US20130110919A1 - Method for creating/issuing electronic document distribution certificate, method for verifying electronic document distribution certificate, and system for distributing electronic document - Google Patents
Method for creating/issuing electronic document distribution certificate, method for verifying electronic document distribution certificate, and system for distributing electronic document Download PDFInfo
- Publication number
- US20130110919A1 US20130110919A1 US13/808,573 US201113808573A US2013110919A1 US 20130110919 A1 US20130110919 A1 US 20130110919A1 US 201113808573 A US201113808573 A US 201113808573A US 2013110919 A1 US2013110919 A1 US 2013110919A1
- Authority
- US
- United States
- Prior art keywords
- certificate
- distribution
- message
- transmitting
- electronic document
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Abandoned
Links
- 238000000034 method Methods 0.000 title claims abstract description 74
- 238000012795 verification Methods 0.000 claims description 72
- 230000005540 biological transmission Effects 0.000 claims description 71
- 230000000694 effects Effects 0.000 claims description 10
- 239000000344 soap Substances 0.000 claims description 8
- 230000000007 visual effect Effects 0.000 description 6
- 230000007774 longterm Effects 0.000 description 3
- 238000010586 diagram Methods 0.000 description 2
- 238000005516 engineering process Methods 0.000 description 2
- 230000002708 enhancing effect Effects 0.000 description 2
- 239000000284 extract Substances 0.000 description 1
- 230000008520 organization Effects 0.000 description 1
- 230000001360 synchronised effect Effects 0.000 description 1
Images
Classifications
-
- G06Q50/40—
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q10/00—Administration; Management
- G06Q10/10—Office automation; Time management
-
- G06Q50/60—
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L51/00—User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
- H04L51/04—Real-time or near real-time messaging, e.g. instant messaging [IM]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L51/00—User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
- H04L51/21—Monitoring or handling of messages
- H04L51/214—Monitoring or handling of messages using selective forwarding
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L69/00—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass
- H04L69/40—Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass for recovering from a failure of a protocol instance or entity, e.g. service redundancy protocols, protocol state redundancy or protocol service redirection
Definitions
- the present invention relates to a method for creating/issuing an electronic document distribution certificate capable of providing a transparent and efficient issuing service and enhancing reliability of distribution of the electronic document due to compatibility guarantee of a certificate, in creating, distributing, and storing a distribution certificate within a system for distributing an electronic document based on a certified electronic address, a method for verifying an electronic document distribution certificate, and a system for distributing an electronic document.
- the present invention has been made in an effort to provide a method for creating/issuing an electronic document distribution certificate capable of providing a transparent and efficient issuing service and enhancing reliability of distribution of the electronic document due to compatibility guarantee of a certificate, in creating, distributing, and storing a distribution certificate within a system for distributing an electronic document based on a certified electronic address. Further, the present invention has been made in an effort to provide a method for verifying a distribution certificate helping to correctly utilize a certificate by defining a standardized verifying method of a distribution certificate. In addition, the present invention has been made in an effort to provide a system for distributing an electronic document capable of guaranteeing reliability of distribution.
- An exemplary embodiment of the present invention provides a method of creating/issuing a distribution certificate in a system for distributing an electronic document including transmitting and receiving entities and a distribution hub, the method including: (a) transmitting, by a transmitting entity, a distribution message including a transmitter's electronic document to a receiving entity; (b) creating, by a receiving entity, a reception certificate by acquiring essential information after receiving the distribution message; (c) transmitting, by the receiving entity, the created reception certificate to the transmitting entity; (d) completing, by the transmitting entity, verification for the received reception certificate and then, attaching verification information on an electronic signature certificate of the reception certificate to the reception certificate; and (e) transmitting, by the transmitting entity, the reception certificate to a third party storage authority and requesting the storage thereto.
- Another exemplary embodiment of the present invention provides a method for verifying a distribution certificate created/issued in a system for distributing an electronic document including transmitting and receiving entities and a distribution hub, the method including: verifying whether a format of a distribution certificate observes constraints of a predefined structure and value; verifying whether transmitting, receiving, and reading date and time of a distribution message that are established in a distribution certificate, an issuance date of a distribution certificate, a verification time of a certification, and an effect expiration date of a certificate are ordered; verifying an electronic signature attached to the distribution certificate; and verifying validity of a certificate in which an electronic signature is written in the distribution certificate and verifying identity with information on an issuer of the distribution certificate.
- Yet another exemplary embodiment of the present invention provides a system for distributing an electronic document, including: transmitting and receiving entities that distribute an electronic document through a distribution messaging server transmitting and receiving a message based on an electronic document and issuing and managing a distribution certificate for message transmission and reception; a distribution hub that registers/manages the electronic addresses of the transmitting and receiving entities, sets an electronic document distribution path between the transmitting and receiving entities, performs message transmission when errors are created during an electronic document distribution process between the transmitting and receiving entities, and issues the distribution certificate; and a trusted third party storage authority that receives and stores the distribution certificate; wherein the distribution certificate includes a reception certificate for non-repudiation for the fact that a receive entity receives a message, a transmission certificate for verifying a transmission try of the transmit entity, and a reading certificate for non-repudiation for the fact that a receiptor reads the received message.
- FIG. 1 is a diagram for describing creation and issuance of a distribution certification according to an exemplary embodiment of the present invention.
- FIG. 2 is a diagram illustrating a process for creating and issuing a distribution certificate according to an exemplary embodiment of the present invention.
- a method for creating an electronic document distribution certificate includes: (a) transmitting, by a transmitting entity, a distribution message including a transmitter's electronic document to a receiving entity; (b) receiving, by the receiving entity, the distribution message and acquiring essential information to create a reception certificate; (c) transmitting, by the receiving entity, the created reception certificate to the transmitting entity; (d) completing, by the transmitting entity, verification on the received reception certificate and then, attaching verification information on an electronic signature certificate of the reception certificate to the reception certificate; and (e) transmitting, by the transmitting entity, the reception certificate to a third party storage authority to request the storage.
- a method for verifying an electronic document distribution certificate includes: verifying whether a format of the distribution certificate observes constraints of predefined structures and values; verifying whether transmitting, receiving, and reading date and time of a distribution message that are established in a distribution certificate, an issuance date of a distribution certificate, a verification time of a certification, and an effect expiration date of a certificate are ordered; verifying an electronic signature attached to the distribution certificate; and verifying validity of an authentication certificate that an electronic signature is written in the distribution certificate and verifying identity with information on an issuer of the distribution certificate.
- a system for distributing an electronic document includes: transmitting and receiving entities that distribute an electronic document through a distribution messaging server transmitting and receiving a message based on an electronic address and issuing and managing a distribution certificate for message transmission and reception; a distribution hub that registers/manages the electronic addresses of the transmitting and receiving entities, sets an electronic document distribution path between the transmitting and receiving entities, performs message transmission when errors are created during an electronic document distribution process between the transmitting and receiving entities, and issues the distribution certificate; and a trusted third party storage authority that receives and stores the distribution certificate, wherein the distribution certificate includes a reception certificate for non-repudiation for the fact that a receiving entity receives a message, a transmission certificate for verifying a transmission try of the transmitting entity, and a reading certificate for non-repudiation for the fact that a receptor reads the received message.
- FIG. 1 illustrates components for creating and issuing a distribution certificate according to an exemplary embodiment of the present invention and each component will be described with reference to the following ⁇ circle around (1) ⁇ to ⁇ circle around (4) ⁇
- a transmitting entity (or transmitting electronic document mediator, hereinafter, referred to as transmitting entity 101 ): basically transmits a transmitter's electronic document to a receiving entity or if necessary, requests a transmission to a distribution relay server.
- the transmitting entity serves to verify the distribution certificate received from the receiving entity or the distribution relay server and then, attach the verification information to the distribution certificate to be stored in a third party storage authority, in connection with the distribution certificate.
- a receiving entity (or receiving electronic document mediator, hereinafter, referred to as receiving entity 102 ): basically, transfers the electronic document received from the transmitting entity or the distribution relay server to a receiptor).
- the receiving entity serves to create the reception certificate as soon as receiving the electronic document from the transmitting entity or the distribution relay server and transmit the created certificate to the transmitting entity or the distribution relay server as a response message or create a reading certificate immediately after the receiptor reads the electronic document and transfer the created reading certificate to the transmitting entity, in connection with the distribution certificate.
- An electronic document distribution hub (or distribution relay server 103 ): basically, transfers an electronic document receiving a transmission request from the transmitting entity to the receiving entity.
- the electronic document distribution hub serves to create the transmission certificate as soon as receiving the transmission request of the electronic document from the transmitting entity so as to be transmitted to the transmitting entity or transfer the electronic document to the receiving entity and then, transfer the reception certificate received as a response to the transmission certificate to the transmitting entity, in connection with the distribution certificate.
