EP1287637A2

Method and apparatus for self-authenticating digital records

Abstract

A method for proving the validity of a digital document digitally signed using a digital key that corresponds to a digital certificate in a chain of digital certificates issued by certification authorities within a hierarchy of certification authorities. At least one secure digital time stamp is applied to at least one record comprising the digital document, the digital signature, certificate chain data, and information relating to the revocation of certificates by certification authorities within the certificate chain. If, at some later time, one or more digital certificates either expire or are revoked, the timestamp serves as evidence of the integrity of the signed digital document.

Term

Term ended

Projected expiry passed 16 May 2021, 5.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

29 claims: 5 independent, 24 dependent

  1. 1
    Claims of equivalent WO 0189133 A2 THE CLAIMS What is claimed is:1. A method of authenticating a first document, the method comprising: a step of digitally signing the first document using a first digital certificate provided by a first certification authority to produce a first digital signature;a step of obtaining a second digital certificate issued by a second certification authority to the first certification authority, wherein the second digital certificate was used to issue the first digital certificate;a step of obtaining first and second certificate revocation information identifying digital certificates which have been revoked by said first and second certification authorities, respectively;and a step of requesting that at least one secure digital timestamp be applied to the digitally signed first document, the first and second digital certificates, and the first and second certificate revocation information, to thereby establish a point in a time when the first digital signature was valid.
  2. 11
    The method of claiml , further comprising:a step of obtaining a third digital certificate issued by a third certification authority to the second certification authority;and a step of obtaining third certificate revocation information identifying digital certificates which have been revoked by the third certification authority;and wherein the step of requesting, requests that said at least one secure digital timestamp be applied to the digitally signed first document, the first, second and third digital certificates, and the first, second and third certificate revocation information.
  3. 19
    A method for a user to authenticate a first document in a hierarchy of certification authorities including a chain of certification authorities having at least an integer number N levels, N ≥2, the chain including a first level certification authority having an associated self-signed root certificate and an N-th level certification authority, wherein the k"1 level certification authority is issued a k^-level digital certificate by the certification authority in the k-lth level, for k:2 ≤ k < N, and wherein an mth level certification authority, for some m: 2 ≤ m < N, issues a user's digital certificate to the user, the method comprising: a step of digitally signing the first document using the user's digital certificate to produce a first digital signature;a step of obtaining a certificate chain corresponding to the user's digital certificate, the certificate chain comprising a total of m digital certificates, one from each of the m certification authorities in the certificate chain;a step of obtaining certificate revocation information corresponding to the m certification authorities, the certificate revocation information identifying digital certificates which have been revoked by the m certification authorities;and a step of requesting that at least one secure digital timestamp be applied to the digitally signed first document, the user's digital certificate, the certificate chain and the certificate revocation information.
  4. 22
    A method of authenticating a first document, the method comprising:a step of digitally signing the first document to thereby create a digital signature;and a step of requesting that at least one secure digital timestamp be applied to the digitally signed first document and also to validation information which attests to the validity of the digital signature.
  5. 27
    A computer readable medium having executable software code thereon, the executable software code comprising:code to digitally sign a first document to thereby create a first digital signature;code to request that at least one secure digital timestamp be applied to the digitally signed first document and also to validation information which attests to the validity of the digital signature.