EP1573474A2

Key server for security and implementing processes with nonrepudiation and audit

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 26 November 2023, 2.8 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

83 claims: 9 independent, 74 dependent

  1. 1
    Claims of equivalent WO 2004049137 A2 N THE CLAIMS What is claimed is:1. A system for securely communicating a message between a plurality of participants, wherein the message has a message header and a message content, the system comprising: a message router that connects the participants via a network and delivers the message between the participants based on the message header;and a key server that stores and releases conversation keys to the participants, wherein said conversation keys are used to apply protection to the message content of the message.
  2. 16
    A method for securely communicating a message between a plurality of participants in a network, wherein the participant sending the message is a source participant and the participants receiving the message are destination participants and the message has a message header and a message content, the method comprising:(a) at the source participant: (1) obtaining a conversation key;(2) applying protection to the message content of the message based on said conversation key, wherein said protection includes at least one member of the set consisting of encrypting and hashing;and (3) sending the message to the destination participants via the network;and (b) at the destination participants: (1) receiving the message from the source participant via the network;(2) obtaining said conversation key from a key server also in the network;and (3) processing the message content of the message based on said conversation key, wherein said processing includes at least one of decrypting and hash analysis.
  3. 29
    A system for determining communications events, comprising:a key server to release keys to communicating parties, wherein said keys are encryption keys to encrypt or decryption keys to decrypt the communications and said communicating parties include originators seeking to create and recipients seeking to view the communications;and for each of the communications, said key server also to: assign an identifier;store a record in a database that includes said identifier, a respective said decryption key, and respective controlling events;receive zero, one, or more requests for said decryption key, wherein said requests include said identifier;and determine at least one member of the set consisting of positive events and negative events based on said controlling events and how many said requests are received or when any said requests are received.
  4. 45
    A method for determining communication events, the method comprising:(a) receiving a first request for a resource LD to identify the communication, wherein said first request includes at least one identity of an intended recipient of the communication;(b) defining at least one controlling event, wherein said controlling events include said at least one identity;(c) providing said resource LD in reply to said first request;(d) storing said resource LD, said controlling events, and a decryption key to decrypt the communication;(e) monitoring for a second request for said decryption key, wherein said second request includes said resource LD and identifying information for a putative said intended recipient;(f) if a said second request is received, then determining whether it conforms with said controlling events, and (1) if so: (i) providing said decryption key in reply to said second request;and (iϊ) storing said identifying information and a positive event in association with said resource LD;(2) else, storing a negative event in association with said resource LD;and (g) alternately, if no said second request is received for a said intended recipient, then storing a negative event in association with said resource LD.
  5. 59
    A method for a transaction source and a transaction target to exchange a transaction that cannot be repudiated, the method comprising:(a) receiving a first request for a transaction identifier to identify the transaction, wherein said request includes a source authentication assertion;(b) verifying said source authentication assertion;(c) storing said transaction identifier and information from said source authentication assertion, thereby establishing information making the transaction source unable to plausibly repudiate once it encrypts and sends the transaction;(d) providing said transaction identifier in reply to said first request so that the transaction and said transaction identifier can be sent to the transaction target;(e) receiving a second request for a decryption key to decrypt the transaction once it has been received by the transaction target, wherein said second request includes said transaction identifier and a target authentication assertion;(f) verifying said target authentication assertion;(g) storing information from said target authentication assertion with the transaction identifier;and (h) providing said decryption key in reply to said second request so that the transaction can be decrypted, thereby establishing information making the transaction target unable to plausibly repudiate being a recipient of the transaction.
  6. 63
    A method for establishing a transaction as nonrepudiate able by a transaction source that is the origin of the transaction, the method comprising:(a) receiving a request for a transaction identifier to identify the transaction, wherein said request includes a source authentication assertion;(b) verifying said source authentication assertion;(c) storing said transaction identifier and information from said source authentication assertion;and (d) providing said transaction identifier in reply to said request, thereby establishing information making the transaction source unable to plausibly repudiate being the origin of the transaction.
  7. 71
    A method for establishing a transaction as nonrepudiate able by a transaction target that is a recipient of the transaction, wherein a transaction identifier identifying the transaction and a decryption key usable to decrypt the transaction have been pre-stored, the method comprising:(a) receiving a request for the decryption key, wherein said request includes the transaction identifier and a target authentication assertion;(b) verifying said target authentication assertion;(c) storing information from said target authentication assertion with the transaction identifier;and (d) providing the decryption key in reply to said request, thereby establishing information making the transaction target unable to plausibly repudiate being a recipient of the transaction.
  8. 76
    A system for a transaction source and a transaction target to exchange a transaction that cannot be repudiated, comprising:a computerized key server;said key server suitable for receiving a first request via a network for a transaction identifier to identify the transaction, wherein said first request includes a source authentication assertion;said key server suitable for receiving a second request via said network for a decryption key usable to decrypt the fransaction, wherein said second request includes said fransaction identifier and a target authentication assertion;said key server suitable for verifying said source authentication assertion and said target authentication assertion;said key server suitable for storing said transaction identifier, information from said source authentication assertion, and information from said target authentication in association in a database;said key server suitable for providing a first reply to said first request via said network that includes said transaction identifier;and said key server suitable for providing a second reply to said second request via said network that includes said decryption key, thereby establishing information making the transaction source unable to plausibly repudiate once it encrypts and sends the transaction and also making the transaction target unable to plausibly repudiate once it is provided said decryption key.
  9. 80
    A system for establishing a transaction as nonrepudiate able by a fransaction source that is the origin of the transaction, comprising:a computerized key server;said key server suitable for receiving a request via a network for a transaction identifier to identify the transaction, wherein said request includes a source authentication assertion;said key server suitable for verifying said source authentication assertion;said key server suitable for storing said transaction identifier and information from said source authentication assertion in a database;and said key server suitable for providing a reply via said network that includes said transaction identifier, thereby establishing information making the transaction source unable to plausibly repudiate once it encrypts and sends the transaction.