Method for issuing a digital certificate by a certification authority, arrangement for performing the method, and computer system of a certification authority
11 claims: 3 independent, 8 dependent
- 1Verfahren zur Ausstellung eines digitalen Zertifikats durch eine Zertifizierungsstelle (B), bei dem - ein Gerät (A) eine Anforderungs-Nachricht zur Ausstellung des Zertifikats an die Zertifizierungsstelle (B) sendet, - die Zertifizierungsstelle (B) die Anforderungs-Nachricht empfängt und eine Anfrage zur Authentifizierung des Geräts (A) an das Gerät (A) sendet, - das Gerät (A) in Beantwortung der empfangenen Anfrage eine Antwort an die Zertifizierungsstelle (B) sendet und - die Zertifizierungsstelle (B) die empfangene Antwort prüft und das Zertifikat erstellt und an das Gerät (A) sendet, falls die Antwort als korrekt identifiziert wurde;wobei die Erzeugung der Anfrage und der Antwort auf einem Diffie-Hellman-Verfahren beruht, und wobei - die Zertifizierungsstelle (B) eine nur der Zertifizierungsstelle bekannte Zufallszahl y erzeugt und einen ersten Wert Y = g y als Anfrage an des Gerät (A) sendet, wobei g ein Generator nach dem Diffie-Hellman-Verfahren ist, - das Gerät (A) aus der empfangenen Anfrage Y einen zweiten Wert Y x berechnet und diesen als Antwort an die Zertifizierungsstelle (B) sendet, wobei x ein nur dem Gerät (A) bekannter dritter Wert ist, und - die Zertifizierungsstelle (B) einen vierten Wert X y berechnet, wobei X = g x ein sowohl dem Gerät (A) als auch der Zertifizierungsstelle (B) bekannter fünfter Wert ist, den berechneten vierten Wert X y mit dem empfangenen zweiten Wert Y x vergleicht und das Zertifikat an das Gerät (A) sendet, falls der zweite und der vierte Wert übereinstimmen.
- 2Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass die Authentifizierung des Geräts (A) auf einem Challenge-Response-Verfahren basiert.
- 3Verfahren nach einem der Ansprüche 1 oder 2, dadurch gekennzeichnet, dass das Gerät (A) vor dem Senden der Anforderungs-Nachricht ein Schlüsselpaar mit einem ersten privaten Schlüssel und einem ersten öffentlichen Schlüssel erstellt und die Anforderungs-Nachricht den ersten öffentlichen Schlüssel enthält und mit dem ersten privaten Schlüssel des Gerätes (A) signiert wird.
- 4Verfahren nach einem der Ansprüche 1 bis 3, dadurch gekennzeichnet, dass die Anfrage auf einer Zufallszahl basiert.
- 5Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass der dritte Wert x als zweiter privater Schlüssel des Geräts (A) fungiert und der fünfte Wert X = g x als zweiter öffentlicher Schlüssel des Geräts (A) fungiert.
- 6Verfahren nach Anspruch 5, dadurch gekennzeichnet, dass das Gerät (A) für den zweiten öffentlichen Schlüssel X über ein weiteres digitales Zertifikat verfügt und die Anforderungs-Nachricht dieses weitere Zertifikat enthält.
- 7Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass dem Gerät (A) ein weiterer öffentlicher Schlüssel der Zertifizierungsstelle (B) bekannt ist und die Anforderungs-Nachricht über eine HTTPS-Verbindung an die Zertifizierungsstelle (B) gesendet wird.
- 8Verfahren nach einem der vorhergehenden Ansprüche, dadurch gekennzeichnet, dass dem Gerät (A) ein weiterer öffentlicher Schlüssel der Zertifizierungsstelle (B) bekannt ist und die Anforderungs-Nachricht verschlüsselt mit dem öffentlichen Schlüssel der Zertifizierungsstelle (B) an die Zertifizierungsstelle (B) gesendet wird.