- a third party storage authority serves to safely store the distribution certificate as a trusted authority.
- reference numerals of FIG. 1 will be omitted.
- the essential information required to create the electronic document distribution certificate according to the present invention is as the following Table 1.
- Non- Receiving Document certificate repudiation entity/immediately information for message after transmitter, receiving reception receiptor, fact of transmitter receiving transmitting time, entity receiptor receiving time Transmission Verification Distribution Document certificate for relay information, transmission server/immediately transmitter, try of after receiptor, transmitting reception of transmitter entity transmission transmission request message requesting time Reading Non- Receiving Document Certificate repudiation entity/immediately information, for fact after being transmitter, that read by receiptor, receiptor receiptor transmitter reads transmitting time, received receiptor receiving message time, receiptor reading time
- a method for acquiring essential information on the electronic document distribution certificate according to the present invention is as the following Table 2.
- the system time of the distribution messaging server and the distribution relay server needs to be periodically synchronized with the time of externally authorized institution.
- FIG. 2 All of the processes involved in the electronic document distribution certificate according to the present invention are illustrated in FIG. 2 .
- the reception certificate is an electronic document distribution certificate created for verifying the fact that the electronic document distribution message is received from the transmitting entity and the processes involved in the reception certificate are as the following Table 3.
- the transmitting entity transmits the distribution message including the transmitter's electronic document to the receiving entity 2
- the receiving entity receives the distribution message and then, immediately receives the essential information to create the reception certificate 3
- the receiving entity transmits the created reception certificate to the transmitting entity 4
- the transmitting entity completes verification for the reception certificate and then, attaches the verification information on the electronic signature certificate of the reception certificate to the reception certificate 5
- the transmitting entity transmits and stores the reception certificate to the certified electronic document storage authority.
- the transmission certificate is created by the distribution relay server for verifying the fact that the transmitting entity makes the transmission request and transmitted to the transmitting entity.
- the process involved in the transmission certificate is as the following Table 4.
- the transmitting entity transmits the distribution message to the receiving entity.
- the distribution relay server creates the transmission certificate for the requested transmission.
- the distribution relay server transmits the transmission certificate to the transmitting entity.
- the transmitting entity completes verification for the transmission certificate and then, attaches the verification information on the electronic signature certificate of the transmission certificate to the transmission certificate.
- the transmitting entity stores the transmission certificate in the certified electronic document storage authority.
- the distribution relay server transfers the distribution message to the receiving entity.
- the receiving entity creates the reception certificate immediately after the reception of the electronic document.
- the receiving entity transmits the reception certificate to the distribution relay server 10
- the distribution relay server transfers the reception certificate to the transmitting entity.
- the transmitting entity completes the verification for the reception certificate and then, attaches the verification information on the electronic signature certificate of the reception certificate to the reception certificate 12
- the transmitting entity transmits and stores the reception certificate to the certified electronic document storage authority.
- the reading certificate is a certificate that is created by the receiving entity and is transmitted to the transmitting entity so as to verify that the receiptor reads the message received from the transmitting entity by the receiving entity and the process involved in the reading certificate is as the following Table 5.
- Process Name 1 The receiptor requests the reading of the distribution message to the receiving entity to read the distribution message received as a response. 2
- the receiving entity creates the reading certificate. 3
- the receiving entity completes the verification for the reading certificate and then, attaches the verification information on the electronic signature certificate of the reading certificate to the reading certificate. 4
- the transmitting entity transmits and stores the reading certificate to the certified electronic document authority.
- the basic preconditions and considerations involved in the issuance and verification of the distribution certificate are as the following ⁇ circle around (1) ⁇ to ⁇ circle around (9) ⁇ .
- the distribution certificate is created and verified by the distribution messaging server and the distribution relay server of the transmitting and receiving entities.
- the distribution certificate is electronically signed and created only based on an NPKI certificate.
- the corresponding distribution certificate is created based on the distribution message. Even though at least two electronic documents are included in a single distribution message, only one distribution certificate created.
- the distribution certificate needs to be allocated with an ID that can identify the distribution message and an electronic document identifier or an electronic document name that can identify the electronic document within the distribution message.
- a serial number of the distribution certificate is created by individual transmitting and receiving entities and thus uses a random number of 32 bytes so as to allocate uniqueness.
- Update and revocation of the distribution certificate is not defined in terms of characteristics of the distribution system.
- the distribution messaging server needs to maintain the synchronization with the visual information of the external trusted institution at all times, thereby guaranteeing the reliability of the visual information within the distribution certificate.
- the policies of the distribution certificate use only an object identifier (OID) and a name that are defined in the present technology standard.
- the transmitting entity verifies the received distribution certificate and then, attaches the verification information on the signature certificate of the distribution certificate to the distribution certificate.
- the electronic document distribution certificate is created by the transmitting and receiving entities and electronically signed by using the NPKI certificate of the transmitting and receiving entities.
- the basic structure of the electronic document distribution certificate uses a SignedData structure of a CMS standard to use the same content identifier as the certificate of the certified electronic document authority.
- a basic field of the electronic document distribution certificate is as the following Table 7.
- ARCCertInfo SEQUENCE ⁇ version [0] EXPLICIT ARCVersion DEFAULT v1, serialNumber SerialNumber, issuer GeneralNames, dateOfIssue GeneralizedTime, dateOfExpire DateOfExpiration, policy ARCCertificatePolicies, requestInfo RequestInfo, target TargetToCertify, extionsions [1] EXPLICIT Extensions OPTIONAL ⁇
- a version of the structure of the electronic document distribution certificate is represented.
- the version is set to be v9 and uses a distributionInfos type of a target field.
- the identification information of the electronic document distribution certificate is represented.
- the serial number of the electronic document distribution certificate uses a random number of 32 bytes so as to be created as a unique amount of integer value. In order to process the electronic document distribution certificate, there is a need to process a serial number of 32 bytes.
- a subject issuing the electronic document distribution certificate is represented.
- a directoryName field having a GeneralName structure is necessarily used and the receiving entity or the distribution relay server extracts a subjectDN value of the certificate in which the electronic document distribution certificate is electronically signed so as to be set as it is.
- the time when the electronic document distribution certificate is issued is represented.
- the dataOfIssue uses a GeneralizedTime format.
- the dataOfExpire of the electronic document distribution certificate is in the future, as compared with the dataOfIssue and needs to be set to have a sufficient spare in consideration of a period required to verify the distribution fact.
- the policy of the electronic document distribution certificate is represented.
- the present field is configured of Qualifier information for representing a policy OID according to types of electronic document distribution certificates and types of electronic document distribution certificates. It is to be noted that only userNotice is used as the Qualifier information and cPSuri is not used.
- the types of electronic document distribution certificates are displayed using an explicitText field that is lower than the userNotice field and a format thereof needs to use BMPString.
- the policy OID within the electronic document distribution certificate follows the types of certificates and needs to use only the values designated in the present invention.
- the OID and the Qualifier information according to the type of the electronic document distribution certificate are as follows.
- the present field is set to be null.
- RequestInfo :: CHOICE ⁇ arcCertRequest ARCCertRequest, null NULL ⁇
- the present field includes the contents to be verified.
- the present field needs to set the information on the distribution message by necessarily using the lower distributionInfos field.
- the certified electronic address of the transmitter transmitting the electronic document distribution message is represented.
- the certified electronic address of the receiptor receiving the electronic document distribution message is represented.
- the time when the distribution message is transmitted by the transmitter is represented.
- the transmitting date and time of the reception certificate and the reading certificate means the time when the transmitting entity transmits the distribution message and the value of the TimeStamp field that is included in the SOAP message within the “message transmission” distribution linkage message is represented in the GeneralizedTime format.
- the transmitting date and time of the transmission certificate means the time when the transmitting entity requests the transmission of the distribution message to the distribution relay server and uses the time when the distribution relay server receives the “message transmission request” distribution message, unlike other distribution certificates using time values within the distribution linkage message.
- the time field only the present field is included in the transmission certificate and the receiving date and time field and the reading date and time field are not created.
- the time when the receiptor receives the distribution message is represented.
- the receiving date and time is a field that is created only in the reception certificate and the reading certificate and is set as the time when the distribution messaging server of the receiving entity receives the “message transmission” distribution message.
- the receiving date and time is after the transmitting date and time and is equal to or earlier than the time when the certificate is created.
- the time when the receiptor reads the electronic document after receiving the electronic document is represented.
- the reading date and time is a field that is created only in the reading certificate and is set as the time when the distribution messaging server of the receiving entity responds to the receiptor's “message detailed information request”.
