EP1517514A2

Method for installing and updating certificates used for device authentication.

Abstract

A communication apparatus, a communication system, a communication apparatus control method and a recording medium for storing an implementation program thereof are disclosed. The communication apparatus includes a communication part providing a communicating party with an individual certificate with identification information thereof as via a first address and a common certificate without the identification information via a second address; a request execution part executing a process corresponding to a request received from the communicating party; and a denial part denying any process corresponding to requests other than a request to set the individual certificate in communication via the second address. According to the invention, it is possible to easily maintain a condition where authentication can be properly performed while maintaining security of communication.

EP1517514A2, drawing sheet 1
Sheet 1 of 21

Term

Term ended

Projected expiry passed 22 September 2024, 2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

22 claims: 13 independent, 9 dependent

  1. 1
    A communication apparatus having a communication part providing a digital certificate to a communicating party via a plurality of addresses so as to obtain authentication and communicating to the communicating party via an address providing the digital certificate authenticated by the communicating party, and a request execution part executing a process corresponding to a request received from the communicating party by the communication part, characterized in that    the communication part provides an individual certificate with identification information of the communication apparatus as the digital certificate via a first address of the plurality of addresses and a common certificate without the identification information as the digital certificate via a second address of the plurality of addresses, and    the communication apparatus further includes a denial part denying any process corresponding to requests other than a request to set the individual certificate in communication via the second address.
  2. 4
    The communication apparatus as claimed in any of claims 1 through 3, characterized in that the request execution part includes a plurality of request processing parts, each of the request processing parts performing a predefined process corresponding to the request.
  3. 6
    The communication apparatus as claimed in any of claims 1 through 5, characterized in that the request is described as a SOAP message.
  4. 7
    The communication apparatus as claimed in any of claims 1 through 6, characterized in that    the authentication is performed in accordance with SSL or TLS, and    the digital certificate includes a public-key certificate used for the authentication.
  5. 8
    A communication system having at least one lower-level apparatus and at least one upper-level apparatus communicating to the at least one lower-level apparatus as a communicating party, wherein each of the at least one lower-level apparatus includes a communication part providing a digital certificate to the communicating party via a plurality of addresses so as to obtain authentication and communicating to the communicating party via an address providing the digital certificate authenticated by the communicating party and a request execution part executing a process corresponding to a request received from the communicating party by the communication part, characterized in that    the communication part provides an individual certificate with identification information of the communication apparatus as the digital certificate via a first address of the plurality of addresses and a common certificate without the identification information as the digital certificate via a second address of the plurality of addresses,    each of the at least one lower-level apparatus includes a denial part denying any process corresponding to requests other than a request to set the individual certificate in communication via the second address, and    each of the at least one upper-level apparatus includes an authentication part authenticating the at least one lower-level apparatus by using a digital certificate received from the at least one lower-level apparatus.
  6. 11
    The communication system as claimed in any of claims 8 through 10, characterized in that the request is described as a SOAP message.
  7. 12
    The communication system as claimed in any of claims 8 through 11, characterized in that    the authentication is performed in accordance with SSL or TLB, and    the digital certificate includes a public-key certificate used for the authentication.
  8. 13
    A method of controlling a communication apparatus, the method having steps of providing a digital certificate via a plurality of addresses so as to obtain authenticate from a communicating party, communicating to the communicating party via an address providing the digital certificate authenticated by the communicating party, and performing a process corresponding to a request received from the communicating party in the communication, characterized in that    the providing step provides an individual certificate with identification information of the communication apparatus as the digital certificate via a first address of the plurality of addresses and a common certificate without the identification information as the digital certificate via a second address of the plurality of addresses, and    the method further includes a step of denying any process corresponding to processes other than a process to set the individual certificate in communication via the second address.
  9. 16
    The method as claimed in any of claims 13 through 15, characterized in that the request is described as a SOAP message.
  10. 17
    The method as claimed in any of claims 13 through 16, characterized in that    the authentication is performed in accordance with SSL or TLS, and    the digital certificate includes a public-key certificate used for the authentication.
  11. 18
    A recording medium for storing a program to cause a computer to execute a procedure, the procedure having steps of providing a digital certificate via a plurality of addresses so as to obtain authenticate from a communicating party, communicating to the communicating party via an address providing the digital certificate authenticated by the communicating party, and performing a process corresponding to a request received from the communicating party in the communication, characterized in that    the providing step provides an individual certificate with identification information of the communication apparatus as the digital certificate via a first address of the plurality of addresses and a common certificate without the identification information as the digital certificate via a second address of the plurality of addresses, and    the procedure further includes a step of denying any process corresponding to processes other than a process to set the individual certificate in communication via the second address.
  12. 21
    The recording medium as claimed in any of claims 18 through 20, characterized in that the request is described as a SOAP message.
  13. 22
    The recording medium as claimed in any of claims 18 through 21, characterized in that    the authentication is performed in accordance with SSL or TLS, and    the digital certificate includes a public-key certificate used for the authentication.