首页> 外国专利> A remote access service enabling trust and interoperability when retrieving certificate status from multiple certification authority reporting components

A remote access service enabling trust and interoperability when retrieving certificate status from multiple certification authority reporting components

机译:一种远程访问服务,当从多个证书颁发机构报告组件中检索证书状态时,可实现信任和互操作性

摘要

A Certificate Status Service that is configurable, directed, and able to retrieve status from any approved Certification Authority (CA) is disclosed. The CSS may be used by a Trusted Custodial Utility (TCU) and comparable systems or applications whose roles are validating the right of an individual to perform a requisite action, the authenticity of submitted electronic information objects, and the status of authentication certificates used in digital signature verification and user authentication processes. The validity check on authentication certificates is performed by querying an issuing CA. Traditionally, to create a trusted Public Key Infrastructure (PKI) needed to validate certificates, complex relationships are formed by cross-certification among CAs or by use of PKI bridges. The PKI and CA interoperability problem is addressed from a different point of view, with a focus on establishing a trust environment suitable for the creation, execution, maintenance, transfer, retrieval and destruction of electronic original information objects that may also be transferable records (ownership may change hands). A TCU is concerned only with a known set of approved CAs although they may support a multitude of business environments, and within that set of CAs, only with those certificates that are associated with TCU user accounts. Building PKI/CA trusted relationships is not required as the CSS achieves a trusted environment by querying only approved CAs and maintaining caches of valid certificates' status.
机译:公开了一种证书状态服务,该证书状态服务是可配置的,定向的并且能够从任何批准的证书颁发机构(CA)检索状态。 CSS可由受信任的监管公用事业(TCU)和类似的系统或应用程序使用,其作用是验证个人执行必要操作的权利,提交的电子信息对象的真实性以及数字证书中使用的身份验证证书的状态签名验证和用户身份验证过程。验证证书的有效性检查是通过查询颁发CA来执行的。传统上,为了创建验证证书所需的受信任的公钥基础结构(PKI),复杂的关系是通过CA之间的交叉验证或使用PKI桥形成的。 PKI和CA的互操作性问题是从不同的角度解决的,重点是建立一个信任环境,该信任环境适用于电子原始信息对象的创建,执行,维护,转移,检索和销毁,这些原始电子对象也可以是可转移的记录(所有权)。可能会易手)。 TCU仅与一组已知的已批准CA有关,尽管它们可能支持多种业务环境,并且在该组CA中,仅与那些与TCU用户帐户关联的证书有关。不需要建立PKI / CA可信关系,因为CSS通过仅查询批准的CA并维护有效证书状态的缓存来实现可信环境。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号