- the time needs to be equal to a value of a TimeStamp field included in the SOAP message within the distribution linkage message responding to the receiptor by the receiving entity represented in the GeneralizedTime format.
- the reading date and time needs to be equal to or earlier than the time when the certificate is created and is equal to or later than the receiving date and time.
- An identification value for the distribution message is represented.
- An identifier of the distribution message that is the issuance object of the electronic document distribution certificate is set as it is.
- the number of electronic document files attached to the distribution message is represented.
- the number of electronic document files attached to the actual distribution message is set.
- the distribution message may be attached with at least one electronic document file and sets the information on the individual files using a DistributedFile structure.
- Hash values of individual electronic document files attached to the distribution message are represented.
- the individual electronic document file is set in a hashedData field after a hash value is created using a hash algorithm of a hashAlg field.
- Identifiers of individual electronic document files attached to the distribution message are represented.
- the file identification value is not present within the distribution message and a Content-ID value of the individual electronic document file attached to the overall distribution linkage message configured of a Multi Part message in an MIME format is set as it is.
- the field may be selectively used, but when the file name field is not used, is necessarily used and it is recommended that the file identification value field be used.
- the distribution certificate is compared with the electronic document file and verified by preferentially using the file identification value field.
- the file names of the individual electronic document files attached to the distribution message are represented.
- the file name field is necessarily created and as a value, the Content-ID value of the individual electronic document file attached to the overall distribution linkage message configured of the Multi Part message in the MIME format is set as it is.
- the file name field may be omitted and the value capable of auxiliarily identifying the electronic document file is set at the time of the creation of the file identification value field.
- the electronic document distribution certificate profile is as the following Table 17.
- a public key encryption algorithm uses RSA and a hash algorithm uses SHA256
- the distribution message transmitting entity needs to perform the verification on the certificate as soon as receiving the electronic document distribution certificate.
- the process of verifying distribution certificate is largely divided into the validity verification of the certificate and the content verification of the certificate.
- the validity verification of the certificate is a process of confirming whether conditions for obtaining an effect as the certificate are satisfied and the content verification of the certificate is a process of confirming the fact by comparing with the distribution message to be verified through the certificate. Therefore, the content verification of the certificate is not the verification for the certificate but may be considered to be performed to confirm whether the distribution fact is truth.
- the validity verification of the electronic document distribution certificate is performed by the processes of ⁇ circle around (1) ⁇ verifying the certificate format, ⁇ circle around (2) ⁇ visually verifying certificate, ⁇ circle around (3) ⁇ verifying the certificate electronic signature, and ⁇ circle around (4) ⁇ verifying the signature certificate and the content verification of the certificate is performed by ⁇ circle around (5) ⁇ the process of comparing and verifying the distribution message.
- the verification of the certificate format is a process of confirming whether the format of the distribution certificate to be verified observes the constraints of the structure and value defined in the present standard and the following 1) to 7) matters are basically confirmed at the time of verifying the certificate format.
- the certificate visual verification is a process of confirming whether the values of each visual field set in the distribution certificate are normal at the verification reference time. That is, it is confirmed that the values of each visual field set in the distribution certificate meets the rule of the following Table 18 unlike those at the verification reference time, during the present process.
- the verification of the electronic signature is a process of verifying the electronic signature attached to the distribution certificate for integrity guarantee and non-repudiation for the contents to be verified by the distribution certificate and follows the method for verifying an electronic signature for the signedData of a general CMS.
- the verification of the signature certificate is a process of verifying the validity of the certificate in which the distribution certificate is electronically signed and the identity with the issuer information of the distribution certificate.
- the validity verification of the electronic signature certificate is a process that is generally included in the process of verifying the electronic signature as a part thereof and is performed by the processes of verifying an available period of the certificate, verifying the revocation, and verifying a path with the upper CA certificates, and the like. This is verified based on “technology standard [KCAC.TS.CERTVAL] of verifying authorized certificate path” of the authorized certificate system.
- the issuer information of the distribution certificate is formed to set a subject DN value of the electronic signature certificate as it is and therefore, two values are extracted to perform the comparison and verification on whether the two values coincide with each other.
- the process of comparing and verifying a distribution message is not a process of verifying the validity of the distribution certificate but is a process of confirming whether the distribution fact is truth by comparing and verifying the information of the distribution message included in the distribution certificate with that of the actual distribution message.
- the transmitting entity transmits the distribution message or receives the distribution certificate after the transmission request, it is to be necessarily confirmed that the corresponding distribution certificate includes the information on the distribution message transmitted by the transmitting entity, by performing the comparison and verification of the present distribution message.
- the distribution certificate is registered and stored in the certified electronic document authority, which provides only the long-term guarantee function for the storage time and integrity of the distribution certificate but cannot guarantee the long period of time for the validity of the electronic signature certificate of the issuance time of the distribution certificate after the available period of the electronic signature certificate expires. That is, after the valid period of the electronic signature certificate expires, the validity guarantee of the distribution certificate is not permitted.
- the transmitting entity collects CRL and ARL and an upper CA certificate and a Root CA certificate for verifying the revocation of the electronic signature certificate and the path so as to perform the process of “5.2.4 verification of signature certificate” among the processes of verifying the validity of the received distribution certificate. It is possible to guarantee the validity of the electronic signature certificate at the time of the issuance of the distribution certificate by storing the corresponding data in the certified electronic document authority together with the distribution certificate, such that the validity of the distribution certificate is guaranteed.
- the transmitting entity includes the CRL and the ARL and the upper CA certificate and the Root CA certificate that are used for verification in a certificates field and a crls field within the signedData structure of the distribution certificate after the verification for the electronic signature certificate succeeds. Precautions need to perform only the work including each information in the corresponding field regardless of an order of including each information. Since the certificates field and the crls field are not the electronic signature object information of the signedData, the verification for the distribution certificate still succeeds even after the corresponding work is performed.
- SignedData SEQUENCE ⁇ version CMSVersion, digestAlgorithms DigestAlgorithmIdentifiers, encapContentInfo EncapsulatedContentInfo, certificates [0] IMPLICIT CertificateSet OPTIONAL, crls [1] IMPLICIT RevocationInfoChoices OPTIONAL, signerInfosSignerInfos ⁇
- the transmitting entity stores the distribution certificate in which the verification information of the electronic signature certificate is included in the certified electronic document authority, such that the long-term verification for the distribution certificate can be performed.
Abstract
Description
- The present invention relates to a method for creating/issuing an electronic document distribution certificate capable of providing a transparent and efficient issuing service and enhancing reliability of distribution of the electronic document due to compatibility guarantee of a certificate, in creating, distributing, and storing a distribution certificate within a system for distributing an electronic document based on a certified electronic address, a method for verifying an electronic document distribution certificate, and a system for distributing an electronic document.
- Generally, an electronic document distribution has limitedly been conducted only within a specific industrial group or a community based on individual inherent regulations of enterprises/organizations.
- There are disadvantages in that e-mail has been used as an auxiliary means between individuals and between individuals and enterprises/organizations without a concept of trusted electronic distribution or one-line communications may be made only by a method of accessing individuals, individual businesses, small-scale enterprises to large-scale enterprises.
- Therefore, enterprises holding a predetermined scale of distribution system and individuals, individual businesses, and small-scale enterprises need to build an electronic document distribution based infrastructure capable of guaranteeing reliability of distribution.
- The present invention has been made in an effort to provide a method for creating/issuing an electronic document distribution certificate capable of providing a transparent and efficient issuing service and enhancing reliability of distribution of the electronic document due to compatibility guarantee of a certificate, in creating, distributing, and storing a distribution certificate within a system for distributing an electronic document based on a certified electronic address. Further, the present invention has been made in an effort to provide a method for verifying a distribution certificate helping to correctly utilize a certificate by defining a standardized verifying method of a distribution certificate. In addition, the present invention has been made in an effort to provide a system for distributing an electronic document capable of guaranteeing reliability of distribution.
- An exemplary embodiment of the present invention provides a method of creating/issuing a distribution certificate in a system for distributing an electronic document including transmitting and receiving entities and a distribution hub, the method including: (a) transmitting, by a transmitting entity, a distribution message including a transmitter's electronic document to a receiving entity; (b) creating, by a receiving entity, a reception certificate by acquiring essential information after receiving the distribution message; (c) transmitting, by the receiving entity, the created reception certificate to the transmitting entity; (d) completing, by the transmitting entity, verification for the received reception certificate and then, attaching verification information on an electronic signature certificate of the reception certificate to the reception certificate; and (e) transmitting, by the transmitting entity, the reception certificate to a third party storage authority and requesting the storage thereto.
