Patent · US Expired

Trusted and unsupervised digital certificate generation using a security token

US9331990B2 · kind B2 · utility

20Cited by
27References
42Claims
0Family size

Assignee

Inventor

Key dates

Filing dateDec 22, 2003
Grant dateMay 3, 2016
Priority date
Expiry dateNov 16, 2025

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2209/80
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method, system and computer program product for ensuring PKI key pairs are operatively installed within a secure domain of a security token prior to generating a digital certificate. The public key component of the PKI key pair is incorporated into a digital certificate which is returned to the security token for storage. The arrangement included herein incorporates the use of a critical security parameter to ensure a chain of trust with an issuing entity such as a registration authority. Furthermore, the arrangement does not require security officer or system administrator oversight during digital certificate generation as the critical security parameter provides a sufficient level of trust to ensure that digital certificate generation is being performed in conjunction with a designated security token rather than a rogue application. Lastly, separate inventive embodiments allow alternate communications and verification arrangements to be implemented.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.