IP Library Granted Patent US 12,513,007
Granted Patent B2
US 12,513,007 · App. 18/085,290 · Granted Dec 30, 2025

Method of managing authentication information of certificate independently of certificate authority

Inventor: Daegeun Yoon (Daejeon, KR)
Assignee: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
H04L9/3268H04L9/0825H04L9/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,007
App. No.
18/085,290
Granted
Dec 30, 2025
Kind
B2
Abstract

A method of managing authentication information of a certificate independently of a certificate authority (CA) is provided. The method includes issuing a certificate, into which identifier information instead of a public key is inserted, to an origin server by using the CA and reading an identifier document from an external storage by using user equipment on a basis of the identifier information received from the origin server and verifying the certificate with the public key included in the identifier document.

Claims (59)

1 . A method of managing authentication information of a certificate independently of a certificate authority (CA), the method comprising:

issuing a certificate, into which identifier information instead of a public key is inserted, to an origin server by using the CA; and

reading an identifier document from an external storage by using user equipment on a basis of the identifier information received from the origin server and verifying the certificate with the public key included in the identifier document,

wherein the verifying of the certificate comprises:

transmitting a first message, representing that it is possible to verify the certificate, to the origin server by using the user equipment; and

transmitting a second message including the identifier information to the user equipment by using the origin server in response to the first message, and

wherein the method further comprises:

before the issuing of the certificate to the origin server,

transferring software, managing the identifier document, to the external storage to install the software in the external storage by using the CA;

generating the identifier document including the public key by using the origin server, based on a predetermined mode; and

performing verification on an ownership of a private key corresponding to the public key included in the identifier document received from the origin server by using the software installed in the external storage.

2 . The method of claim 1 , wherein the issuing of the certificate to the origin server comprises:

transferring the identifier information to the CA by using the origin server;

verifying an ownership of the identifier information with the public key included in the identifier document from the external storage by using the CA, based on the identifier information;

when the ownership of the identifier information is verified, inserting the identifier information into the certificate; and

issuing the certificate, into which the identifier information is inserted, to the origin server.

3 . The method of claim 2 , wherein the verifying of the ownership of the identifier information comprises verifying the ownership of the identifier information with a public key specified in the identifier document.

4 . The method of claim 2 , wherein the inserting of the identifier information comprises inserting, instead of the public key, the identifier information into a Subject public key field of an X.509-based certificate.

5 . The method of claim 2 , wherein the inserting of the identifier information further comprises inserting type information, representing that the X.509-based certificate includes the identifier information instead of the public key, into a Public key algorithm field of the X.509-based certificate.

6 . The method of claim 1 , wherein the identifier information comprises URI information indicating the identifier document.

7 . The method of claim 1 , wherein the external storage comprises a decentralized storage or a distributed storage.

8 . The method of claim 1 , wherein the verifying of the certificate further comprises:

reading an identifier document from the external storage by using the user equipment, based on the identifier information included in the second message; and

verifying the certificate with the public key included in the identifier document by using the user equipment.

9 . The method of claim 8 , wherein the first message comprises a ClientHello message defined in The Transport Layer Security (TLS) Version 1.3, and the second message comprises a ServerHello message defined in the TLS Version 1.3.

10 . The method of claim 1 , further comprising:

when the ownership of the private key is verified, registering the identifier document by using the software installed in the external storage.

11 . The method of claim 10 , wherein the software provides a create, read, update, and delete (CRUD) function on the identifier document.

12 . The method of claim 10 , wherein the generating of the identifier document comprises generating the identifier document including a first field for recording the public key, a second field for recording a modification authority of the identifier document, and a third field recording a uniform resource locator (URL) of a web service provider.

13 . The method of claim 10 , further comprising transferring a registration request message of the identifier document by using the origin server, between the generating of the identifier document and the performing the verification on the ownership of the private key corresponding to the public key included in the identifier document,

wherein the registration request message comprises a value where a hash value of the identifier document is signed with a private key corresponding to a public key specified in the identifier document.

