IP Library › Granted Patent US 8,732,457
Granted Patent B2
US 8,732,457 · App. 10/103,541 · Granted May 20, 2014

Scalable certificate validation and simplified PKI management

Inventor: Silvio Micali (Brookline, MA)
Assignee: Assa Abloy AB
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,732,457
App. No.
10/103,541
Granted
May 20, 2014
Kind
B2
Abstract

Managing a digital certificate includes a landlord providing a digital certificate, a secure hardware device generating a series of n hash values, the secure hardware device providing an nth hash value to the landlord, wherein other hash values are not readily available to the landlord, the landlord placing the nth hash value in the certificate, the landlord digitally verifying the certificate containing the nth hash value to obtain a digitally signed certificate, a tenant obtaining the digitally signed certificate, the tenant obtaining the n hash values and the tenant managing the certificate by periodically issuing a previous hash value in the series of n hash values in response to the certificate being valid when the previous hash value is issued.

Claims (53)

1. A method of accessing a door, comprising:

providing a card with previously-verified data that includes a digital signature;

causing the card to receive a proof of access rights to the door for a specified time interval, wherein the specified time interval includes at least some time after a time that the previously-verified data was verified, and wherein the proof is unverified and separate from the previously-verified data, wherein the unverified proof does not include an associated digital signature;

causing the card to be presented to a mechanism of the door at a current time, the mechanism being local to the door;

causing the mechanism to locally verify the proof without verification of the proof from any other party; and

causing the door to open if the proof is verified and the current time is within the specified time interval.

2. A method according to claim 1 , wherein the card receives the proof from a wired card device.

3. A method according to claim 1 , wherein the card is contactless.

4. A method according to claim 1 , wherein the card is at least one of: a cellular phone and a PDA.

5. A method according to claim 1 , wherein the card receives the proof via the Internet.

6. A method according to claim 1 , wherein the card receives the proof wirelessly.

7. A method according to claim 1 , wherein the card receives the proof from a relying party during a prior interaction.

8. A method according to claim 7 , wherein the relying party queried for and received the proof from a responder.

9. A method according to claim 1 , wherein the previously-verified data includes a digital certificate.

10. A method according to claim 9 , wherein the digital signature is relative to a public key certified within the digital certificate contained in the card.

11. A method according to claim 10 , wherein the card presents to the mechanism of the door both the proof and the certificate.

12. A method according to claim 10 , wherein a public key certified within the certificate is obtained by iterating a one-way hash function.

13. A method according to claim 10 , wherein the access rights are selected from the group consisting of: granted, suspended, re-granted, re-suspended or revoked keeping the same certificate.

14. A method according to claim 13 , wherein the proof is one of a plurality of proofs relative to a plurality of access rights.

15. A method according to claim 1 , wherein the specified time interval is one day.

16. A method according to claim 1 , wherein the access rights are selected from the group consisting of: granted, suspended, re-granted, re-suspended or revoked.

17. A method according to claim 16 , wherein the proof is one of a plurality of proofs relative to a plurality of access rights.

18. A method according to claim 17 , wherein a single authority manages the plurality of access rights.

19. A method according to claim 17 , wherein the plurality of access rights are independently managed by a plurality of authorities.

20. A method according to claim 1 , wherein the proof is one of a plurality of proofs relative to a plurality of access rights.

21. A method according to claim 1 , wherein locally verifying the proof includes performing a one-way function on the proof to yield result data within the mechanism that locally verifies the proof.

22. A method of issuing a card to a user for accessing a door, comprising:

verifying that the user is entitled to access rights to the door;

providing the card with previously-verified data that includes a digital signature; and

if the user is entitled to access rights to the door, causing the card to receive a proof of access rights to the door for a specified time interval, wherein the proof is unverified and separate from the previously-verified data, wherein the unverified proof does not include an associated digital signature, wherein the specified time interval includes at least some time after a time that the previously-verified data was verified, and wherein, in response to the card being presented to a mechanism of the door at a current time, the mechanism being local to the door, and without verification of the proof from any other party, the mechanism locally verifies the proof and causes the door to open if the proof is verified and the current time is within the specified time interval.

23. A method according to claim 22 , wherein the card receives the proof from a wired card device.

24. A method according to claim 22 , wherein the card is contactless.

25. A method according to claim 22 , wherein the card is at least one of: a cellular phone and a PDA.

26. A method according to claim 22 , wherein the card receives the proof via the Internet.

27. A method according to claim 22 , wherein the card receives the proof wirelessly.

28. A method according to claim 22 , wherein the card receives the proof from a relying party during a prior interaction.

29. A method according to claim 22 , wherein locally verifying the proof includes performing a one-way function on the proof to yield result data within the mechanism that locally verifies the proof.

