EP0328232B1

Public key/signature cryptosystem with enhanced digital signature certification.

Abstract

This record has no abstract on file.

EP0328232B1, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Expired 6 January 2009, 17.7 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

13 claims: 1 independent, 12 dependent

  1. 1
    In a communication system having a plurality of terminal devices (terminals A to N) coupled to a channel (12) over which users of said terminal devices may exchange messages, at least some of said users having a public key (30) and an associated private key (32), a method for managing authority by digitally signing and certifying a digital message to be transmitted to an independent recipient comprising the steps of:generating at least a portion of said digital message (20);digitally signing at least said portion of said message (40);and characterised by    associating with said message an authorizing digital certificate (28,116) having a plurality of digital fields created by a certifier, said authorizing certificate being created by the steps of:    specifying by the certifier in at least one of said digital fields, the authority which is vested in the certifier and which has been delegated to the signer of said message, by including sufficient digital information to enable said independent recipient of said message to verify, by electronically analyzing said message in accordance with a predetermined validation algorithm, that the authority exercised by the signer in signing the content of said message created by the signer was properly exercised by the signer in accordance with the authority delegated by the certifier;and    identifying the certifier who has created the signer's certificate in other of said digital fields by including sufficient digital information for said recipient of the message to determine by electronically analyzing said message that the certifier has been granted the authority to grant said delegated authority.
  2. 2
    A method according to Claim 1, further including the step of providing at least one field in said message identifying the nature of the digital data being transmitted.
  3. 3
    A method according to Claim 1, wherein the formulating step includes the step of providing a field allowing the user to insert a predetermined comment (26) regarding the date being transmitted.
  4. 4
    A method according to Claim 1, further including the step of applying a hashing function (34) to at least a portion of the message to be transmitted to form a presignature hash (36);and wherein the digitally signing step includes the step of processing said presignature hash with the signer's private key (32) to form said digital signature.
  5. 5
    A method according to Claim 4, further including the step of forming a digital signature packet (42) comprising the digital signature and a representation of said at least a portion of the message to be transmitted.
  6. 6
    A method according to Claim 1, wherein said authorizing certificate (116) includes digital fields defining the cosignature requirements which must accompany the signer's signature in order for the signer's signature to be treated as properly authorized.
  7. 7
    A method according to Claim 6, wherein said digital fields defining co-signature requirements set forth a required digital signature by a specified third party indicating approval of the signer's signature (116) to thereby define a counter signature requirement.
  8. 8
    A method according to Claim 7, wherein the third party countersigns (86) by digitally signing the signer's digital signature.
  9. 9
    A method according to Claim 6, wherein the cosignature requirements include a digital field specifying at least one other digital signature which is required to appear in the digital message thereby defining a joint signature requirement (116).
  10. 10
    A method according to Claim 1, wherein said authorizing certificate includes at least one digital field defining limitations as to the authority granted by the certificate (116).
  11. 11
    A method according to Claim 10, further including the step of specifying a monetary limit for the signer in a digital field in said certificate (116).
  12. 12
    A method according to Claim 1, wherein said authorizing certificate (116) includes at least one digital field defining a trust level indicative of the degree of responsibility delegated to the signer by the certifier.
  13. 13
    A method according to Claim 1, wherein said identifying step includes the step of specifying in digital fields in said authorizing certificate a hierarchy of certificates, whereby a recipient of the message can electronically verify in accordance with a predetermined validation algorithm the authority of the signer based upon an analysis of the signed message.