- 9Anordnung zur Durchführung eines Verfahrens gemäß einem der Ansprüche 1 bis 8 mit - einem Gerät (A) zum Senden einer Anforderungs-Nachricht zur Ausstellung eines digitalen Zertifikats, zum Empfangen einer Anfrage zur Authentifizierung und zum Senden einer Antwort in Beantwortung der empfangenen Anfrage und - einer Zertifizierungsstelle (B) zum Empfangen der Anforderungs-Nachricht, zum Senden einer Anfrage zur Authentifizierung, zum Prüfen der empfangenen Antwort und zum Erstellen und Senden des Zertifikats, falls die Antwort als korrekt identifiziert wird;wobei die Erzeugung der Anfrage und der Antwort auf einem Diffie-Hellman-Verfahren beruht, und wobei - die Zertifizierungsstelle (B) eine nur der Zertifizierungsstelle bekannte Zufallszahl y erzeugt und einen ersten Wert Y = g y als Anfrage an des Gerät (A) sendet, wobei g ein Generator nach dem Diffie-Hellman-Verfahren ist, - das Gerät (A) aus der empfangenen Anfrage Y einen zweiten Wert Y x berechnet und diesen als Antwort an die Zertifizierungsstelle (B) sendet, wobei x ein nur dem Gerät (A) bekannter dritter Wert ist, und - die Zertifizierungsstelle (B) einen vierten Wert X y berechnet, wobei X = g x ein sowohl dem Gerät (A) als auch der Zertifizierungsstelle (B) bekannter fünfter Wert ist, den berechneten vierten Wert X y mit dem empfangenen zweiten Wert Y x vergleicht und das Zertifikat an das Gerät (A) sendet, falls der zweite und der vierte Wert übereinstimmen.
- 10Anordnung gemäß Anspruch 9, dadurch gekennzeichnet, dass das Gerät (A) einen Authentifizierungs-Chip aufweist, in welchem der zweite private und der zweite öffentliche Schlüssel des Geräts (A) abgespeichert sind.
- 11Rechnersystem einer Zertifizierungsstelle (B) ausgebildet und programmiert zur Durchführung des Verfahrens nach einem der Ansprüche 1 bis 8 auf Seite der Zertifizierungsstelle mit - einem Empfangsmodul zum Empfangen von Anforderungs-Nachrichten und Antworten, - einem Sendemodul zum Senden von Anfragen zur Authentifizierung und eines digitalen Zertifikats - einem Prüfmodul zum Prüfen der Antworten und - einem Zertifizierungsmodul zum Erstellen des Zertifikats;wobei die Erzeugung der Anfrage und der Antwort auf einem Diffie-Hellman-Verfahren beruht, und wobei - die das Rechnersystem der Zertifizierungsstelle (B) eine nur der Zertifizierungsstelle bekannte Zufallszahl y erzeugt und einen ersten Wert Y = g y als Anfrage an des Gerät (A) sendet, wobei g ein Generator nach dem Diffie-Hellman-Verfahren ist, - ein Gerät (A) aus der empfangenen Anfrage Y einen zweiten Wert Y x berechnet und diesen als Antwort an die Zertifizierungsstelle (B) sendet, wobei x ein nur dem Gerät (A) bekannter dritter Wert ist, und - die Zertifizierungsstelle (B) einen vierten Wert X y berechnet, wobei X = g x ein sowohl dem Gerät (A) als auch der Zertifizierungsstelle (B) bekannter fünfter Wert ist, den berechneten vierten Wert X y mit dem empfangenen zweiten Wert Y x vergleicht und das Zertifikat an das Gerät (A) sendet, falls der zweite und der vierte Wert übereinstimmen.
Independent claims11
22 paragraphs, as filed
0001The invention relates to a method for issuing a digital certificate by a certification body, an arrangement for carrying out the method and a computer system of a certification body.
0002In the initial setting of safety parameters for devices, often referred to as "bootstrapping", a key pair with a public key and a private key is usually created by a device itself. The public key can be signed by a certification authority, often also as a certification authority (or CA), by means of a request message, which is usually designed as a Certificate Signing Request (short: CSR or Certificate Request). The addressed Certificate Signing Request is defined in RSC 2986, PKCS # 10. The certificate is then sent to the device and can then be used in security applications, for example, to authenticate itself against an infrastructure. The term "device" is understood here and in the following to mean any component and any service which is suitable for certification by a certification body.
0003In today's conventional methods for issuing a digital certificate by a certification authority, a public key PubKey A generated by the device is sent to the certification agency by means of a CSR signed by the device with a private key PK A created by it. By verifying the signature, the CA verifies whether the device that sent the CSR is owned by the corresponding private key PK_A. In addition, device data can be sent in so-called attributes as part of the CSR, which can not be verifiable by the certification authority.
