EP1162783A2

System and method for efficient and secure revocation of a signature certificate in a public key infrastructure

Abstract

System and method for revocation of a signature certificate in a Public Key Infrastructure (PKI) that includes an enterprise with one or more servers, a directory, a registration web server, and one or more client platforms that allow users to access the servers of the enterprise. A user may desire to revoke a potentially compromised signature certificate of the user, or a manger of the user may revoke a signature certificate because it has been lost by the user, or the manager no longer desires that the user has access to servers of an enterprise. A user or personal revocation authority (manager) initiates a revocation process by creating an authenticated secure channel with a registration web server. Using the authenticated secure channel, the user or personal revocation authority requests the registration web server revoke a user signature certificate. The registration web server queries a directory to verify that the personal revocation authority is permitted to revoke the signature certificate of the user. The user signature certificate is revoked. The directory is notified by the registration web server of revocation of the user signature certificate. A user entry in the directory is set to a state without a signature certificate. A process for a new signature certificate for the user may now occur.

EP1162783A2, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Projected expiry passed 31 May 2021, 5.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

28 claims: 3 independent, 25 dependent

  1. 1
    A method for revocation of a signature certificate in a Public Key Infrastructure (PKI) comprising:creating an authenticated secure channel with a registration web server;requesting the registration web server revoke a user signature certificate, the requesting occurring over the authenticated secure channel;revoking the user signature certificate;notifying a directory by the registration web server of revocation of the user signature certificate;and setting a user entry in the directory to a state without a signature certificate.
  2. 18
    An article comprising a storage medium having instructions stored therein, the instructions when executed causing a processing device to perform:creating an authenticated secure channel with an entity;receiving a request from the entity to revoke a user signature certificate;revoking the user signature certificate;and notifying a directory of revocation of the user signature certificate.
  3. 23
    A system for revocation of a signature certificate in a Public Key Infrastructure (PKI) comprising:at least one server operably connected to a network;a directory operably connected to the network, the directory containing information on at least one user;at least one client platform operably connected to the network, the at least one user having access to the at least one server from the at least one client platform;and a registration web server operably connected to the network, the registration wet server receiving a request for revocation of a user signature certificate from an entity, the registration web server revoking the user signature certificate only if the entity is permitted to revoke the user signature certificate, the registration web server notifying the directory of revocation of the user signature certificate if revoked.