- Another exemplary embodiment of the present invention provides a method for verifying a distribution certificate created/issued in a system for distributing an electronic document including transmitting and receiving entities and a distribution hub, the method including: verifying whether a format of a distribution certificate observes constraints of a predefined structure and value; verifying whether transmitting, receiving, and reading date and time of a distribution message that are established in a distribution certificate, an issuance date of a distribution certificate, a verification time of a certification, and an effect expiration date of a certificate are ordered; verifying an electronic signature attached to the distribution certificate; and verifying validity of a certificate in which an electronic signature is written in the distribution certificate and verifying identity with information on an issuer of the distribution certificate.
- Yet another exemplary embodiment of the present invention provides a system for distributing an electronic document, including: transmitting and receiving entities that distribute an electronic document through a distribution messaging server transmitting and receiving a message based on an electronic document and issuing and managing a distribution certificate for message transmission and reception; a distribution hub that registers/manages the electronic addresses of the transmitting and receiving entities, sets an electronic document distribution path between the transmitting and receiving entities, performs message transmission when errors are created during an electronic document distribution process between the transmitting and receiving entities, and issues the distribution certificate; and a trusted third party storage authority that receives and stores the distribution certificate; wherein the distribution certificate includes a reception certificate for non-repudiation for the fact that a receive entity receives a message, a transmission certificate for verifying a transmission try of the transmit entity, and a reading certificate for non-repudiation for the fact that a receiptor reads the received message.
- As set forth above, according to the exemplary embodiments of the present invention, it is possible to provide the transparent and efficient issuance service, in creating, distributing, and storing the distribution certificate within the system for distributing an electronic document based on the certified electronic address.
- According to the exemplary embodiments of the present invention, it is possible to enhance the reliability of distribution of the electronic document by guaranteeing the compatibility in the certificate within a system for distributing an electronic document based on a certified electronic address.
- According to the exemplary embodiments of the present invention, it is possible to provide the method for verifying a distribution certificate helping to correctly utilize a certificate by defining the standardized verifying method for the distribution certificate.
-
FIG. 1 is a diagram for describing creation and issuance of a distribution certification according to an exemplary embodiment of the present invention. -
FIG. 2 is a diagram illustrating a process for creating and issuing a distribution certificate according to an exemplary embodiment of the present invention. - A method for creating/issuing an electronic document distribution certificate, a method for verifying an electronic document distribution certificate, and a system for distributing an electronic document according to exemplary embodiments of the present invention will be described below with reference to the accompanying drawings and Tables.
- A method for creating an electronic document distribution certificate according to an exemplary embodiment of the present invention includes: (a) transmitting, by a transmitting entity, a distribution message including a transmitter's electronic document to a receiving entity; (b) receiving, by the receiving entity, the distribution message and acquiring essential information to create a reception certificate; (c) transmitting, by the receiving entity, the created reception certificate to the transmitting entity; (d) completing, by the transmitting entity, verification on the received reception certificate and then, attaching verification information on an electronic signature certificate of the reception certificate to the reception certificate; and (e) transmitting, by the transmitting entity, the reception certificate to a third party storage authority to request the storage.
- A method for verifying an electronic document distribution certificate according to another exemplary embodiment of the present invention includes: verifying whether a format of the distribution certificate observes constraints of predefined structures and values; verifying whether transmitting, receiving, and reading date and time of a distribution message that are established in a distribution certificate, an issuance date of a distribution certificate, a verification time of a certification, and an effect expiration date of a certificate are ordered; verifying an electronic signature attached to the distribution certificate; and verifying validity of an authentication certificate that an electronic signature is written in the distribution certificate and verifying identity with information on an issuer of the distribution certificate.
- A system for distributing an electronic document according to yet another exemplary embodiment of the preset invention includes: transmitting and receiving entities that distribute an electronic document through a distribution messaging server transmitting and receiving a message based on an electronic address and issuing and managing a distribution certificate for message transmission and reception; a distribution hub that registers/manages the electronic addresses of the transmitting and receiving entities, sets an electronic document distribution path between the transmitting and receiving entities, performs message transmission when errors are created during an electronic document distribution process between the transmitting and receiving entities, and issues the distribution certificate; and a trusted third party storage authority that receives and stores the distribution certificate, wherein the distribution certificate includes a reception certificate for non-repudiation for the fact that a receiving entity receives a message, a transmission certificate for verifying a transmission try of the transmitting entity, and a reading certificate for non-repudiation for the fact that a receptor reads the received message.
- The method for creating an electronic document distribution certificate, the method for verifying an electronic document distribution certificate, and the system for distributing an electronic document according to the exemplary embodiments of the present invention having the foregoing configuration will be described in detail with reference to
FIGS. 1 and 2 . - [Model for Creating and Issuing Electronic Document Distribution Certificate]
-
FIG. 1 illustrates components for creating and issuing a distribution certificate according to an exemplary embodiment of the present invention and each component will be described with reference to the following {circle around (1)} to {circle around (4)} - {circle around (1)} A transmitting entity (or transmitting electronic document mediator, hereinafter, referred to as transmitting entity 101): basically transmits a transmitter's electronic document to a receiving entity or if necessary, requests a transmission to a distribution relay server. The transmitting entity serves to verify the distribution certificate received from the receiving entity or the distribution relay server and then, attach the verification information to the distribution certificate to be stored in a third party storage authority, in connection with the distribution certificate.
- {circle around (2)} A receiving entity (or receiving electronic document mediator, hereinafter, referred to as receiving entity 102): basically, transfers the electronic document received from the transmitting entity or the distribution relay server to a receiptor). The receiving entity serves to create the reception certificate as soon as receiving the electronic document from the transmitting entity or the distribution relay server and transmit the created certificate to the transmitting entity or the distribution relay server as a response message or create a reading certificate immediately after the receiptor reads the electronic document and transfer the created reading certificate to the transmitting entity, in connection with the distribution certificate.
- {circle around (3)} An electronic document distribution hub (or distribution relay server 103): basically, transfers an electronic document receiving a transmission request from the transmitting entity to the receiving entity. The electronic document distribution hub serves to create the transmission certificate as soon as receiving the transmission request of the electronic document from the transmitting entity so as to be transmitted to the transmitting entity or transfer the electronic document to the receiving entity and then, transfer the reception certificate received as a response to the transmission certificate to the transmitting entity, in connection with the distribution certificate.
- {circle around (4)} A third party storage authority (certified electronic document storage authority 104) serves to safely store the distribution certificate as a trusted authority. Hereinafter, in describing the present invention, reference numerals of
FIG. 1 will be omitted. - The essential information required to create the electronic document distribution certificate according to the present invention is as the following Table 1.
-
TABLE 1 Creation Essential Type Purpose Subject/Time information Reception Non- Receiving Document certificate repudiation entity/immediately information, for message after transmitter, receiving reception receiptor, fact of transmitter receiving transmitting time, entity receiptor receiving time Transmission Verification Distribution Document certificate for relay information, transmission server/immediately transmitter, try of after receiptor, transmitting reception of transmitter entity transmission transmission request message requesting time Reading Non- Receiving Document Certificate repudiation entity/immediately information, for fact after being transmitter, that read by receiptor, receiptor receiptor transmitter reads transmitting time, received receiptor receiving message time, receiptor reading time - A method for acquiring essential information on the electronic document distribution certificate according to the present invention is as the following Table 2.
-
TABLE 2 Essential Type information Method for acquiring information Reception Document Use the sensitive field value of certificate information, the distribution message and the transmitter, SOAP message within the receiptor, distribution linkage message transmitter transmitted by the transmitting transmitting entity time Receiptor Use the receiving time of the receiving distribution messaging server of time the receiving entity Transmission Document Use the sensitive field value of certificate information, the distribution message within transmitter, the distribution linkage message receiptor transmitted by the transmitting entity Transmitter Use the receiving time of the transmission distribution relay server requesting time Reading Document Use the sensitive field value of Certificate information, the distribution message and the transmitter, SOAP message within the receiptor, distribution linkage message transmitter transmitted by the transmitting transmitting entity time Receiptor Use the receiving time of the receiving distribution messaging server by time the receiving entity Receiptor Use the response time of the reading time receiving entity for the document information request of the receiptor - The system time of the distribution messaging server and the distribution relay server needs to be periodically synchronized with the time of externally authorized institution.
- All of the processes involved in the electronic document distribution certificate according to the present invention are illustrated in
FIG. 2 . - The reception certificate is an electronic document distribution certificate created for verifying the fact that the electronic document distribution message is received from the transmitting entity and the processes involved in the reception certificate are as the following Table 3.