30. A method of granting access to a door, comprising:

providing previously-verified data that includes a digital signature;

locally verifying a proof provided to a mechanism of the door at a current time, the mechanism being local to the door, and without verification of the proof from any other party, wherein the proof is unverified and separate from the previously-verified data, wherein the unverified proof does not include an associated digital signature, wherein the proof indicates access rights to the door for a specified time interval, and wherein the specified time interval includes at least some time after a time that the previously-verified data was verified; and

causing the door to open if the proof is verified and the current time is within the specified time interval.

31. A method according to claim 30 , wherein the digital signature is relative to a public key certified within a digital certificate.

32. A method according to claim 31 , wherein the mechanism of the door is presented with both the proof and the certificate.

33. A method according to claim 31 , wherein a public key certified within the certificate is obtained by iterating a one-way hash function.

34. A method according to claim 30 , wherein the specified time interval is one day.

35. A method according to claim 30 , wherein the access rights are selected from the group consisting of: granted, suspended, re-granted, re-suspended or revoked.

36. A method according to claim 35 , wherein the proof is one of a plurality of proofs relative to a plurality of access rights.

37. A method according to claim 36 , wherein a single authority manages the plurality of access rights.

38. A method according to claim 36 , wherein the plurality of access rights are independently managed by a plurality of authorities.

39. A method according to claim 30 , wherein the access rights are selected from the group consisting of: granted, suspended, re-granted, re-suspended or revoked keeping the same certificate.

40. A method according to claim 39 , wherein the proof is one of a plurality of proofs relative to a plurality of access rights.

41. A method according to claim 30 , wherein the proof is one of a plurality of proofs relative to a plurality of access rights.

42. A method according to claim 30 , wherein locally verifying the proof includes performing a one-way function on the proof to yield result data within the mechanism that locally verifies the proof.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2014
From: CORESTREET LTD
To: ASSA ABLOY AB
Reel/Frame 032404/0759 →
RELEASE OF SECURITY INTEREST Recorded Oct 8, 2013
From: ASSA ABLOY AB
To: CORESTREET, LTD.
Reel/Frame 031361/0975 →
ASSIGNMENT OF SECURITY AGREEMENT Recorded Jan 26, 2007
From: ASSA ABLOY IDENTIFICATION TECHNOLOGY GROUP AB
To: ASSA ABLOY AB
Reel/Frame 018806/0814 →
SECURITY AGREEMENT Recorded Dec 16, 2005
From: CORESTREET, LTD.
To: ASSA ABLOY IDENTIFICATION TECHNOLOGY GROUP AB
Reel/Frame 016902/0444 →
CHANGE OF NAME Recorded Dec 31, 2002
From: CORESTREET SECURITY, LTD.
To: CORESTREET, LTD.
Reel/Frame 013624/0593 →
CHANGE OF NAME Recorded Sep 23, 2002
From: NOVOMODO, INC.
To: CORESTREET SECURITY, LTD.
Reel/Frame 013315/0230 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2002
From: MICALI, SILVIO
To: NOVOMODO, INC.
Reel/Frame 012865/0618 →
Continuity (36)
Continuation In Part 09915180 · Jul 25, 2001
Continuation 09483125 · Jan 14, 2000
Continuation 09356745 · Jul 19, 1999
Continuation 08823354 · Mar 24, 1997
Continuation 08559533 · Nov 16, 1995
Continuation 10103541
Continuation In Part 08992897 · Dec 18, 1997
Continuation In Part 08715712 · Sep 19, 1996
Continuation In Part 08729619 · Oct 11, 1996
Continuation In Part 08804868 · Feb 24, 1997
Continuation 08741601 · Nov 1, 1996
Continuation In Part 08872900 · Jun 11, 1997
Continuation 08746007 · Nov 5, 1996
Continuation In Part 08906464 · Aug 5, 1997
Continuation 08763536 · Dec 9, 1996
Continuation In Part 08636854 · Apr 23, 1996
Continuation In Part 08756720 · Nov 26, 1996
Continuation In Part 08715712 · Sep 19, 2006
Continuation In Part 08559533 · Nov 16, 1995
Continuation In Part 08752223 · Nov 19, 1996
Continuation In Part 08804869 · Feb 24, 1997
Continuation 08741601 · Nov 1, 1996
Continuation In Part 08823354 · Mar 24, 1997
Continuation 08559533 · Nov 16, 1995
Provisional Application 60006038 · Oct 24, 1995
Provisional Application 60033415 · Dec 18, 1996
Provisional Application 60004796 · Oct 2, 1995
Provisional Application 60006143 · Nov 2, 1995
Provisional Application 60025128 · Aug 29, 1996
Provisional Application 60035119 · Feb 3, 1997
Provisional Application 60024786 · Sep 10, 1996
Provisional Application 60025128 · Aug 29, 1996
Provisional Application 60277244 · Mar 20, 2001
Provisional Application 60300621 · Jun 25, 2001
Provisional Application 60344245 · Dec 27, 2001
Related Publication 20020165824A1 · Nov 7, 2002