US2015278808A1PendingUtilityA1

Transaction coordinator for digital certificate validation and other services

Assignee: IDENTRUST INCPriority: Sep 10, 1999Filed: Aug 25, 2014Published: Oct 1, 2015
Est. expirySep 10, 2019(expired)· nominal 20-yr term from priority
G06Q 20/3829G06Q 2220/00H04L 63/0823G06Q 20/38215G06Q 20/12H04L 9/3265G06Q 20/02G06Q 20/3674G06F 21/33H04L 2209/56G06Q 20/04
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for facilitating electronic commerce by securely providing certificate-related and other services including certificate validation and warranty. In a preferred embodiment, these services are provided within the context of a four-corner trust model. The four-corner model comprises a buyer, or subscribing customer, and a seller, or relying customer, who engage in an on-line transaction. The buyer is a customer of a first financial institution, or issuing participant. The issuing participant operates a certificate authority and issues the buyer a hardware token including a private key and a digital certificate signed by the issuing participant. The seller is a customer of a second financial institution, or relying participant. The relying participant operates a certificate authority and issues the seller a hardware token including a private key and a digital certificate signed by the relying participant. The system also includes a root certificate authority that operates a certificate authority that issues digital certificates to the issuing and relying participants. At the time of a transaction, the buyer creates a hash of the transaction data, signs the hash, and transmits the transaction data, the signature, and its digital certificate to the seller. The seller may then request system services via a connection with its financial institution, the relying participant. The system services may include a certificate status check service and a warranty service. The certificate status check service allows the relying customer to validate the subscribing customer's certificate. The warranty service allows the relying customer to receive a collateral-backed warranty that the subscribing customer's certificate is valid. Each participant and the root entity is provided with a transaction coordinator for combining services and operations into a single transaction having the qualities of atomicity, consistency, isolation, and durability. The transaction coordinator provides a single consistent interface for certificate-status messages and requests, as well as messages and requests relating to other services.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system for providing a digital certificate status check service via a computer network, the system comprising:
 a root entity server comprising a first transaction coordinator;   at least one issuing participant server comprising a second transaction coordinator; and   at least one relying participant server comprising a third transaction coordinator;   wherein each respective transaction coordinator comprises a digital certificate authentication and validation module that determines a status of digital certificates, receives online digital certificate status requests from the transaction coordinator, and transmits the online digital certificate status responses to the transaction coordinator; and   wherein coupled to each digital certificate authentication and validation module is a hardware security module.   
     
     
         2 . The system of  claim 1 , wherein each respective digital certificate authentication and validation module transmits a revoked status associated with a checked digital certificate in response to the module determining the checked digital certificate, or a linked certificate in a certificate chain with the checked digital certificate, has been revoked prior to a particular time. 
     
     
         3 . The system of  claim 2 , wherein the at least one issuing participant server transmits a disclaimer of liability for documents that have been digitally signed by the check digital certificate in the certificate chain after the particular time. 
     
     
         4 . The system of  claim 1 , wherein each respective digital certificate authentication and validation module transmits a valid status associated with a checked digital certificate in response to the module determining the checked digital certificate, and every other certificate in a certificate chain with the checked digital certificate, is in good standing as of a particular time. 
     
     
         5 . The system of  claim 4 , wherein the at least one issuing participant transmits an acceptance of liability for documents that have been digitally signed by the checked digital certificate in the certificate chain prior to the particular time using a private key corresponding to the checked digital certificate. 
     
     
         6 . The system of  claim 1 , wherein each digital certificate authentication and validation module transmits an unknown status associated with a checked digital certificate in response to the module determining the checked digital certificate, or a certificate in a certificate chain with the checked digital certificate, is not known to be in good standing. 
     
     
         7 . The system of  claim 6 , wherein the at least one issuing participant server transmits a disclaimer of liability for documents that have been digitally signed using a private key corresponding to the checked digital certificate. 
     
     
         8 . The system of  claim 1 , wherein each respective digital certificate authentication and validation module stores private keys in non-transitory memory of the coupled hardware security module. 
     
     
         9 . The system of  claim 1 , wherein each digital certificate authentication and validation module meets a set of minimum security requirements established by the root entity. 
     
     
         10 . The system of  claim 1 , wherein at least one digital certificate authentication and validation module is an online certificate status protocol responder. 
     
     
         11 . The system of  claim 1 , wherein at least one digital certificate authentication and validation module uses eXtensible Markup Language. 
     
     
         12 . A computer-implemented method for providing a digital certificate status check service via a computer network, said method comprising:
 providing a root entity server, at least one issuing participant server, and at least one relying participant server; and   providing each of the root entity server, each issuing participant server, and each relying participant server with a microprocessor-based transaction coordinator;   coupling to each respective transaction coordinator a digital certificate authentication and validation module executing a set of instruction to check a status of digital certificates, to receive online certificate status requests from the transaction coordinator, and to transmit online certificate status responses to the transaction coordinator; and   coupling to each respective digital certificate authentication and validation module a hardware security module.   
     