-
TABLE 3 No. Process Name 1 The transmitting entity transmits the distribution message including the transmitter's electronic document to the receiving entity 2 The receiving entity receives the distribution message and then, immediately receives the essential information to create the reception certificate 3 The receiving entity transmits the created reception certificate to the transmitting entity 4 The transmitting entity completes verification for the reception certificate and then, attaches the verification information on the electronic signature certificate of the reception certificate to the reception certificate 5 The transmitting entity transmits and stores the reception certificate to the certified electronic document storage authority. - When the transmitting entity tries the distribution message transmission to the receiving entity but fails in the distribution message transmission, and thus requests the transmission of the corresponding message to the distribution relay server, the transmission certificate is created by the distribution relay server for verifying the fact that the transmitting entity makes the transmission request and transmitted to the transmitting entity. The process involved in the transmission certificate is as the following Table 4.
-
TABLE 4 No. Process Name 1 The transmitting entity transmits the distribution message to the receiving entity. 2 When the distribution message transmission fails, the transmitting entity requests the distribution message transmission to the distribution relay server. 3 The distribution relay server creates the transmission certificate for the requested transmission. 4 The distribution relay server transmits the transmission certificate to the transmitting entity. 5 The transmitting entity completes verification for the transmission certificate and then, attaches the verification information on the electronic signature certificate of the transmission certificate to the transmission certificate. 6 The transmitting entity stores the transmission certificate in the certified electronic document storage authority. 7 The distribution relay server transfers the distribution message to the receiving entity. 8 The receiving entity creates the reception certificate immediately after the reception of the electronic document. 9 The receiving entity transmits the reception certificate to the distribution relay server 10 The distribution relay server transfers the reception certificate to the transmitting entity. 11 The transmitting entity completes the verification for the reception certificate and then, attaches the verification information on the electronic signature certificate of the reception certificate to the reception certificate 12 The transmitting entity transmits and stores the reception certificate to the certified electronic document storage authority. - The reading certificate is a certificate that is created by the receiving entity and is transmitted to the transmitting entity so as to verify that the receiptor reads the message received from the transmitting entity by the receiving entity and the process involved in the reading certificate is as the following Table 5.
-
TABLE 5 No. Process Name 1 The receiptor requests the reading of the distribution message to the receiving entity to read the distribution message received as a response. 2 The receiving entity creates the reading certificate. 3 The receiving entity completes the verification for the reading certificate and then, attaches the verification information on the electronic signature certificate of the reading certificate to the reading certificate. 4 The transmitting entity transmits and stores the reading certificate to the certified electronic document authority. - The basic preconditions and considerations involved in the issuance and verification of the distribution certificate are as the following {circle around (1)} to {circle around (9)}.
- {circle around (1)} The distribution certificate is created and verified by the distribution messaging server and the distribution relay server of the transmitting and receiving entities.
- {circle around (2)} In the present invention, the distribution certificate is electronically signed and created only based on an NPKI certificate.
- {circle around (3)} The corresponding distribution certificate is created based on the distribution message. Even though at least two electronic documents are included in a single distribution message, only one distribution certificate created.
- {circle around (4)} The distribution certificate needs to be allocated with an ID that can identify the distribution message and an electronic document identifier or an electronic document name that can identify the electronic document within the distribution message.
- {circle around (5)} A serial number of the distribution certificate is created by individual transmitting and receiving entities and thus uses a random number of 32 bytes so as to allocate uniqueness.
- {circle around (6)} Update and revocation of the distribution certificate is not defined in terms of characteristics of the distribution system.
- {circle around (7)} The distribution messaging server needs to maintain the synchronization with the visual information of the external trusted institution at all times, thereby guaranteeing the reliability of the visual information within the distribution certificate.
- {circle around (8)} The policies of the distribution certificate use only an object identifier (OID) and a name that are defined in the present technology standard.
- {circle around (9)} The transmitting entity verifies the received distribution certificate and then, attaches the verification information on the signature certificate of the distribution certificate to the distribution certificate.
- The electronic document distribution certificate is created by the transmitting and receiving entities and electronically signed by using the NPKI certificate of the transmitting and receiving entities. The basic structure of the electronic document distribution certificate uses a SignedData structure of a CMS standard to use the same content identifier as the certificate of the certified electronic document authority.
- ContentType of the electronic document distribution certificate is as the following Table 6.
-
TABLE 6 id-kiec-arcCertReseponse OBJECT IDENTIFIER ::= { iso(1) member-body(2) korea(410) kiec(200032) certificate(2) 2 } ARCCertResponse ::= CHOICE { arcCertInfo [0] EXPLICIT ARCCertInfo, arcErrorNotice [1] EXPLICIT ARCErrorNotice } - A basic field of the electronic document distribution certificate is as the following Table 7.
-
TABLE 7 ARCCertInfo ::= SEQUENCE { version [0] EXPLICIT ARCVersion DEFAULT v1, serialNumber SerialNumber, issuer GeneralNames, dateOfIssue GeneralizedTime, dateOfExpire DateOfExpiration, policy ARCCertificatePolicies, requestInfo RequestInfo, target TargetToCertify, extionsions [1] EXPLICIT Extensions OPTIONAL } - The detailed contents of the basic field of the foregoing distribution certificate are the following to.
- {circle around (1)} Version, Version
- A version of the structure of the electronic document distribution certificate is represented. For the electronic document distribution certificate, the version is set to be v9 and uses a distributionInfos type of a target field.
-
TABLE 8 ARCVersion ::= INTEGER {v1(1), v2(2), v9(9)} - {circle around (2)} SerialNumber, Serial Number
- The identification information of the electronic document distribution certificate is represented.
- The serial number of the electronic document distribution certificate uses a random number of 32 bytes so as to be created as a unique amount of integer value. In order to process the electronic document distribution certificate, there is a need to process a serial number of 32 bytes.
-
TABLE 9 SerialNumber ::= INTEGER - {circle around (3)} Issuer, Issuer of Certificate
- A subject issuing the electronic document distribution certificate is represented.
- When the value of the present field is created, a directoryName field having a GeneralName structure is necessarily used and the receiving entity or the distribution relay server extracts a subjectDN value of the certificate in which the electronic document distribution certificate is electronically signed so as to be set as it is.
-
TABLE 10 GeneralNames ::= SEQUENCE SIZE (1..MAX) OF GeneralName GeneralName ::= CHOICE { otherName [0] OtherName, rfc822Name [1] IA5String, dNSName [2] IA5String, x400Address [3] ORAddress, directoryName [4] Name, ediPartyName [5] EDIPartyName, uniformResourceIdentifier [6] IA5String, iPAddress [7] OCTET STRING, registeredID [8] OBJECT IDENTIFIER } Name ::= CHOICE { RDNSequence } RDNSequence ::= SEQUENCE OF RelativeDistinguishedName RelativeDistinguishedName ::= SET OF AttributeTypeAndValue AttributeTypeAndValue ::= SEQUENCE { type AttributeType, value AttributeValue } AttributeType ::= OBJECT IDENTIFIER AttributeValue ::= ANY DEFINED BY AttributeType DirectoryString ::= CHOICE { teletexString TeletexString (SIZE (1..MAX)), printableString PrintableString (SIZE (1..MAX)), universalString UniversalString (SIZE (1..MAX)), utf8String UTF8String (SIZE (1..MAX)), bmpString BMPString (SIZE (1..MAX)) } - {circle around (4)} DataOfIssue, Issuance Date of Certificate
- The time when the electronic document distribution certificate is issued is represented.
- The dataOfIssue uses a GeneralizedTime format.
- {circle around (5)} DataOfExpire, Effect Expiration Date of Certificate
- The time when the electronic document distribution certificate expires is represented.
- The dataOfExpire of the electronic document distribution certificate is in the future, as compared with the dataOfIssue and needs to be set to have a sufficient spare in consideration of a period required to verify the distribution fact.
-
TABLE 11 DateOfExpiration ::= GeneralizedTime - {circle around (6)} Policy, Certificate Policy
- The policy of the electronic document distribution certificate is represented.
- The present field is configured of Qualifier information for representing a policy OID according to types of electronic document distribution certificates and types of electronic document distribution certificates. It is to be noted that only userNotice is used as the Qualifier information and cPSuri is not used. The types of electronic document distribution certificates are displayed using an explicitText field that is lower than the userNotice field and a format thereof needs to use BMPString.
