发明名称 Multi-certificate revocation using encrypted proof data for proving certificate's validity or invalidity
摘要 A certification authority (CA, 120 ) generates decryption key data (K'<SUB>Fj</SUB>) for each set (F) in the complement cover ( 804 ) for a plurality of digital certificates. The CA encrypts all or a portion of the validity proof data (c<SUB>j</SUB>(i)) for each digital certificate ( 140 .i) for each time period j for which the validity proof is to be provided. For each certificate, the decryption can be performed with decryption keys (K<SUB>ij</SUB>) that can be obtained from the decryption key data (K'<SUB>Fj</SUB>) for any set containing the certificate. The CA distributes the encrypted portions of the validity proof data to prover systems that will provide validity proofs in the periods j. To perform certificate re-validation in a period j, the CA constructs the complement cover for the set of the revoked certificates, and distributes the decryption key data (K'<SUB>Fj</SUB>) for the sets in the complement cover. In some embodiments, for each period j, the decryption keys (K<SUB>ij</SUB>) are also a function of the decryption key data provided for the preceding periods of time. Therefore, to perform the re-validation, the CA constructs the complement cover not for the set of all the revoked certificates but only for the set of the certificates revoked in the previous period j-1. The complement cover size can therefore be reduced. Other features and embodiments are also provided.
申请公布号 US2007074036(A1) 申请公布日期 2007.03.29
申请号 US20050304201 申请日期 2005.12.14
申请人 NTT DOCOMO INC. 发明人 RAMZAN ZULFIKAR A.;GENTRY CRAIG B.;BRUHN BERNHARD
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址