0004Often, however, it is not sufficient just to check whether the device that sent a CSR is also owned by the corresponding private key. In this way, it is only possible to check whether a device is able to send a signed CSR, as it is sent by original devices. However, the originality or authenticity of the device itself can not be controlled by the methods customary today. This problem is often countered by the fact that the CSR is transported in a secure manner, for example by a physically separate network or by trustworthy service personnel, on data carriers, such as USB sticks, so that the certification body can only be used for authentic CSRs and thus for original device certificates.
0005The <patcit id="pcit0001" dnum="US20030088772A1"><text>US 2003/0 088 772 A1</text></patcit> 10 shows a method for certifying a public key in a local network. The<patcit id="pcit0002" dnum="US6993651B2"><text>US 6,993,651 B2</text></patcit> Shows a system in which Diffie Hellmann is used for key exchange.
0006The invention is based on the object of specifying an improved method for issuing a digital certificate by a certification body in which the authenticity or authenticity of the device is also checked before the certificate is created and sent. In addition, a suitable arrangement for carrying out the method as well as a computer system of a certification body which is suitable for carrying out the method on the side of the certification body is to be indicated.
0007The object is achieved by a method with the features of patent claim 1, an arrangement with the features of patent claim 9 and a computer system with the features of patent claim 11.
0008By including a dialog section for authenticating the device, which consists of inquiry and response and is advantageously based on a challenge-response method, it is highly likely that a certificate is issued only to original or authentic devices and not to plagiarism. In contrast to the known methods, however, a secure second transmission path is not required for this purpose. The embodiment of the method according to the invention makes the application of so-called man-in-the-middle attacks considerably more difficult since a potential attacker must now also be able to correctly answer the request sent by the certification authority in order to obtain a certificate .
0009According to one embodiment of the invention, prior to sending the request message, the device creates a key pair with a first private key and a first public key, integrates this first public key into the request message, and signs the request message with the first private key. In this manner, the request message is given the form of a Certificate Signing Request, as defined in RFC2986, PKCS # 10.
0010If the request, which advantageously represents a challenge in the context of a challenge-response method, is based on a random number, the probability of a manipulation can be further reduced.
0011The asymmetric key-abatement method based on the Diffie-Hellman method ensures a further increased security standard and has the advantage over symmetric encryption methods that no pre-configuration of the certification authority is required. It is, however, expressly pointed out that in addition to the Diffie-Hellman method, asymmetrical encryption methods or alternatively symmetrical encryption methods can also be used for the invention.
0012It is provided that the certification authority generates a random number y which is known only to the certification authority and has a first value Y = g<sup>Y</sup> As a request to the device, where g is a generator according to the Diffie-Hellman method. From the received inquiry Y, the device then calculates a second value Y<sup>X</sup> And sends it in response to the certification authority, where x is a third value known only to the device. The certification authority finally calculates a fourth value X<sup>Y</sup>, Where X = g<sup>X</sup> Is a fifth value known to both the device and the certification authority, compares this calculated fourth value X<sup>Y</sup> With the received second value Y.<sup>X</sup> And sends the certificate to the device if the second and fourth values match.
0013This data communication, which is based on the Diffie-Hellman method, is used to implement a secure, difficult-to-access authentication of the device in the context of a CSR.
0014The third value x functions as the second private key of the device and the fifth value X = g<sup>X</sup> As the second public key of the device. If the device for the second public key X has a digital certificate, it is advantageous to integrate this into the request message. This avoids the need for the certification authority to know the second public key X in advance.
0015If a public key of the certification body is known to the device, then according to a further embodiment of the invention, the request message for issuing the certificate can be sent to the certification authority via an HTTPS connection. By using a unilaterally authenticated HTTPS connection, it is ensured that the device can only send the request message to the desired certification authority. It is also ensured that the respective communication partner can not switch during the certification dialog. Alternatively, the device can encrypt the request message directly with the public key of the certification authority and send it to the certification authority.
0016According to an embodiment of the invention, the device has an authentication chip in which the second private and public key are stored. Such chips are already used, for example, for classical plagiarism protection. This makes it a simple way to equip a device with the second keys necessary for authentication.
