IP Library Patent Application 10949712
Patent Application
App. No. 10/949,712

Blocked tree authorization and status systems

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
10/949,712
Abstract

A method is provided for communicating authenticated information concerning a digital public key certificate. A hash-tree data structure is created containing a pre-defined list of possible information, such as authorizations, restrictions, privileges, or validity period notices. The list items may include text and coded values. Each list entry is prefixed with a different random data (blocker) value that is securely stored and infeasible to guess. Each list item is hashed to produce a leaf hash, the leaf hashes are combined to produce a hash tree, and the root node of said tree is embedded into a digital certificate or message that is signed using a private key. In response to a request for authenticated information concerning a digital public key certificate, the certificate authority releases the relevant list item, its blocker value, and other hash values sufficient to authenticate the list item using the root node embedded in the digital certificate.

Claims (7)

1 . (canceled)

2 . A method of managing authority associated with holders of public key certificates, comprising:

determining a plurality of initial random values, wherein each of the initial random values corresponds to a particular type of authority granted to a user;

applying a one-way hash function N times to the each of the initial random values to obtain a plurality of final hashed values;

a certificate authority issuing a public key certificate to the user that includes the plurality of final hashed values digitally signed by the certificate authority;

the certificate authority issuing, at T1, a first set of periodic freshness indicators corresponding to application of the one-way hash function to the initial random values M1 times, wherein M1 is a number of refresh intervals from the date of issuance of the digital certificate to T1; and

in response to a change of authority granted to the holder after T1 and prior to T2, the certificate authority issuing, at T2, a second set of periodic freshness indicators corresponding to application of the one-way hash function to a subset of the initial random values M2 times, wherein M2 is a number of refresh intervals from the date of issuance of the digital certificate to T2 and wherein the subset of initial random values is less than all of the initial random values and corresponds to the change of authority granted to the holder.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Oct 8, 2013
From: ASSA ABLOY AB
To: CORESTREET, LTD.
Reel/Frame 031361/0975 →
ASSIGNMENT OF SECURITY AGREEMENT Recorded Jan 26, 2007
From: ASSA ABLOY IDENTIFICATION TECHNOLOGY GROUP AB
To: ASSA ABLOY AB
Reel/Frame 018806/0814 →
SECURITY AGREEMENT Recorded Dec 16, 2005
From: CORESTREET, LTD.
To: ASSA ABLOY IDENTIFICATION TECHNOLOGY GROUP AB
Reel/Frame 016902/0444 →