Nova Patents
EP0869637A2

Digital certification system

Abstract

The present invention provides a digital certification system which allows a user to add information to a digital certificate without requiring the re-issuance of the digital certificate and the invalidating of all distributed copies of the previous certificate. The invention comprises a digital certificate and the associated computer system and procedure which support its usage. The certificate of the present invention is split into two components. One component (the "certificate index") is distributed to the user and the public. The other component (the "certificate information") is maintained by the certification authority in a publicly available trusted repository. In one embodiment, a certification authority generates a unique user ID for an applicant for a digital certificate. The certification authority then issues a digital certificate index containing the unique user ID, the user's public key, and the user's name. Unlike in the prior art, in the present invention, additional certificate information (such as, for example, the user's E-mail address) is excluded from the digital certificate index. Instead, such additional certificate information is maintained by a certification authority in a publicly available trusted repository. The location of the additional information is indicated by the unique ID. Instead of linking a public key, a user name, and the additional information, the digital certificate of the present invention links a public key with an unchanging user ID, which indicates where the additional certificate information may be found. The present invention thus allows a certification authority to change the additional certificate information at the request of the user without requiring issuance of a new certificate.

EP0869637A2, drawing sheet 1
Sheet 1 of 12

Term

Term ended

Projected expiry passed 1 April 2018, 8.5 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

35 claims: 5 independent, 30 dependent

  1. 1
    A digital certificate for authenticating an association between a user and a public key of said user; said digital certificate comprising a first set of data related to said digital certificate; said first set of data comprising:said public key of said user;an indicator identifying a location for obtaining a second set of data related to said digital certificate.
  2. 11
    A method for issuing a digital certificate authenticating an association between a user and a public key of said user, said method comprising the steps of:receiving a certificate application, said application comprising said public key of said user and information related to said user;generating a pointer to a storage system;constructing a digital certificate comprising a first set of data comprising: said pointer;said public key of said user;and a first portion of said information related to said user;storing a second set of data comprising a second portion of said information related to said user in said storage system.
  3. 20
    A program storage device readable by a machine, tangibly embodying a program of instructions executable by the machine to perform method steps for authenticating an association between a user and a public key, said method comprising the steps of:receiving a certificate application from said user, said application comprising a public key of said user and user data;verifying said user data;generating a unique user ID pointing to a repository;constructing a digital certificate comprising a first set of data comprising: said unique user ID;said public key of said user;generating a message digest of said first set of data;encrypting said message digest with a private key to generate a digital signature of said digital certificate;storing a second set of data comprising a portion of said user data in said repository.
  4. 27
    An article of manufacture comprising:a computer usable medium having computer readable program code embodied therein for authenticating an association between a user and a public key, the computer readable program code in said article of manufacture comprising: computer readable code configured to cause a computer to receive a certificate application, said application comprising a public key of said user and information related to said user;computer readable code configured to cause said computer to generate a pointer to a storage system;computer readable code configured to cause said computer to construct a digital certificate comprising a first set of data comprising: said pointer;said public key of said user;and a first portion of said information related to said user;computer readable code configured to cause said computer to store a second set of data comprising a second portion of said information related to said user in said storage system.
  5. 34
    A method for verifying the authenticity of an electronic document based on digital certification, wherein said electronic document is digitally signed by a sender and said digital certificate is issued by a certificate issuer, said method comprising the steps of:obtaining a digital signature of said electronic document signed by said sender;obtaining a digital certificate for said sender, wherein said digital certificate comprises a unique user ID and a public key of said user, said unique user ID uniquely identifying a location in a repository;obtaining user information from said repository location using said unique user ID;verifying an authenticity of said electronic document using said public key of said sender.