-
TABLE 12 ARCCertificatePolicies ::= SEQUENCE SIZE (1..MAX) OF PolicyInformation PolicyInformation ::= SEQUENCE { policyIdentifier CertPolicyId, policyQualifiers SEQUENCE SIZE (1..MAX) OF PolicyQualifierInfo OPTIONAL } CertPolicyId ::= OBJECT IDENTIFIER PolicyQualifierInfo ::= SEQUENCE { policyQualifierId PolicyQualifierId, qualifier ANY DEFINED BY policyQualifierId } PolicyQualifierId ::= OBJECT IDENTIFIER ( id-qt-cps | id- qt-unotice ) Qualifier ::= CHOICE { cPSuri CPSuri, userNotice UserNotice } UserNotice ::= SEQUENCE { noticeRef NoticeReference OPTIONAL, explicitText DisplayText OPTIONAL} NoticeReference ::= SEQUENCE { organization DisplayText, noticeNumbers SEQUENCE OF INTEGER } DisplayText ::= CHOICE { ia5String IA5String(SIZE (1..200)), visibleString VisibleString(SIZE (1..200)), bmpString BMPString(SIZE (1..200)), utf8String UTF8String(SIZE (1..200)) } - The policy OID within the electronic document distribution certificate follows the types of certificates and needs to use only the values designated in the present invention.
- The OID and the Qualifier information according to the type of the electronic document distribution certificate are as follows.
-
TABLE 13 Type of Certificate Policy OID Qualifier Transmission 1.2.410.200032.6.1 “Transmission certificate certificate” Reception 1.2.410.200032.6.2 “Reception certificate certificate” Reading 1.2.410.200032.6.3 “Reading certificate certificate” - {circle around (7)} RequestInfo, Certificate Request Message Information
- The present field is set to be null.
-
TABLE 14 RequestInfo ::= CHOICE { arcCertRequest ARCCertRequest, null NULL } - {circle around (8)} Target, Object to Certify
- The present field includes the contents to be verified.
- The present field needs to set the information on the distribution message by necessarily using the lower distributionInfos field.
-
TABLE 15 TargetToCertify ::= CHOICE { opRecord [0] EXPLICIT OperationRecord, orgAndIssued [1] EXPLICIT OriginalAndIssuedDocumentInfo, dataHash [2] EXPLICIT HashedDataInfo distributionInfos [10] EXPLICIT DistributionInfos } DistributionInfos ::= SEQUENCE OF DistributionInfo DistributionInfo ::= SEQUENCE { senderAdd UTF8String, receiptorAdd UTF8String, dateOfSend GeneralizedTime, dateOfReceive [0] EXPLICIT GeneralizedTime OPTIONAL, dateOfReceiveConfirm [1] EXPLICIT GeneralizedTime OPTIONAL, distributionId UTF8String, numberOfFiles INTEGER, distributedFileInfos DistributedFileInfos } - 1) SenderAdd, Transmitter's Certified Electronic Address
- The certified electronic address of the transmitter transmitting the electronic document distribution message is represented.
- 2) ReceiverAdd, Receiptor's Certified Electronic Address
- The certified electronic address of the receiptor receiving the electronic document distribution message is represented.
- 3) DateOfsend, Transmitting Date and Time
- The time when the distribution message is transmitted by the transmitter is represented.
- The transmitting date and time of the reception certificate and the reading certificate means the time when the transmitting entity transmits the distribution message and the value of the TimeStamp field that is included in the SOAP message within the “message transmission” distribution linkage message is represented in the GeneralizedTime format.
- It is to be noted that the transmitting date and time of the transmission certificate means the time when the transmitting entity requests the transmission of the distribution message to the distribution relay server and uses the time when the distribution relay server receives the “message transmission request” distribution message, unlike other distribution certificates using time values within the distribution linkage message. In connection with the time field, only the present field is included in the transmission certificate and the receiving date and time field and the reading date and time field are not created.
- 4) DateOfReceive, Receiving Date and Time
- The time when the receiptor receives the distribution message is represented.
- The receiving date and time is a field that is created only in the reception certificate and the reading certificate and is set as the time when the distribution messaging server of the receiving entity receives the “message transmission” distribution message.
- The receiving date and time is after the transmitting date and time and is equal to or earlier than the time when the certificate is created.
- 5) DateOfReceiveConfirm, Reading Date and Time
- The time when the receiptor reads the electronic document after receiving the electronic document is represented.
- The reading date and time is a field that is created only in the reading certificate and is set as the time when the distribution messaging server of the receiving entity responds to the receiptor's “message detailed information request”. The time needs to be equal to a value of a TimeStamp field included in the SOAP message within the distribution linkage message responding to the receiptor by the receiving entity represented in the GeneralizedTime format.
- The reading date and time needs to be equal to or earlier than the time when the certificate is created and is equal to or later than the receiving date and time.
- 6) DistributionId, Distribution Identification Value
- An identification value for the distribution message is represented.
- An identifier of the distribution message that is the issuance object of the electronic document distribution certificate is set as it is.
- 7) NumberOfFiles, The Number of Distribution Files
- The number of electronic document files attached to the distribution message is represented.
- The number of electronic document files attached to the actual distribution message is set.
- 8) DistributedFileInfos, Distribution Document Information
- The distribution message may be attached with at least one electronic document file and sets the information on the individual files using a DistributedFile structure.
-
TABLE 16 DistributedFileInfos ::= SEQUENCE OF DistributedFile DistributedFile ::= SEQUENCE { fileHashedData HashedDataInfo, fileId [0] EXPLICIT UTF8String OPTIONAL, fileName [1] EXPLICIT UTF8String OPTIONAL } HashedDataInfo ::= SEQUENCE { hashAlg HashAlgorithm, hashedData BIT STRING } HashAlgorithm ::= AlgorithmIdentifier - 9) FileHashedData, File Hash Information
- Hash values of individual electronic document files attached to the distribution message are represented.
- The individual electronic document file is set in a hashedData field after a hash value is created using a hash algorithm of a hashAlg field.
- 10) Filed, File Identification Value
- Identifiers of individual electronic document files attached to the distribution message are represented. The file identification value is not present within the distribution message and a Content-ID value of the individual electronic document file attached to the overall distribution linkage message configured of a Multi Part message in an MIME format is set as it is.
- The field may be selectively used, but when the file name field is not used, is necessarily used and it is recommended that the file identification value field be used.
- When there are both the file identification value field and the file name field at the time of the verification of the distribution certificate, the distribution certificate is compared with the electronic document file and verified by preferentially using the file identification value field.
- 11) FileName, File Name
- The file names of the individual electronic document files attached to the distribution message are represented.
- When the file identification value field is not created, the file name field is necessarily created and as a value, the Content-ID value of the individual electronic document file attached to the overall distribution linkage message configured of the Multi Part message in the MIME format is set as it is. When the file identification value field is created, the file name field may be omitted and the value capable of auxiliarily identifying the electronic document file is set at the time of the creation of the file identification value field.
- The electronic document distribution certificate profile is as the following Table 17.
-
TABLE 17 Basic field Content Peculiar Matters version Version v9 serialNumber Serial Number Random number of 32 bytes issuer Certificate subject DN of Issuer signature certificate dateOfIssue Issuance date GeneralizedTime of certificate dateOfExpire Effect GeneralizedTime expiration date of certificate policy Certificate OID: policy 1.2.410.200032.6.1 (Transmission): 1.2.410.200032.6.2 (Reception): 1.2.410.200032.6.3 (Reading) requestInfo Certificate null request message information target Verification Use of object distributionInfos structure senderAdd Transmitter's UTF8String certified electronic address receiptorAdd Receiptor's UTF8String certified electronic address dateOfSend Transmitting GeneralizedTime, date and time necessary dateOfReceive Receiving date GeneralizedTime, and time selection dateOfReceiveConfirm Receiving GeneralizedTime, acknowledgement selection date and time distributionId Distribution UTF8String identifier numberOfFiles The number of transmission files distributedFileInfos Transmission At least one file DistributedFile information DistributedFile fileHashedData File hash value SHA256 fileId File ID One of two fields, fileName File name that is, fileId and filename is essential - Considerations associated with the electronic document distribution certificate profile are as the following {circle around (1)} to {circle around (3)}.
- {circle around (1)} At the time of electronic signature, a public key encryption algorithm uses RSA and a hash algorithm uses SHA256
- {circle around (2)} The electronic signature certificate is necessarily included in signedData
- {circle around (3)} Only one signerInfo is included in a signerInfos field.
- The distribution message transmitting entity needs to perform the verification on the certificate as soon as receiving the electronic document distribution certificate.
- The process of verifying distribution certificate is largely divided into the validity verification of the certificate and the content verification of the certificate. The validity verification of the certificate is a process of confirming whether conditions for obtaining an effect as the certificate are satisfied and the content verification of the certificate is a process of confirming the fact by comparing with the distribution message to be verified through the certificate. Therefore, the content verification of the certificate is not the verification for the certificate but may be considered to be performed to confirm whether the distribution fact is truth.
- The validity verification of the electronic document distribution certificate is performed by the processes of {circle around (1)} verifying the certificate format, {circle around (2)} visually verifying certificate, {circle around (3)} verifying the certificate electronic signature, and {circle around (4)} verifying the signature certificate and the content verification of the certificate is performed by {circle around (5)} the process of comparing and verifying the distribution message.
