发明名称 Computer implemented method and a computer system to prevent security problems in the use of digital certificates in code signing and a computer program product thereof
摘要 A computer implemented method including a software distributor signing via a first server at least one software file using a digital certificate with a digital signature and at least one user via a computing device acquiring a copy of the signed software file. The digital certificate to be used is previously recorded in a second server in communication with the first server, the digital certificate to be recorded being provided by the software distributor upon a registration of the latter in the second server and including information obtained from a trust certificate chain associated to the digital certificate when performing the registration. The second server generates, upon a request made by the software distributor, a hashstamp of the signed software file.
申请公布号 US9634841(B2) 申请公布日期 2017.04.25
申请号 US201414559379 申请日期 2014.12.03
申请人 TELEFONICA DIGITAL ESPANA, S.L.U. 发明人 De Los Santos Sergio;Barroso Berrueta David;Guzman Sacristan Antonio;De La Rosa Tero;Alonso Cebrian Jose Maria
分类号 H04L9/32;H04L29/06;G06F21/64 主分类号 H04L9/32
代理机构 Sughrue Mion, PLLC 代理人 Sughrue Mion, PLLC
主权项 1. A computer implemented method to promptly detect digital certificate misuse, the method comprising: signing, by a software distributor via a first server, at least one software file using a digital certificate with a digital signature identifying said software distributor; and acquiring, by at least one user via a computing device, a copy of said at least one signed software file, wherein said digital certificate to be used for said signing is previously recorded in a second server in communication with said first server, the digital certificate to be recorded being provided by the software distributor upon a registration of the software distributer in said second server and the digital certificate including information obtained from a trust certificate chain associated to the digital certificate when performing said registration, wherein the second server, upon a request made by the software distributor, generates a hashstamp of the at least one signed software file, wherein said registration comprises checking, by the second server, data included in the provided digital certificate including at least a domain and/or an electronic address, and; performing, by the second server, a second authentication of said digital certificate by performing the following steps: generating a one-time password (OTP);sending said generated OTP to the software distributor through a communication channel including at least a text message, an electronic message or an instant message; andcertifying, upon receiving said OTP from the software distributor, that the received OTP matches with said generated OTP.
地址 Madrid ES