0017Further features and advantages of the invention result from exemplary embodiments, which are explained in the following with reference to the drawings. Show it:<dl id="dl0001"><dt>FIG</dt><dd>5 is a signal diagram of a first embodiment of the method according to the invention, and FIG</dd><dt>FIG</dt><dd>2 shows a signal diagram of a second embodiment of the method according to the invention.</dd></dl>
0018According to the embodiment shown in FIG <figref idrefs="f0001">FIG</figref> A device A first transmits a request message, for example in the form of a CSR according to RFC2986, to a certification site B, wherein the request message contains, in the case of a CSR, a first public key PubKey_A of the device A, Private key PK_A of the device A is signed. These first keys were prepared in advance of the communication by the device A itself. If a public key of the certification body B is known to the device A, the connection to the certification body B can be realized via a unilaterally authenticated HTTPS connection. Upon receipt of the request message, the certification body B transmits a request for the authentication of the device A to the device A. This request represents a challenge in the context of a challenge-response method. For example, if this is based on a Diffie-Hellman method, As a request or challenge, a first value Y = g<sup>Y</sup> , Where g is a generator according to the Diffie-Hellman method and y is a random number known only to the certification site B.
0019In response to the received request or challenge, the device returns a response, which is a response in the sense of a challenge-response method, to the certification body B. If the challenge-response method is based on a Diffie-Hellman method, the device calculates a second value Y from the received query Y.<sup>X</sup> And sends it back to the certification body B as a response or response. Where x is a third value known only to the device. This is advantageously stored in an authentication chip provided in the device.
0020The certification authority B now checks the received response or response and creates and sends the certificate to the device if the answer is identified as correct. The certificate includes the first public key, which has been signed by the certification authority B. In the case of the Diffie-Hellmann approach described by way of example, the test is carried out by the certification body B having a fourth value X.<sup>Y</sup> Where X = g<sup>X</sup> Is a fifth value known to both device A and certification body B, this calculated fourth value X<sup>Y</sup> With the received second value Y.<sup>X</sup> And transmits the certificate to the device A in the form of the first public key PubKey_A of the device A, which is signed by a private key PK_B of the certification authority B, if the second and the fourth value coincide. The certificate issued by the certification authority can then contain, in addition to the first public key PubKey_A, the second public key X for verifying the authenticity of the device.
0021Again, it should be pointed out that the described authentication method, based on the Diffie-Hellman method, is merely an example. For the method according to the invention, it is only necessary that a request or challenge transmitted by the certification office B to the device A is correctly answered by the device A and thus the authenticity of the device A is detected.
0022In the <figref idrefs="f0001">FIG</figref> The second embodiment of the method according to the invention differs from the embodiment shown in FIG <figref idrefs="f0001">FIG</figref> Only by the fact that the request message, in addition to the first public key PubKey_A of the device A, also contains a certificate {g<sup>X</sup>}<sub>PK_CA</sub> To the second public key. To this end, the device A must, of course, have a certificate matching the second public key of the device A, which may have been issued by the same certification body B or by any other, but of course, trustworthy CA certification authority. In this way, certification body B is no longer required to know the second public key of device A in the run-up to the communication.
