Method for integrating online and offline cryptographic signatures and providing secure revocation
Abstract
A verification method and system including a verifier which can both interpret policies and determine if they are satisfied, and request and obtain relevant certificates. This new architecture includes a verifier which itself can both direct a retrieval mechanism and use a local database of information. Users and applications can obtain and supply certificates to the verifier and the local database. The verifier may invoke a retrieval mechanism to obtain necessary certificates from other authenticated data servers and store them in a secondary database. The flexibility to allow for both on-line and off-line authenticated data server responses for verification is encompassed, as is an enhanced system for security including revocation of certificates using a polarity discipline, which allows data used for revocation to be handled with the same system used for other verification data without imperiling security.
Claims
exact text as granted — not AI-modified1 . The method for verification by a verifier of information comprising the steps of:
receiving a verification request for verification information from a requesting application, said verification request expressed in a programming language which includes two syntactically distinct classes of names and variables, one of said classes expressing positive information, and the second of said classes negative information; examining available policies and certificates to determine whether said verification request is satisfiable; based upon one or more of said verification request, said policies, and said certificates, optionally generating a query based upon said verification request; sending said query to an authenticated data server; receiving a response from said authenticated data server based upon said query; determining whether said response includes information indicating said verification request is satisfiable; sending information on the satisfiability of said vertification request to said requesting application.
2 . The method of claim 1 , where said class expressing negative information expresses the revocation of certificates or permissions.
3 . The method of claim 1 , where said steps sending said query to an authenticated data server comprises the step of sending said query to an authenticated data server via a distributed computer network, and said step of and receiving a response from said authenticated data server based upon said query comprises the step of receiving a response from said authenticated data server based upon said query via said distributed computer network.
4 . The method of claim 3 , where said distributed computer network is the Internet.
5 . The method of claim 1 , where said step of determining whether said response includes information indicating said verification request is satisfiable comprises the step of evaluating whether an on-line or an off-line response has been received.
6 . The method of claim 1 , where said programming language is an XML markup language.Join the waitlist — get patent alerts
Track US2006090075A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.