Claims
- 1. A certificate path information management system that manages path information used for validation of certificates issued by certification authorities, comprising:
a path registration device that is installed in a certification authority issuing a certificate and that stores entry information on the certificate issued by the certification authority; a path management device that includes a path information list, which stores path information on the certificates, for storing the entry information sent from the path registration device into the path information list; and a terminal that sends path request information on a certificate to be verified to said path management device, wherein, in response to the path request information received from said terminal, said path management device searches the path information list for path information on the certificate and sends a result of the search to said terminal.
- 2. The certificate path information management system according to claim 1,
wherein, in response to the path information on the certificate from said path management device, said terminal accesses an external device in which information on the certificate is stored to obtain information on the certificate.
- 3. The certificate path information management system according to claim 1,
wherein the path request information sent by said terminal to said path management device includes information on a certification authority that is a path start point and information on a certification authority that is a path end point.
- 4. The certificate path information management system according to claim 1,
wherein said path management device checks whether the entry information sent from said path registration device is information already included in the path information list or new information before updating the information in the path information list.
- 5. The certificate path information management system according to claim 1,
wherein the path information list is information identifying a connected-to certification authority of the certification authority that issues the certificate.
- 6. The certificate path information management system according to claim 1,
wherein the entry information includes information identifying a storage location of the issued certificate.
- 7. A certificate path management system that manages certificate path information on certificates issued by certification authorities, comprising:
a sending/receiving unit that receives entry information on the certificates issued by the certification authorities; a storage unit that stores a path information list in which path information on the certificates is stored; and a processor that adds the entry information received by said sending/receiving unit to the path information list stored in said storage unit.
- 8. The certificate path management system according to claim 7,
wherein, when said sending/receiving unit receives path request information on a certificate, said processor searches the path information list for path information on the certificate specified by the path request information and said sending/receiving unit sends the search result.
- 9. The certificate path management system according to claim 7,
wherein said processor checks whether the entry information received by said sending/receiving unit is entry information from a new certification authority or entry information from an existing certification authority and, if the entry information is from an existing certification authority, updates information on the certification authority.
- 10. The certificate path management system according to claim 7,
wherein the path information list includes nodes each identifying a certification authority and wherein each node includes at least attribute information including a storage location of a certificate certified by the certification authority.
- 11. The certificate path management system according to claim 8,
wherein, in response to the path request information, said certificate path management system searches for a certification authority path based on the attribute information in the path information list and, in addition, converts the certification authority path to a certificate path to search for certificate path information.
- 12. A certificate path management method for managing certificate path information on a certificate issued by a certification authority, comprising the steps of:
receiving entry information on a certificate issued by the certification authority; storing a path information list in which certificate path information on certificates is stored; checking if the received entry information is received from a new certification authority; if the entry information is received from a new certification authority, creating a node corresponding to the new certification authority in the path information list; and adding the received entry information as attribute information on the node.
- 13. The certificate path management method according to claim 12, further comprising the steps of:
receiving path search request information that is path search request information on a certificate, said path search request information including at least information on certification authorities at both ends of a path; searching the path information list based on the information on certification authorities at both ends of the path; and outputting a search result of path information on the certificate.
- 14. The certificate path management method according to claim 13, further comprising the steps of:
checking if a time at which the path search request information is received is within an update period of the certificate for which the search is made; and if the time is out of the update period, extracting information on a current self-signed certificate storage location from the path information list as the search result, said information being included in the attribute information on a certification authority that issued the certificate for which the search is made.
- 15. The certificate path management method according to claim 14,
wherein, if the time at which the path search request information is received is within the update period, said method further comprises the steps of: checking whether an issuer of the path request information trusts a currently effective self-signed certificate before updating or a new self-signed certificate after updating; and extracting information on a self-signed certificate storage location, which is trusted by the issuer, as the path search result.
- 16. A certificate path management system that manages certificate path information on certificates issued by certification authorities, comprising:
communication means for receiving entry information on the certificates issued by the certification authorities; storage means for storing a path information list in which path information on the certificates is stored; and processing means for adding the entry information received by said communication means to the path information list stored in said storage means, wherein, when said communication means receives path search request information on a certificate, said processing means searches the path information list for path information on the certificate specified by the path search request information.
- 17. The certificate path management system according to claim 16,
wherein said processing means checks whether the entry information received by said communication means is entry information from a new certification authority or entry information from an existing certification authority and, if the entry information is from an existing certification authority, updates information on the certification authority.
- 18. The certificate path management system according to claim 16,
wherein, when said processing means searches for the path information on the certificate based on the path search request information received by said communication means, said processing means checks if a time of day is within an update processing time of the certificate and, if the time of day is out of the update processing time, extracts path information on a current self-signed certificate in the path information list.
- 19. A computer program product stored on a computer readable storage medium for use in a certificate path management system that manages certificate path information on a certificate issued by a certification authority, said program product comprising:
codes for receiving entry information on a certificate issued by the certification authority; codes for storing a path information list in which certificate path information on certificates is stored; codes for checking if the received entry information is received from a new certification authority; if the entry information is received from a new certification authority, codes for creating a node corresponding to the new certification authority in the path information list; and codes for adding the received entry information as attribute information on the node.
- 20. The computer program product according to claim 19, further comprising:
codes for receiving path search request information that is path search request information on a certificate, said path search request information including at least information on certification authorities at both ends of a path; codes for searching the path information list based on the information on certification authorities at both ends of the path; and codes for outputting a search result of path information on the certificate.
Priority Claims (1)
Number |
Date |
Country |
Kind |
2002-378941 |
Dec 2002 |
JP |
|
CROSS-REFERENCE TO RELATED APPLICATIONS
[0001] This application relates to U.S. Patent Application Ser. No. 09/952,743 filed on Sep. 13, 2001 based on Japanese Application Number 2000-372925 filed on Dec. 4, 2000 and assigned to the present assignee. The content of the application is incorporated herein by reference.