- {circle around (1)} Verification of Certificate Format
- The verification of the certificate format is a process of confirming whether the format of the distribution certificate to be verified observes the constraints of the structure and value defined in the present standard and the following 1) to 7) matters are basically confirmed at the time of verifying the certificate format.
- 1) Does the overall structure of the distribution certificate meet the signedData format and observe a rule on whether the lower field defined in the present standard is created?
- 2) Is the version to be set to v9?
- 3) Is the serial number created as the positive integer value by using the random number of 32 bytes?
- 4) Is the certificate issuer set by using the dirctroyName field of the GeneralName structure?
- 5) Are the issuance date of the certificate and the effect expiration date of the certificate set by using the GeneralizedTime format?
- 6) Is the certificate policy created by using the structure and values of the lower field defined in the present standard?
- 7) Is the verification object field created by using the distributionInfos field and does the verification object field observe a rule on whether the lower field according to the types of certificates proposed in the certificate policy is created?
- {circle around (2)} Certificate Visual Verification
- The certificate visual verification is a process of confirming whether the values of each visual field set in the distribution certificate are normal at the verification reference time. That is, it is confirmed that the values of each visual field set in the distribution certificate meets the rule of the following Table 18 unlike those at the verification reference time, during the present process.
-
TABLE 18 Transmitting date and time < receiving date and time ≦ reading date and time ≦ issuance date of certificate ≦ certificate verification time ≦ effect expiration date of certificate - {circle around (3)} Verification of Certificate Electronic Signature
- The verification of the electronic signature is a process of verifying the electronic signature attached to the distribution certificate for integrity guarantee and non-repudiation for the contents to be verified by the distribution certificate and follows the method for verifying an electronic signature for the signedData of a general CMS.
- {circle around (4)} Verification of Signature Certificate
- The verification of the signature certificate is a process of verifying the validity of the certificate in which the distribution certificate is electronically signed and the identity with the issuer information of the distribution certificate.
- The validity verification of the electronic signature certificate is a process that is generally included in the process of verifying the electronic signature as a part thereof and is performed by the processes of verifying an available period of the certificate, verifying the revocation, and verifying a path with the upper CA certificates, and the like. This is verified based on “technology standard [KCAC.TS.CERTVAL] of verifying authorized certificate path” of the authorized certificate system.
- If the validity verification of the electronic signature certificate succeeds, the comparison and verification with the issuer information of the distribution certificate needs to be performed. The issuer information of the distribution certificate is formed to set a subject DN value of the electronic signature certificate as it is and therefore, two values are extracted to perform the comparison and verification on whether the two values coincide with each other.
- {circle around (5)} Comparison and Verification of Distribution Message
- The process of comparing and verifying a distribution message is not a process of verifying the validity of the distribution certificate but is a process of confirming whether the distribution fact is truth by comparing and verifying the information of the distribution message included in the distribution certificate with that of the actual distribution message.
- When the transmitting entity transmits the distribution message or receives the distribution certificate after the transmission request, it is to be necessarily confirmed that the corresponding distribution certificate includes the information on the distribution message transmitted by the transmitting entity, by performing the comparison and verification of the present distribution message.
- At the time of the comparison and verification of the distribution message, the following matters are basically confirmed.
-
- Do the transmitter's certificated electronic address and the receiptor's certified electronic address correspond to the distribution message?
- Does the transmitting date and time of the reception certificate and the reading certificate coincide with a value of TimeStamp field included in the SOAP message within the “message transmission” distribution linkage message?
- Is the transmitting date and time of the transmission certificate the reasonable time for the distribution relay server to receive the “message transmission request” distribution message?
- Is the receiving date and time of the reception certificate and the reading certificate for the “message transmission” distribution message directly transmitted to the receiving entity by the transmitting entity the reasonable time for the distribution messaging server of the receiving entity to receive the “message transmission” distribution message?
- Is the receiving date and time of the reception certificate and the reading certificate for the “message transmission request” distribution message requested to the distribution relay server by the transmitting entity the reasonable time for the distribution messaging server of the receiving entity to receive the “message transmission” distribution message? (however, correspond to only to the case in which the transmitting entity can know the time when the distribution relay server transfers the distribution message to the receiving entity).
- Does the reading date and time of the reading certificate coincide with the value of the TimeStamp field included in the SOAP message within the distribution linkage message responding to the “message detailed information request” of the receiptor by the receiving entity (however, corresponding to only the case in which the transmitting entity can know the value of the corresponding TimeStamp field).
- Does the distribution identification value coincide with the identifier of the distribution message that is the issuance object of the distribution certificate?
- Is the number of distribution files equal to the number of electronic document files attached to the actual distribution message?
- Do all of the file identification values or the file names of the individual files included in the distribution document information coincide with the Content-ID values of the electronic document file attached to the actual distribution message?
- Does all of the file hash information of the individual files included in the distribution document information coincide with the values obtained by hashing the electronic document files attached to the actual distribution message?
- [Long-Term Verification Information of Electronic Signature]
- When the verification for the issued distribution certificate is completed in consideration of the importance of the distribution certificate, the distribution certificate is registered and stored in the certified electronic document authority, which provides only the long-term guarantee function for the storage time and integrity of the distribution certificate but cannot guarantee the long period of time for the validity of the electronic signature certificate of the issuance time of the distribution certificate after the available period of the electronic signature certificate expires. That is, after the valid period of the electronic signature certificate expires, the validity guarantee of the distribution certificate is not permitted. In order to solve the problem, it is possible to verify the distribution certificate even after the available period of the certificate in which the distribution certificate is electronically signed expires, by storing the verification information that can confirm that the corresponding electronic signature certificate is valid at the time when the distribution certificate is issued together with the distribution certificate.
- {circle around (1)} Acquisition of Verification Information of Electronic Signature Certificate
- The transmitting entity collects CRL and ARL and an upper CA certificate and a Root CA certificate for verifying the revocation of the electronic signature certificate and the path so as to perform the process of “5.2.4 verification of signature certificate” among the processes of verifying the validity of the received distribution certificate. It is possible to guarantee the validity of the electronic signature certificate at the time of the issuance of the distribution certificate by storing the corresponding data in the certified electronic document authority together with the distribution certificate, such that the validity of the distribution certificate is guaranteed.
- {circle around (2)} Storage of Verification Information of Electronic Signature Certificate
- The transmitting entity includes the CRL and the ARL and the upper CA certificate and the Root CA certificate that are used for verification in a certificates field and a crls field within the signedData structure of the distribution certificate after the verification for the electronic signature certificate succeeds. Precautions need to perform only the work including each information in the corresponding field regardless of an order of including each information. Since the certificates field and the crls field are not the electronic signature object information of the signedData, the verification for the distribution certificate still succeeds even after the corresponding work is performed.
-
TABLE 19 SignedData ::= SEQUENCE { version CMSVersion, digestAlgorithms DigestAlgorithmIdentifiers, encapContentInfo EncapsulatedContentInfo, certificates [0] IMPLICIT CertificateSet OPTIONAL, crls [1] IMPLICIT RevocationInfoChoices OPTIONAL, signerInfosSignerInfos } - {circle around (3)} Storage in Certificated Electronic Document Authority
- The transmitting entity stores the distribution certificate in which the verification information of the electronic signature certificate is included in the certified electronic document authority, such that the long-term verification for the distribution certificate can be performed.
