WO2009001855A1 - サーバ証明書発行システム - Google Patents

サーバ証明書発行システム Download PDF

Info

Publication number
WO2009001855A1
WO2009001855A1 PCT/JP2008/061541 JP2008061541W WO2009001855A1 WO 2009001855 A1 WO2009001855 A1 WO 2009001855A1 JP 2008061541 W JP2008061541 W JP 2008061541W WO 2009001855 A1 WO2009001855 A1 WO 2009001855A1
Authority
WO
WIPO (PCT)
Prior art keywords
server
password
verification
generating
verification information
Prior art date
Application number
PCT/JP2008/061541
Other languages
English (en)
French (fr)
Inventor
Keisuke Kido
Ichiro Chujo
Original Assignee
Globalsign K.K.
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from JP2007262485A external-priority patent/JP4128610B1/ja
Application filed by Globalsign K.K. filed Critical Globalsign K.K.
Priority to EP08790608.7A priority Critical patent/EP2154817B1/en
Priority to US12/452,255 priority patent/US8234490B2/en
Priority to JP2009520614A priority patent/JP4494521B2/ja
Priority to CN2008801008408A priority patent/CN101828358B/zh
Publication of WO2009001855A1 publication Critical patent/WO2009001855A1/ja

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/60Digital content management, e.g. content distribution

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Information Transfer Between Computers (AREA)

Abstract

本発明によるサーバ証明書発行システムでは、Web サーバは、少なくともWeb及びメールの設定及び管理を行うコントロールパネル(21)を有する。当該コントロールパネルには、サーバ証明書の発行申込事項を入力するための入力画面を生成する手段(30)と、暗号化のためのパスワードを生成するパスワード生成手段(34)と、証明書の発行要求の意志を示す検証ページを生成する手段(32)とを実装する。検証ページには、検証情報として例えば生成されたパスワードを表示する。登録サーバ(10)は、受信したサーバ証明書発行要求からパスワードを取り出すと共に、Web サーバにアクセスして検証ページに表示されている検証情報を読み取り、読み取った検証情報とパスワードとを照合する。照合の結果として、Web サーバから読み取った検証情報とパスワードとが一致した場合、サーバ証明書の発行対象となるWeb サーバが実在するものと判断し、キーペア及びCSR を生成し、CSR を証明書発行サーバ(11)に送出する。
PCT/JP2008/061541 2007-06-27 2008-06-25 サーバ証明書発行システム WO2009001855A1 (ja)

Priority Applications (4)

Application Number Priority Date Filing Date Title
EP08790608.7A EP2154817B1 (en) 2007-06-27 2008-06-25 Server certificate issuing system
US12/452,255 US8234490B2 (en) 2007-06-27 2008-06-25 Server certificate issuing system
JP2009520614A JP4494521B2 (ja) 2007-06-27 2008-06-25 サーバ証明書発行システム
CN2008801008408A CN101828358B (zh) 2007-06-27 2008-06-25 服务器认证书发行系统

Applications Claiming Priority (4)

Application Number Priority Date Filing Date Title
JP2007168777 2007-06-27
JP2007-168777 2007-06-27
JP2007262485A JP4128610B1 (ja) 2007-10-05 2007-10-05 サーバ証明書発行システム
JP2007-262485 2007-10-05

Publications (1)

Publication Number Publication Date
WO2009001855A1 true WO2009001855A1 (ja) 2008-12-31

Family

ID=40185668

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2008/061541 WO2009001855A1 (ja) 2007-06-27 2008-06-25 サーバ証明書発行システム

Country Status (5)

Country Link
US (1) US8234490B2 (ja)
EP (1) EP2154817B1 (ja)
JP (1) JP4494521B2 (ja)
CN (1) CN101828358B (ja)
WO (1) WO2009001855A1 (ja)

