Claims
- 1. A system for providing one or more services via a network, comprising:
a root entity, the root entity operating a root entity certification authority, the root entity maintaining a root entity configuration baseline for the root entity certification authority, the root entity configuration baseline comprising the operating environment of the root entity certification authority; at least one level-one participant, the level-one participant operating a level-one certification authority, the level-one participant maintaining a configuration baseline for the level-one certification authority, the configuration baseline for the level-one certification authority comprising the operating environment of the level-one certification authority; at least one level-two participant, the level-two participant operating a level-two certification authority, the level-two participant maintaining a configuration baseline for the level-two certification authority, the configuration baseline for the level-two certification authority comprising the operating environment of the level-two certification authority.
- 2. The system of claim 1, wherein the configuration baseline of each entity's certification authority is recorded on a form.
- 3. The system of claim 1, wherein a copy of each entity's configuration baseline is maintained by the root entity.
- 4. The system of claim 1, further comprising a configuration manager, the configuration manager being an officer of the root entity, the configuration manager further having primary responsibility for configuration management within the system.
- 5. The system of claim 1, wherein each certification authority comprises a technical operations staff, the technical operations staff having primary responsibility for maintaining record of an entity certification authority's configuration.
- 6. The system of claim 1, wherein the configuration baseline for each entity's certification authority is maintained at the same physical location of the entity's certification authority.
- 7. The system of claim 1, wherein the configuration baseline for each entity's certification authority is maintained at a secure location outside the physical location of the entity's certification authority.
- 8. The system of claim 1, wherein the configuration baseline for each entity's certification authority is maintained at an offsite location.
- 9. The system of claim 1, wherein changes to the configuration baseline of an entity's certification authority are made to address a system requirement.
- 10. The system of claim 1, wherein an affected party is notified of a change to the configuration baseline of an entity's certification authority.
- 11. The system of claim 1, wherein a change to the configuration baseline of an entity's certification authority takes into account configuration change criteria imposed by government bodies.
- 12. The system of claim 1, wherein a change to the configuration baseline of an entity's certification authority takes into account configuration change criteria imposed by standards-setting bodies.
- 13. A system for providing a certificate status check service via a network comprising a plurality of entities including at least one root entity, at least one issuing participant, and at least one relying participant, each entity comprising:
a transaction coordinator; an online certificate status protocol responder, the online certificate status protocol responder checking status of a certificate, the online certificate status protocol responder receiving online certificate status requests from the transaction coordinator, the online certificate status protocol responder sending online certificate status responses to the transaction coordinator; and at least one hardware security module.
- 14. The system of claim 13, wherein the online certificate status protocol responder sends a revoked response regarding a checked certificate, the revoked response indicating that the certificate, or a certificate in a certificate chain of the certificate, has been revoked prior to a particular time.
- 15. The system of claim 14, wherein the issuing participant does not accept liability for documents that have been signed after the particular time using a private key corresponding to the checked certificate.
- 16. The system of claim 13, wherein the online certificate status protocol responder sends a good response regarding a checked certificate, the good response indicating that the certificate and every other certificate in the certificate chain of the certificate is in good standing at a particular time.
- 17. The system of claim 16, wherein the issuing participant accepts liability for documents that have been signed prior to the particular time using a private key corresponding to the checked certificate.
- 18. The system of claim 13, wherein the online certificate status protocol responder sends an unknown response regarding a certificate, the unknown response indicating that the certificate, or a certificate in the certificate chain of the certificate, is not known to be in good standing at a particular time.
- 19. The system of claim 18, wherein the issuing participant does not accept liability for documents that have been signed prior to the particular time using a private key corresponding to the checked certificate.
- 20. The system of claim 13, wherein the online certificate status protocol responder stores its private keys in a hardware security module.
- 21. The system of claim 13, wherein the online certificate status protocol responder meets a set of minimum security requirements established by the root entity.
Parent Case Info
[0001] This application claims priority from U.S. provisional patent application serial No. 60/231,319, filed Sep. 8, 2000, entitled Transaction Coordinator Certificate Status Check (CSC) Protocol Definition, Transaction Coordinator Messaging Protocol Definition, and Transaction Coordinator Requirements, which is hereby incorporated by reference. This application is also a continuation of U.S. patent application Ser. No. 09/657,605, filed Sep. 8, 2000, entitled System and Method for Providing Certificate Validation and Other Services, which claimed priority to U.S. provisional patent application serial No. 60/153,726, filed Sep. 13, 1999, entitled Transaction Coordinator for Certificate Status Checking and Other Services; U.S. provisional patent application serial No. 60/153,724, filed Sep. 13, 1999, entitled Transaction Coordinator Requirements and High Level Design; and U.S. provisional patent application serial No. 60/153,203, filed Sep. 10, 1999, entitled System and Process for Certification in Electronic Commerce, all of which are hereby incorporated by reference.
Provisional Applications (4)
|
Number |
Date |
Country |
|
60231319 |
Sep 2000 |
US |
|
60153726 |
Sep 1999 |
US |
|
60153724 |
Sep 1999 |
US |
|
60153203 |
Sep 1999 |
US |
Continuations (2)
|
Number |
Date |
Country |
Parent |
09657605 |
Sep 2000 |
US |
Child |
09950440 |
Sep 2001 |
US |
Parent |
09657605 |
Sep 2000 |
US |
Child |
09950440 |
Sep 2001 |
US |