EP1162781A2

System and method for generation of a signature certificate in a public key infrastructure

Abstract

System and method for generation of a signature certificate in a Public Key Infrastructure (PKI) that includes sending a new user a first piece of information required for generation of a signature certificate for the new user. A personal registration authority is sent a second piece of information required for generation of a signature certificate for the new user. The second piece of information is delivered to the new user by the personal registration authority in a face-to-face meeting. The first piece of information and the second piece of information are provided to a registration authority by the new user. A key pair is generated for the new user that includes a public key and a private key. The public key is provided to a certification authority. A signature certificate is generated for the new user by the certification authority. The certification authority digitally signs the signature certificate. The digitally signed signature certificate is then stored in a database.

EP1162781A2, drawing sheet 1
Sheet 1 of 4

Term

Term ended

Projected expiry passed 31 May 2021, 5.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

32 claims: 6 independent, 26 dependent

  1. 1
    A method for generation of a signature certificate in a Public Key Infrastructure (PKI) comprising:sending a new user a first piece of information required for generation of a signature certificate for the new user;sending a personal registration authority a second piece of information required for generation of a signature certificate for the new user;delivering the second piece of information to the new user by the personal registration authority in a face-to-face meeting;providing the first piece of information and the second piece of information to a registration authority by the new user;generating a key pair for the new user comprising a public key and a private key;providing the public key to a certification authority;and generating and digitally signing a signature certificate for the new user by the certification authority.
  2. 11
    The method according to 10, wherein the verifying comprises:generating a digest by executing an algorithm on a document by the new user;generating a digital signature by encrypting the digest using the private key of the new user;sending a document from the new user to the second user;receiving the document from the new user by the second user, the document having the digital signature appended to the document;using the public key referenced in the signature certificate of the new user to decrypt the appended digital signature;generating a received digest by executing the algorithm on the received document by the second user;and verifying the digital signature of the new user by comparing the decrypted digital signature with the received digest.
  3. 20
    A method for generation of a signature certificate in a Public Key Infrastructure (PKI) comprising:entering data about a new user into a database;requesting access to an enterprise server by the new user;querying the database for new user information by a registration authority;sending a new user a first piece of information required for generation of a signature certificate for the new user;sending a personal registration authority a second piece of information required for generation of a signature certificate for the new user;delivering the second piece of information to the new user by the personal registration authority in a face-to-face meeting;providing the first piece of information and the second piece of information to a registration authority by the new user;registering the new user by the registration authority;generating a key pair for the new user comprising a public key and a private key;providing the public key to a certification authority;generating and digitally signing a signature certificate for new user by the certification authority;and sending the signed signature certificate to the database.
  4. 27
    An article comprising a storage medium having instructions stored therein, the instructions when executed causing a processing device to perform:querying a database for new user information;sending the new user a first piece of information required for generation of a signature certificate for the new user;sending a personal registration authority a second piece of information required for generation of a signature certificate for the new user;receiving the first piece of information and the second piece of information from the new user;registering the new user;and signaling a client platform to generate a key pair for the new user comprising a public key and a private key.
  5. 28
    An article comprising a storage medium having instructions stored therein, the instructions when executed causing a processing device to perform:receiving a public key from a user;generating a signature certificate for the user;digitally signing the signature certificate;and sending the digitally signed signature certificate to a database.
  6. 29
    A system for generating a signature certificate in a Public Key Infrastructure (PKI) comprising:at least one server operably connected to a network;a database operably connected to the network, the database containing information on at least one user;a directory operably connected to the network, the directory containing the same information as the database but providing faster access to the information;at least one client platform operably connected to the network, the at least one user requesting access to the at least one server from the at least one client platform;and a registration web server operably connected to the network, the registration web server sending the new user a first piece of information required for generation of a signature certificate for the new user and sending a personal registration authority a second piece of information required for generation of a signature certificate for the new user, and wherein the second piece of information is delivered to the new user by the personal registration authority in a face-to-face meeting, the first piece of information and the second piece of information being used by the new user in a process for generation of public and private keys and a signature certificate for the new user.