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2012065004A (ja) * 2010-09-14 2012-03-29 Panasonic Corp 電子情報導入システム、端末装置、サーバ装置、電子情報導入方法およびプログラム
JP2014517567A (ja) * 2011-04-19 2014-07-17 オーセンテイフイ・インコーポレーテツド 疑似帯域外認証アーキテクチャを用いる鍵管理
JP2016507843A (ja) * 2013-02-08 2016-03-10 サーティファイド セキュリティー ソルーションズ,インクCertified Security Solutions,Inc. Scep証明書登録要求の正当性を確認するためのシステムおよび方法
KR20160087753A (ko) * 2015-01-14 2016-07-22 캐논 가부시끼가이샤 Ssl 통신을 행하는 것이 가능한 정보 처리 장치, 그 제어 방법 및 기억 매체
US9832183B2 (en) 2011-04-19 2017-11-28 Early Warning Services, Llc Key management using quasi out of band authentication architecture
CN110730162A (zh) * 2019-09-16 2020-01-24 北京齐尔布莱特科技有限公司 一种页面的验证方法、移动终端、可读存储介质
JP2020533853A (ja) * 2017-09-07 2020-11-19 西安西▲電▼捷通▲無▼綫▲網▼絡通信股▲分▼有限公司China Iwncomm Co., Ltd. デジタル証明書を管理するための方法および装置
TWI714359B (zh) * 2018-12-26 2020-12-21 大陸商中國銀聯股份有限公司 一種電子憑證上傳的方法及裝置
JP2021016149A (ja) * 2020-06-08 2021-02-12 一般財団法人日本情報経済社会推進協会 電子証明書導入・運用システム、電子証明書導入・運用方法、及び証明書申請装置

Families Citing this family (29)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US9160545B2 (en) * 2009-06-22 2015-10-13 Beyondtrust Software, Inc. Systems and methods for A2A and A2DB security using program authentication factors
US20100325687A1 (en) * 2009-06-22 2010-12-23 Iverson Gyle T Systems and Methods for Custom Device Automatic Password Management
US8863253B2 (en) * 2009-06-22 2014-10-14 Beyondtrust Software, Inc. Systems and methods for automatic discovery of systems and accounts
US8788811B2 (en) * 2010-05-28 2014-07-22 Red Hat, Inc. Server-side key generation for non-token clients
US9137017B2 (en) * 2010-05-28 2015-09-15 Red Hat, Inc. Key recovery mechanism
US20110296171A1 (en) * 2010-05-28 2011-12-01 Christina Fu Key recovery mechanism
US9015469B2 (en) 2011-07-28 2015-04-21 Cloudflare, Inc. Supporting secure sessions in a cloud-based proxy service
US8738911B2 (en) * 2012-06-25 2014-05-27 At&T Intellectual Property I, L.P. Secure socket layer keystore and truststore generation
US8707027B1 (en) 2012-07-02 2014-04-22 Symantec Corporation Automatic configuration and provisioning of SSL server certificates
CN103139201B (zh) * 2013-01-22 2015-12-23 中兴通讯股份有限公司 一种网络策略获取方法及数据中心交换机
US8782774B1 (en) 2013-03-07 2014-07-15 Cloudflare, Inc. Secure session capability using public-key cryptography without access to the private key
US9178888B2 (en) * 2013-06-14 2015-11-03 Go Daddy Operating Company, LLC Method for domain control validation
US9521138B2 (en) 2013-06-14 2016-12-13 Go Daddy Operating Company, LLC System for domain control validation
US9300623B1 (en) * 2014-02-18 2016-03-29 Sprint Communications Company L.P. Domain name system cache integrity check
CN104917740B (zh) * 2014-03-14 2018-09-04 中国移动通信集团广东有限公司 一种密码重置方法、密码验证方法及装置
US8996873B1 (en) 2014-04-08 2015-03-31 Cloudflare, Inc. Secure session capability using public-key cryptography without access to the private key
US8966267B1 (en) 2014-04-08 2015-02-24 Cloudflare, Inc. Secure session capability using public-key cryptography without access to the private key
RU2702076C2 (ru) * 2015-04-23 2019-10-03 Унхо ЧХОИ Аутентификация в распределенной среде
US10791110B2 (en) * 2015-07-09 2020-09-29 Cloudflare, Inc. Certificate authority framework
US10305871B2 (en) 2015-12-09 2019-05-28 Cloudflare, Inc. Dynamically serving digital certificates based on secure session properties
CN105846996B (zh) * 2016-03-17 2019-03-12 上海携程商务有限公司 服务器证书的自动部署系统及方法
US10977361B2 (en) 2017-05-16 2021-04-13 Beyondtrust Software, Inc. Systems and methods for controlling privileged operations
CN110069941A (zh) * 2019-03-15 2019-07-30 深圳市买买提信息科技有限公司 一种接口访问鉴权方法、装置及计算机可读介质
US11528149B2 (en) 2019-04-26 2022-12-13 Beyondtrust Software, Inc. Root-level application selective configuration
JP7352092B2 (ja) * 2019-12-24 2023-09-28 富士通株式会社 制御方法、情報処理装置及び制御プログラム
US10903990B1 (en) 2020-03-11 2021-01-26 Cloudflare, Inc. Establishing a cryptographic tunnel between a first tunnel endpoint and a second tunnel endpoint where a private key used during the tunnel establishment is remotely located from the second tunnel endpoint
CN111460405B (zh) * 2020-03-17 2023-06-30 福建升腾资讯有限公司 一种柜外设备进入后台设置的方法、装置、设备和介质
CN112235267A (zh) * 2020-09-29 2021-01-15 北京金山云网络技术有限公司 加载证书的方法、网页服务器、中继服务器、介质和系统
TWI831515B (zh) * 2022-12-13 2024-02-01 臺灣網路認證股份有限公司 自動化憑證申請與網域驗證系統及其方法

