EP1371171B1

Scalable certificate validation and simplified PKI management

Abstract

This record has no abstract on file.

EP1371171B1, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Expired 20 March 2022, 4.5 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

15 claims: 1 independent, 14 dependent

  1. 1
    A method of managing a digital certificate, comprising:a landlord certificate authority providing a digital certificate;a secure hardware device generating a series of n hash values;the secure hardware device providing an nth hash value to the landlord certificate authority, wherein other hash values are not readily available to the landlord certificate authority;the landlord certificate authority placing the nth hash value in the certificate;the landlord certificate authority digitally signing the certificate containing the nth hash value to obtain a digitally signed certificate;a tenant certificate authority obtaining the digitally signed certificate;the tenant certificate authority obtaining the n hash values;the tenant certificate authority periodically issuing a proof of validity that is a hash value previous to the nth hash value in the series of n hash values if the certificate is valid when the proof is issued by the tenant certificate authority.
  2. 3
    The method according to Claim 2, wherein the card receives the proof from a wired card device.
  3. 4
    The method according to Claim 2, wherein the card is contactless.
  4. 5
    The method according to Claim 2, wherein the card is at least one of:a cellular phone and a PDA.
  5. 6
    The method according to Claim 2, wherein the card receives the proof wirelessly.
  6. 8
    The method according to Claim 1, wherein a relying party queries for and receives the proof from the tenant certificate authority.
  7. 9
    The method according to Claim 2, wherein the card also carries the digitally signed certificate.
  8. 10
    The method according to Claim 9, wherein the digitally signed certificate is relative to a public key certified within the digital certificate contained in the card.
  9. 11
    The method according to Claim 10, wherein the card presents to the mechanism of the door both the proof and the digitally signed certificate.
  10. 12
    The method according to Claim 1, wherein the proof is locally verified by iterating a one-way hash function on the proof a number of times and comparing a result thereof to the nth hash value included in the digitally signed certificate.
  11. 13
    The method according to Claim 2, wherein the proof is one of a plurality of proofs relative to a plurality of access rights to the door.
  12. 14
    The method according to Claim 13, wherein a single authority manages the plurality of access rights.