credential format, the second certificate permitted to be subsequently extracted by the first correspondent for permitting communication with a second correspondent using the second certificate according to the second specified credential format, and the supplementary information further comprising information permitting a construction of a private key by the first correspondent to be used with the second certificate in the second specified credential format;and issuing, to the first correspondent, the first certificate in the first specified credential format, the first certificate comprising the supplementary information comprising the second certificate in conformance with the second specified credential format, the first certificate providing the first correspondent with an option to communicate with the second correspondent using one of the first certi ficate and the second certificate according to the first specified credential format and the second specified credential format, respectively.
  2. 4
    The method according to any one of claims 1 to 3, wherein the first certificate is signed using a first key, and wherein the supplementary information is generated using a second key.
  3. 5
    A method of generating a first certificate at a certification authority to authenticate a public key of a first correspondent that is external to the certification authority, the method comprising:generating the first certificate and including the public key in the first certificate such that the first certificate conforms to a first specified credential format supported by the first correspondent, the first certificate permitting the first correspondent to communicate with a second correspondent according to the first specified credential format;and including, in· the first certificate, supplementary information conforming to a second specified credential format that is different from the first specified credential format, the supplementary information permitted to be subsequently extracted by the second correspondent, after receiving the first certificate for permitting conversion of the first certificate into a second certificate of the second specified credential format, the supplementary information comprising information permitting construction of a private key by the second correspondent to be used with the second certificate in accordance with the second specified credential format, the second certificate permitting the first correspondent to communicate with the second correspondent according to the second specified credential format.
  4. 9
    A method performed by a requestor device for obtaining credentials, the method comprising:sending a request to a certification authority to issue a first certificate, wherein the certification authority is external to the requestor device, and wherein the request is absent any certificates;receiving, based on sending the request, the first certificate according to a first specified credential format, the first certificate comprising supplementary information comprising a second certificate conforming to a second specified credential format, wherein the second specified credential format is different from the first specified credential format;extracting the supplementary information from the first certificate;constructing,· based on the extracting, a private key utilizing the supplementary information conforming to the second specified credential format;and transmitting the second certificate and the private key to a recipient, the second certificate conforming to the second specified credential format.
  5. 11
    A method performed by a server for providing certificates in a public key cryptographic system, the method comprising:receiving a request from a first correspondent to issue a first certificate, wherein the first correspondent is external to the server, and wherein the request is absent any certificates;generating, based on receiving the request, the first certificate associated with the first correspondent, the first certificate conforming to a first specified credential format;obtaining supplementary information, the supplementary information comprising a second certificate conforming to a second specified credential format that is different from the first specified credential format, the second certificate permitting the first correspondent to communicate with a second correspondent according to the second specified credential format, and the supplementary information further comprising information permitting a construction of a private key -22CA 02772136 2016-07-20 by the first correspondent to be used with the second certificate in the second specified credential format;inserting the supplementary information into the first certificate permitting the first correspondent to subsequently extract the second certificate and the information permitting construction of the private key;and issuing the first certificate to the first correspondent, the first certificate providing the first correspondent with an option to communicate with the second correspondent using one of the first certificate and the second certificate according to the first specified credential format and the second specified credential format, respectively.
  6. 13
    A computer readable medium comprising computer executable instructions for providing credentials, the computer readable medium including instructions for performing the acts of any one of claims 1 to 4.
  7. 14
    A computer readable medium comprising computer executable instructions for generating a certificate at a certification authority to authenticate a public key of a correspondent, the computer readable medium including instructions for performing the acts of any one of claims 5 to 8.
  8. 17
    A computing device in a cryptographic system configured for providing credentials, the computing device comprising a processor configured for performing the acts of any one of claims 1 to 4. -23 CA 02772136 2016-07-20
  9. 18
    A computing device in a cryptographic system configured for generating a certificate at a certification authority to authenticate a public key of a correspondent, the computing device comprising a processor configured for performing the acts of any one of claims 5 to 8.
  10. 22
    The computing device according to any one of claims 19 to 21, wherein the computing device comprises a server.
  11. 23
    The computing device according to any one of claims 19 to 22, wherein the computing device comprises a cell phone.
  12. 24
    The computing device according to any one of claims 19 to 23, wherein the computing device comprises a smart phone.
  13. 26
    The computing device according to any one of claims 17, 18 and 25, wherein the computing device comprises a server.