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH10340253A (ja) * 1997-06-09 1998-12-22 Chugoku Nippon Denki Software Kk ホームページ情報の登録方法および装置
JP2002512395A (ja) * 1998-04-20 2002-04-23 サン・マイクロシステムズ・インコーポレーテッド 仮想デスクトップ・システム・アーキテクチャを提供するための方法および装置
JP2005506737A (ja) 2001-10-12 2005-03-03 ジオトラスト インコーポレーテッド 自動認証処理及びディジタル証書発行方法及びシステム
US20070067465A1 (en) * 2005-09-16 2007-03-22 Microsoft Corporation Validation of domain name control

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6035402A (en) * 1996-12-20 2000-03-07 Gte Cybertrust Solutions Incorporated Virtual certificate authority
US6816900B1 (en) * 2000-01-04 2004-11-09 Microsoft Corporation Updating trusted root certificates on a client computer
US7047409B1 (en) * 2000-06-09 2006-05-16 Northrop Grumman Corporation Automated tracking of certificate pedigree
WO2003049358A1 (en) 2001-11-29 2003-06-12 Morgan Stanley A method and system for authenticating digital certificates
ITRM20020335A1 (it) * 2002-06-14 2003-12-15 Telecom Italia Mobile Spa Metodo di autoregistrazione e rilascio automatizzato di certificati digitali e relativa architettura di rete che lo implementa.
US7395424B2 (en) * 2003-07-17 2008-07-01 International Business Machines Corporation Method and system for stepping up to certificate-based authentication without breaking an existing SSL session
US7698549B2 (en) * 2003-08-15 2010-04-13 Venafi, Inc. Program product for unified certificate requests from certificate authorities
EP1766848A1 (en) * 2004-06-21 2007-03-28 Echoworx Corporation Method, system and computer program for protecting user credentials against security attacks
US20060143442A1 (en) * 2004-12-24 2006-06-29 Smith Sander A Automated issuance of SSL certificates

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH10340253A (ja) * 1997-06-09 1998-12-22 Chugoku Nippon Denki Software Kk ホームページ情報の登録方法および装置
JP2002512395A (ja) * 1998-04-20 2002-04-23 サン・マイクロシステムズ・インコーポレーテッド 仮想デスクトップ・システム・アーキテクチャを提供するための方法および装置
JP2005506737A (ja) 2001-10-12 2005-03-03 ジオトラスト インコーポレーテッド 自動認証処理及びディジタル証書発行方法及びシステム
US20070067465A1 (en) * 2005-09-16 2007-03-22 Microsoft Corporation Validation of domain name control

