发明名称 Method and apparatus for long term verification of digital signatures
摘要 The time over which a digital signature can be verified is extended well beyond the expiration of any or all of the certificates upon which that signature depends. A "save state" approach is disclosed, in which an archive facility is used to store public key infrastructure (PKI) state, e.g. cryptographic information, such as certificates and certificate revocation lists (CRLs), in addition to non-cryptographic information, such as trust policy statements or the document itself. This information comprises all that is necessary to re-create the signature verification process at a later time. When a user wants to reverify the signature on a document, possibly years later, a long term signature verification (LTSV) server re-creates the precise state of the PKI at the time the document was originally submitted. The LTSV server restores the state, and the signature verification process executes the exact process it performed (or would have performed) years earlier. In another embodiment the strength of cryptography is combined with the proven resilience of (non-public key) technology and procedures currently associated with secure data stores by saving the PKI state for future reverification; and protecting the PKI state information from intrusion by maintaining it in a secure storage facility which is protected by services, such as firewalls, access control mechanisms, audit facilities, intrusion detection facilities, physical isolation, and network isolation.
申请公布号 US6584565(B1) 申请公布日期 2003.06.24
申请号 US19970892792 申请日期 1997.07.15
申请人 HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P. 发明人 ZAMEK STEVEN
分类号 G09C1/00;H04L9/08;H04L9/32;H04L29/06;(IPC1-7):H04L9/30 主分类号 G09C1/00
代理机构 代理人
主权项
地址