Invention Grant
- Patent Title: Revocation of cryptographic digital certificates
- Patent Title (中): 撤销加密数字证书
-
Application No.: US12492908Application Date: 2009-06-26
-
Publication No.: US08156327B2Publication Date: 2012-04-10
- Inventor: Craig B. Gentry , Zulfikar Amin Ramzan , Bernhard Bruhn
- Applicant: Craig B. Gentry , Zulfikar Amin Ramzan , Bernhard Bruhn
- Applicant Address: JP Tokyo
- Assignee: NTT DoCoMo, Inc.
- Current Assignee: NTT DoCoMo, Inc.
- Current Assignee Address: JP Tokyo
- Agency: Haynes and Boone, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A distributed certificate authority includes a CA and a number of Sub-CAs (2610). The Sub-CAs have secret certificate validation data, but different data are provided to different Sub-CAs for each certificate. If a Sub-CA is compromised, the Sub-CA validity proof will be withheld by the CA to alert the verifiers not to use the data from this Sub-CA. Also, the secret data are encrypted when distributed to the Sub-CAs. A decryption key (DK.j.k) for each “partition” of time is distributed to each Sub-CA at or shortly before the start of the partition. A compromised Sub-CA can be reactivated at the end of the partition because the adversary does not get the decryption keys for the future partitions.
Public/Granted literature
- US20090259843A1 REVOCATION OF CRYPTOGRAPHIC DIGITAL CERTIFICATES Public/Granted day:2009-10-15
Information query