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP2154817A4

Cited By (14)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2012065004A (ja) * 2010-09-14 2012-03-29 Panasonic Corp 電子情報導入システム、端末装置、サーバ装置、電子情報導入方法およびプログラム
US9832183B2 (en) 2011-04-19 2017-11-28 Early Warning Services, Llc Key management using quasi out of band authentication architecture
JP2014517567A (ja) * 2011-04-19 2014-07-17 オーセンテイフイ・インコーポレーテツド 疑似帯域外認証アーキテクチャを用いる鍵管理
US9197406B2 (en) 2011-04-19 2015-11-24 Authentify, Inc. Key management using quasi out of band authentication architecture
JP2016507843A (ja) * 2013-02-08 2016-03-10 サーティファイド セキュリティー ソルーションズ,インクCertified Security Solutions,Inc. Scep証明書登録要求の正当性を確認するためのシステムおよび方法
US10200200B2 (en) 2015-01-14 2019-02-05 Canon Kabushiki Kaisha Information processing apparatus capable of performing SSL communication, method of controlling the same, and storage medium
KR20160087753A (ko) * 2015-01-14 2016-07-22 캐논 가부시끼가이샤 Ssl 통신을 행하는 것이 가능한 정보 처리 장치, 그 제어 방법 및 기억 매체
KR101979488B1 (ko) * 2015-01-14 2019-05-16 캐논 가부시끼가이샤 Ssl 통신을 행하는 것이 가능한 정보 처리 장치, 그 제어 방법 및 기억 매체
JP2020533853A (ja) * 2017-09-07 2020-11-19 西安西▲電▼捷通▲無▼綫▲網▼絡通信股▲分▼有限公司China Iwncomm Co., Ltd. デジタル証明書を管理するための方法および装置
US11323433B2 (en) 2017-09-07 2022-05-03 China Iwncomm Co., Ltd. Digital credential management method and device
TWI714359B (zh) * 2018-12-26 2020-12-21 大陸商中國銀聯股份有限公司 一種電子憑證上傳的方法及裝置
CN110730162A (zh) * 2019-09-16 2020-01-24 北京齐尔布莱特科技有限公司 一种页面的验证方法、移动终端、可读存储介质
JP2021016149A (ja) * 2020-06-08 2021-02-12 一般財団法人日本情報経済社会推進協会 電子証明書導入・運用システム、電子証明書導入・運用方法、及び証明書申請装置
JP7102461B2 (ja) 2020-06-08 2022-07-19 一般財団法人日本情報経済社会推進協会 電子証明書導入・運用システム、電子証明書導入・運用方法、及び証明書申請装置

Also Published As

Publication number Publication date
EP2154817A1 (en) 2010-02-17
EP2154817A4 (en) 2012-04-11
JPWO2009001855A1 (ja) 2010-08-26
US20100111300A1 (en) 2010-05-06
EP2154817B1 (en) 2013-09-04
US8234490B2 (en) 2012-07-31
CN101828358A (zh) 2010-09-08
JP4494521B2 (ja) 2010-06-30
CN101828358B (zh) 2012-07-04

Similar Documents

Publication Publication Date Title
WO2009001855A1 (ja) サーバ証明書発行システム
WO2009044577A1 (ja) サーバ証明書発行システム
KR100697133B1 (ko) 전자 서명 첨부 전자 문서 교환 지원 방법 및 정보 처리장치
KR100929488B1 (ko) 서버 기반의 전자서명 위임 시스템 및 방법
KR20210091677A (ko) 디지털 신원 인증 방법, 장치, 기기 및 저장 매체
JP2020145733A (ja) 信頼できるアイデンティティを管理する方法
CN100485699C (zh) 获取凭证的方法和验证凭证的方法
TW202117603A (zh) 二維條碼的處理方法、裝置及系統
CN102035654B (zh) 身份认证方法、设备、服务器及基于身份认证的加密方法
JP2007523396A5 (ja)
JP2005269158A (ja) 電子署名保証システム、方法、プログラム及び装置
TW200723145A (en) Prescription authentication
EP3853758A1 (en) Systems and computer-based methods of document certification and publication
KR20160085143A (ko) 익명 서비스 제공 방법 및 사용자 정보 관리 방법 및 이를 위한 시스템
Jones et al. Proof-of-possession key semantics for JSON Web Tokens (JWTs)
CN103384983B (zh) 长期签名用终端及长期签名用服务器
KR20140140280A (ko) 전자문서 검증 시스템 및 방법
KR20160015152A (ko) 전자문서 관리 시스템 및 방법
JP2018022501A (ja) 複数のサービスシステムを制御するサーバシステム及び方法
Millett et al. Authentication and its privacy effects
JP2009111443A (ja) 属性認証システム、同システムにおける属性認証方法およびプログラム
JP2008027089A (ja) 電子データの開示方法およびシステム
JP2009181598A (ja) デジタル著作権管理のための情報処理装置
JP2015158881A5 (ja) アクセス可否管理システム、WebSocketサーバ、情報処理方法、およびプログラム
JP2009026097A (ja) 情報処理方法、情報処理システムおよびコンピュータ

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 200880100840.8

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 08790608

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2009520614

Country of ref document: JP

WWE Wipo information: entry into national phase

Ref document number: 12452255

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

WWE Wipo information: entry into national phase

Ref document number: 2008790608

Country of ref document: EP