14 . A method of managing authentication information of a certificate independently of a certificate authority (CA), the method comprising:

issuing a certificate, into which a decentralized identifier (DID) instead of a public key is inserted, to an origin server by using the CA;

reading a DID document from a data storage by using user equipment on a basis of the DID received from the origin server and verifying the certificate with the public key included in the DID document;

transferring a message, issuing a request to add, modify, or delete a public key included in the DID document, to the data storage by using the origin server; and

adding, modifying, or deleting the public key included in the DID document by using the data storage in response to the message,

wherein the verifying of the certificate comprises:

transmitting a first message, representing that it is possible to verify the certificate, to the origin server by using the user equipment; and

transmitting a second message including the identifier information to the user equipment by using the origin server in response to the first message, and

wherein the method further comprises:

before the issuing of the certificate to the origin server,

transferring software, managing the identifier document, to the external storage to install the software in the external storage by using the CA;

generating the identifier document including the public key by using the origin server, based on a predetermined mode; and

performing verification on an ownership of a private key corresponding to the public key included in the identifier document received from the origin server by using the software installed in the external storage.

15 . The method of claim 14 , wherein the adding, modifying, or deleting the public key comprises adding, modifying, or deleting the public key included in the DID document by using the data storage, based on software providing a create, read, update, and delete (CRUD) function on the DID document.

16 . The method of claim 14 , wherein the DID comprises a URI indicating a position of the public key.

17 . A system for managing authentication information of a certificate independently of a certificate authority (CA), the system comprising:

an origin server configured to receive a certificate based on public key infrastructure (PKI), into which a decentralized identifier (DID) instead of a public key is inserted, from the CA; and

a user equipment configured to read a DID document from a verifiable data registry (VDR) on a basis of the DID received from the origin server and verify the certificate with the public key included in the DID document,

wherein verification of the certificate comprises:

transmission of a first message, representing that it is possible to verify the certificate, to the origin server by using the user equipment; and

transmission of a second message including the identifier information to the user equipment by using the origin server in response to the first message, and

wherein, before reception of the certificate by the origin server,

the CA is configured to transfer software, managing the identifier document, to an external storage to install the software in the external storage,

the origin server is further configured to generate the identifier document including the public key based on a predetermined mode, and

the installed software in the external storage is configured to perform verification on an ownership of a private key corresponding to the public key included in the identifier document received from the origin server.

18 . The system of claim 17 , wherein the DID document comprises a first field with the public key recorded therein, a second field with a modification authority of the identifier document recorded therein, and a third field with a uniform resource locator (URL) of a web service provider recorded therein.

19 . The system of claim 17 , wherein the DID document comprises a uniform resource identifier (URI) indicating the DID document.

20 . The system of claim 17 , wherein the DID document comprises a uniform resource identifier (URI) indicating a position of the public key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2022
From: YOON, DAEGEUN
To: ELECTRONICS AND TELECOMMUNICATIONS RESEARCH INSTITUTE
Reel/Frame 062163/0112 →
Priority Claims (1)
KR 10-2022-0030198 · Mar 10, 2022 · national
Continuity (1)
Related Publication 20230308296A1 · Sep 28, 2023
References Cited (15)
US 10771249B2 · Park · 2020 [cited by applicant]
US 10778420B2 · Hong et al. · 2020 [cited by applicant]
US 20100122081A1 · Sato · 2010 [cited by examiner]
US 20130156189A1 · Gero et al. · 2013 [cited by applicant]
US 20170026177A1 · Pilcher · 2017 [cited by examiner]
US 20170223054A1 · Wing · 2017 [cited by examiner]
US 20200394322A1 · Ramos · 2020 [cited by examiner]
US 20210126916A1 · Yang · 2021 [cited by examiner]
US 20220167166A1 · Je · 2022 [cited by examiner]
US 20230132505A1 · Lee · 2023 [cited by examiner]
KR 102267735 · 2021 [cited by applicant]
KR 102323522 · 2021 [cited by applicant]
KR 1020220006234 · 2022 [cited by applicant]
KR 1020220013328 · 2022 [cited by applicant]
Chuat et al., “SoK: Delegation and Revocation, the Missing Links in the Web's Chain of Trust”, 2020 IEEE European Symposium on Security and Privacy (EuroS&P), 2020, pp. 624-638. [cited by applicant]