     
         13 . The method of  claim 12 , wherein a digital certificate authentication and validation module transmits a revoked response regarding a checked digital certificate when the checked digital certificate, or a certificate in a certificate chain with the checked digital certificate, has been revoked prior to a particular time. 
     
     
         14 . The method of  claim 13 , wherein each issuing participant server disclaims liability for documents that have been digitally signed after the particular time. 
     
     
         15 . The method of  claim 12 , wherein a digital certificate authentication and validation module transmits a good response regarding a checked digital certificate when the checked digital certificate, and every other certificate in a certificate chain with the checked digital certificate, is in good standing as of a particular time. 
     
     
         16 . The method of  claim 15 , wherein each issuing participant server accepts liability for documents that have been digitally signed prior to the particular time using a private key corresponding to the checked digital certificate. 
     
     
         17 . The method of  claim 12 , wherein a digital certificate authentication and validation module transmits an “unknown” response regarding a checked digital certificate when the checked digital certificate, or a certificate in a certificate chain with the checked digital certificate, is not known to be in good standing. 
     
     
         18 . The method of  claim 17 , wherein each issuing participant server disclaims liability for documents that have been digitally signed using a private key corresponding to the checked digital certificate. 
     
     
         19 . The method of  claim 12 , wherein each respective digital certificate authentication and validation module stores one or more private keys in non-transitory machine-readable memory of the hardware security module. 
     
     
         20 . The method of  claim 12 , wherein each digital certificate authentication and validation module meets a set of minimum security requirements established by the root entity server. 
     
     
         21 . The method of  claim 12 , wherein at least one digital certificate authentication and validation module is an online certificate status protocol responder. 
     
     
         22 . The method of  claim 12 , wherein at least one digital certificate authentication and validation module uses eXtensible Markup Language. 
     
     
         23 . A computer-implemented method comprising:
 receiving, by a first processor of a first transaction coordinator associated with an issuing participant server, from a second processor of a second transaction coordinator a request for a status of a digital certificate associated with a first certificate authority;   querying, by the first processor, the first certificate authority based on the request, wherein the first certificate authority stores the status of one or more digital certificates in non-transitory machine-readable memory;   determining, by the first processor, the status of the digital certificate responsive to querying the first certificate authority; and   upon determining the status of the digital certificate:
 transmitting, by the first processor, to the second processor a response comprising the status of the digital certificate and an indicator of liability. 
   
     
     
         24 . The method according to  claim 23 , wherein determining the status of the digital certificate further comprises:
 querying, by the first processor, a next-higher certificate authority storing the status of one or more digital certificates in non-transitory machine-readable memory, wherein the next-higher certificate authority comparatively above the first certificate authority in a hierarchy of one or more certificate authorities.   
     
     
         25 . The method according to  claim 24 , wherein the issuing participant server comprises the first certificate authority. 
     
     
         26 . The method according to  claim 25 , wherein the second transaction coordinator is associated with a relying participant server. 
     
     
         27 . The method according to  claim 26 , wherein a root certificate authority is a comparatively highest certificate authority in relation to the first certificate authority, wherein the root certificate authority is a comparatively highest certificate authority in relation to a second certificate authority, and wherein the second certificate authority is associated with the relying participant server. 
     
     
         28 . The method according to  claim 23 , wherein determining the status of the digital certificate further comprises:
 identifying, by the first processor, the status of a next-higher digital certificate in a certificate chain containing the digital certificate.   
     
     
         29 . The method according to  claim 23 , wherein determining the status of the digital certificate further comprises:
 identifying, by the first processor, a revoked status for the digital certificate prior to a particular time, wherein the status of the digital certificate is invalid.   
     
     
         30 . The method according to  claim 29 , wherein the indicator of liability contains a disclaimer of liability associated with a machine-readable document digitally signed with the digital certificate after the particular time. 
     
     
         31 . The method according to  claim 23 , wherein determining the status of the digital certificate further comprises:
 identifying, by the first processor, a valid status for the digital certificate after a particular time, wherein the status of the digital certificate is valid.   
     
     
         32 . The method according to  claim 31 , wherein the indicator of liability contains an acceptance of liability associated with a machine-readable document digitally signed with the digital certificate before the particular time. 
     
     
         33 . The method according to  claim 23 , wherein determining the status of the digital certificate further comprises:
 identifying, by the first processor, an unknown status for the digital certificate, wherein the status of the digital certificate is unknown.

Join the waitlist — get patent alerts

Track US2015278808A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.