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2003088772A1 | Cites | United States of America | Examiner |
| US2009158031A1 | Cites | United States of America | Examiner |
| US6993651B2 | Cites | United States of America | Examiner |
| EP1549019A1 | Cites | European Patent Office (EPO) | – |
| US2003088772A1 | Cites | United States of America | – |
| US2009158031A1 | Cites | United States of America | – |
| US6993651B2 | Cites | United States of America | – |
| "Chapter 10: Identification and Entity Authentication ED - MENEZES A; OORSCHOT VAN P; VANSTONE S" [Online] 1. Oktober 1996 (1996-10-01), HANDBOOK OF APPLIED CRYPTOGRAPHY; [CRC PRESS SERIES ON DISCRETE MATHEMATICES AND ITS APPLICATIONS], CRC PRESS, BOCA RATON, FL, US, PAGE(S) 385 - 424 , XP001525010 ISBN: 978-0-8493-8523-0 Gefunden im Internet: URL:http://www.cacr.math.uwaterloo.ca/hac/ ORD - 1996-10-00> Section 10.3 | Non-patent | – | – |
| "Chapter 12: Key Establishment Protocols ED - MENEZES A; OORSCHOT VAN P; VANSTONE S" [Online] 1. Oktober 1996 (1996-10-01), HANDBOOK OF APPLIED CRYPTOGRAPHY; [CRC PRESS SERIES ON DISCRETE MATHEMATICES AND ITS APPLICATIONS], CRC PRESS, BOCA RATON, FL, US, PAGE(S) 489 - 541 , XP001525012 ISBN: 978-0-8493-8523-0 Gefunden im Internet: URL:http://www.cacr.math.uwaterloo.ca/hac/ ORD - 1996-10-00> Section 12.6 | Non-patent | – | – |
| HUGO KRAWCZYK ED - VICTOR SHOUP: "HMQV: A High-Performance Secure Diffie-Hellman Protocol" 1. Januar 2005 (2005-01-01), ADVANCES IN CRYPTOLOGY - CRYPTO 2005 LECTURE NOTES IN COMPUTER SCIENCE;;LNCS, SPRINGER, BERLIN, DE, PAGE(S) 546 - 566 , XP019016574 ISBN: 978-3-540-28114-6 Section 4 | Non-patent | – | – |
6 members in 4 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 102009036179 | Germany | A | |
| 102009036179 | Germany | – | |
| 2010059629 | European Patent Office (EPO) | W | |
| DE20091036179 | – | – | – |
| WO2010EP59629 | – | – | – |
| 102009036179 | – | – | – |
| 2010059629 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| DE102009036179A1 | Germany | A1 | |
| WO2011015414A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2012137129A1 | United States of America | A1 | |
| EP2462529A1 | European Patent Office (EPO) | A1 | |
| US8688976B2 | United States of America | B2 | |
| EP2462529B1This record | European Patent Office (EPO) | B1 |
74 legal events, as 11 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Ep patent has lapsedLapsedEUG | EUG | SE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapse because of not paying annual feesLapsedMM01 | MM01 | AT | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent lapsedLapsedMM4A | MM4A | IE | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| New agentNV | NV | CH | |
| Change of address of patent owner(s)NEW ADDRESS: WERNER-VON-SIEMENS-STRASSE 1, 80333 MUENCHEN (DE)PCOW | PCOW | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filed against granted patent, or epo opposition proceedings concluded without decisionGrantedR097 | R097 | DE | |
| Party data changed (patent owner data changed or rights of a patent transferred)RAP2 | RAP2 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent invalid in the netherlands as no translation has been filedMP | MP | NL | |
| Invalidated european patentMG4D | MG4D | LT | |
| Translation of granted ep patentGrantedTRGR | TRGR | SE | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| Reference to at number (ep patent validated in austria)REF | REF | AT | |
| Designated contracting statesAK | AK | EP | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Request for extension of the european patent (deleted)DAX | DAX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 2462529
- Publication, DOCDB
- 2462529
- Publication, EPODOC
- EP2462529
- Application
- 10734071
- Application, DOCDB
- 10734071
- Application, EPODOC
- EP20100734071
Titles3
- German
- VERFAHREN ZUR AUSSTELLUNG EINES DIGITALEN ZERTIFIKATS DURCH EINE ZERTIFIZIERUNGSSTELLE, ANORDNUNG ZUR DURCHFÜHRUNG DES VERFAHRENS UND RECHNERSYSTEM EINER ZERTIFIZIERUNGSSTELLE
- English
- METHOD FOR ISSUING A DIGITAL CERTIFICATE BY A CERTIFICATION AUTHORITY, ARRANGEMENT FOR PERFORMING THE METHOD, AND COMPUTER SYSTEM OF A CERTIFICATION AUTHORITY
- French
- PROCÉDÉ D'ÉTABLISSEMENT D'UN CERTIFICAT NUMÉRIQUE PAR UNE AUTORITÉ DE CERTIFICATION, AGENCEMENT DE MISE EN UVRE DU PROCÉDÉ ET SYSTÈME INFORMATIQUE D'UNE AUTORITÉ DE CERTIFICATION
Classification
- CPC, 6
- G06F21/57
- G06F2221/2103
- G06F2221/2117
- H04L9/0844
- H04L9/3263
- H04L9/3271
- IPC, 2
- G06F21 00
- G06F21 57
Designated states37
- Contracting states, 37
- Albania
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
and 13 moreShow fewer
- Monaco
- North Macedonia
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- San Marino
- Türkiye