Claims (17)
Applications Claiming Priority (9)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
KR20100065985 | 2010-07-08 | ||
KR10-2010-0065985 | 2010-07-08 | ||
KR10-2010-0131936 | 2010-12-21 | ||
KR10-2010-0131935 | 2010-12-21 | ||
KR20100131935A KR20120005363A (en) | 2010-07-08 | 2010-12-21 | Electronic document distribution system, and electronic document distribution method |
KR20100131936A KR20120005364A (en) | 2010-07-08 | 2010-12-21 | Electronic address, and eletronic document distribution system |
KR10-2011-0067188 | 2011-07-07 | ||
KR20110067188A KR101364612B1 (en) | 2010-07-08 | 2011-07-07 | System for circulating electronic document for creating and issuing and verifying electronic document circulation certificate |
PCT/KR2011/005039 WO2012005555A2 (en) | 2010-07-08 | 2011-07-08 | Method for creating/issuing electronic document distribution certificate, method for verifying electronic document distribution certificate, and system for distributing electronic document |
Publications (1)
Publication Number | Publication Date |
---|---|
US20130110919A1 true US20130110919A1 (en) | 2013-05-02 |
Family
ID=45611562
Family Applications (2)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US13/808,573 Abandoned US20130110919A1 (en) | 2010-07-08 | 2011-07-08 | Method for creating/issuing electronic document distribution certificate, method for verifying electronic document distribution certificate, and system for distributing electronic document |
US13/808,576 Expired - Fee Related US9143358B2 (en) | 2010-07-08 | 2011-07-08 | Electronic document communication system and electronic document communication method |
Family Applications After (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US13/808,576 Expired - Fee Related US9143358B2 (en) | 2010-07-08 | 2011-07-08 | Electronic document communication system and electronic document communication method |
Country Status (7)
Country | Link |
---|---|
US (2) | US20130110919A1 (en) |
EP (2) | EP2602758B1 (en) |
JP (3) | JP2013535858A (en) |
KR (4) | KR20120005363A (en) |
CN (2) | CN103124981B (en) |
SG (3) | SG187006A1 (en) |
WO (2) | WO2012005555A2 (en) |
Cited By (11)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20130305041A1 (en) * | 2012-05-08 | 2013-11-14 | Hagai Bar-El | Method, device, and system of secure entry and handling of passwords |
US20140082095A1 (en) * | 2012-09-17 | 2014-03-20 | Helen Y. Balinsky | Workflow monitoring |
US20170228412A1 (en) * | 2016-02-10 | 2017-08-10 | Red Hat, Inc. | Certificate based expiration of file system objects |
CN109314712A (en) * | 2016-07-01 | 2019-02-05 | 高通股份有限公司 | It is routed based on encryption Partial Blind Signature and the multi-hop secure content for being embedded in clause |
US20190289439A1 (en) * | 2016-10-04 | 2019-09-19 | Samsung Electronics Co Ltd | Method and apparatus for transmitting a mission critical data message in a communication system |
CN112651008A (en) * | 2019-10-09 | 2021-04-13 | 富士通株式会社 | Computer-readable recording medium, management apparatus and method for authentication |
EP3806005A1 (en) * | 2019-10-09 | 2021-04-14 | Fujitsu Limited | Identity verification program, control apparatus, and method for identity verification |
US11126665B1 (en) | 2017-04-18 | 2021-09-21 | Microstrategy Incorporated | Maintaining dashboard state |
CN113591439A (en) * | 2020-04-30 | 2021-11-02 | 北京字节跳动网络技术有限公司 | Information interaction method and device, electronic equipment and storage medium |
US11212363B2 (en) | 2016-02-08 | 2021-12-28 | Microstrategy Incorporated | Dossier interface and distribution |
US11706170B2 (en) | 2020-04-30 | 2023-07-18 | Beijing Bytedance Network Technology Co., Ltd. | Collaborative editing method of an electronic mail, electronic device, and storage medium |
Families Citing this family (72)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US8826375B2 (en) * | 2008-04-14 | 2014-09-02 | Lookwithus.Com Inc. | Rich media collaboration system |
US8083129B1 (en) * | 2008-08-19 | 2011-12-27 | United Services Automobile Association (Usaa) | Systems and methods for electronic document delivery, execution, and return |
KR20120005363A (en) * | 2010-07-08 | 2012-01-16 | 정보통신산업진흥원 | Electronic document distribution system, and electronic document distribution method |
SG193014A1 (en) * | 2011-09-30 | 2013-09-30 | Ranganath C Abeyweera | Method, system and apparatus for a communications client program and anassociated transfer server for onymous and secure communications |
CN103067338B (en) * | 2011-10-20 | 2017-04-19 | 上海贝尔股份有限公司 | Third party application centralized safety management method and system and corresponding communication system |
CA2796540A1 (en) * | 2011-11-28 | 2013-05-28 | Pika Technologies Inc. | Transparent bridge device |
US9367560B1 (en) * | 2011-12-14 | 2016-06-14 | Unboundid, Corp. | Method, system and apparatus for synchronizing changes in a directory service |
EP2632097A1 (en) * | 2012-02-21 | 2013-08-28 | Lleidanetworks Serveis Telemàtics S.A. | Method for certifying delivery of SMS/MMS data messages to mobile terminals |
US9736121B2 (en) * | 2012-07-16 | 2017-08-15 | Owl Cyber Defense Solutions, Llc | File manifest filter for unidirectional transfer of files |
KR101223674B1 (en) * | 2012-09-06 | 2013-01-22 | 토피도 주식회사 | E-mail client daemon system for # mail and method of sending # mail using the system |
KR20140048415A (en) * | 2012-10-12 | 2014-04-24 | 삼성전자주식회사 | Device and method for providing download service of electronic letter paper in terminal |
US9357382B2 (en) * | 2012-10-31 | 2016-05-31 | Intellisist, Inc. | Computer-implemented system and method for validating call connections |
KR102065390B1 (en) | 2013-02-15 | 2020-01-13 | 엘지이노텍 주식회사 | Light emitting device, light emitting device package, and light unit |
US8739243B1 (en) | 2013-04-18 | 2014-05-27 | Phantom Technologies, Inc. | Selectively performing man in the middle decryption |
US10776384B1 (en) | 2013-04-30 | 2020-09-15 | Ping Identity Corporation | Method, server and system for criteria-based assured replication |
US9021575B2 (en) | 2013-05-08 | 2015-04-28 | Iboss, Inc. | Selectively performing man in the middle decryption |
US9160718B2 (en) | 2013-05-23 | 2015-10-13 | Iboss, Inc. | Selectively performing man in the middle decryption |
US20140379584A1 (en) * | 2013-06-25 | 2014-12-25 | FraudFree Finance, LLC | Anti-fraud financial transaction method |
US9009461B2 (en) | 2013-08-14 | 2015-04-14 | Iboss, Inc. | Selectively performing man in the middle decryption |
KR101332607B1 (en) * | 2013-09-02 | 2013-11-25 | 서호진 | System and method of forwarding # mail and verifying the forwarded mail in official mailing system |
US9710808B2 (en) * | 2013-09-16 | 2017-07-18 | Igor V. SLEPININ | Direct digital cash system and method |
US20150135338A1 (en) | 2013-11-13 | 2015-05-14 | Fenwal, Inc. | Digital certificate with software enabling indicator |
KR101425513B1 (en) * | 2014-02-12 | 2014-08-05 | 주식회사 티모넷 | System for certificating device using hsm and applet of certification and method therefor |
US9130996B1 (en) | 2014-03-26 | 2015-09-08 | Iboss, Inc. | Network notifications |
CN103997453B (en) * | 2014-05-13 | 2018-03-30 | 北京奇虎科技有限公司 | A kind of method and apparatus to the related information processing of application |
US9673998B2 (en) * | 2014-05-15 | 2017-06-06 | Futurewei Technologies, Inc. | Differential cache for representational state transfer (REST) API |
US9906367B2 (en) * | 2014-08-05 | 2018-02-27 | Sap Se | End-to-end tamper protection in presence of cloud integration |
CN105337950B (en) * | 2014-08-14 | 2019-02-19 | 阿里巴巴集团控股有限公司 | A kind of form filling method and associated terminal |
KR102295570B1 (en) * | 2014-11-07 | 2021-08-30 | 주식회사 엘지유플러스 | Method and system for managing printout using watermark in cloud printing environment |
KR102256642B1 (en) * | 2014-12-04 | 2021-05-27 | 삼성전자주식회사 | Apparatus for transmiting and receiving message and method for transmiting and receiving message |
US20160162991A1 (en) * | 2014-12-04 | 2016-06-09 | Hartford Fire Insurance Company | System for accessing and certifying data in a client server environment |
US10079833B2 (en) * | 2015-03-30 | 2018-09-18 | Konica Minolta Laboratory U.S.A., Inc. | Digital rights management system with confirmation notification to document publisher during document protection and distribution |
KR101709197B1 (en) * | 2015-05-21 | 2017-02-22 | (주)데이터코리아 | Method and application for transceiving a confirmation of receivables based on application |
US10175977B2 (en) * | 2015-11-04 | 2019-01-08 | International Business Machines Corporation | User profile based code review |
US10839378B1 (en) * | 2016-01-12 | 2020-11-17 | 21, Inc. | Systems and methods for performing device authentication operations using cryptocurrency transactions |
US10068074B2 (en) | 2016-03-25 | 2018-09-04 | Credly, Inc. | Generation, management, and tracking of digital credentials |
US9680801B1 (en) | 2016-05-03 | 2017-06-13 | Iboss, Inc. | Selectively altering references within encrypted pages using man in the middle |
US10291604B2 (en) * | 2016-06-03 | 2019-05-14 | Docusign, Inc. | Universal access to document transaction platform |
CN106789585A (en) * | 2016-12-27 | 2017-05-31 | 沃通电子认证服务有限公司 | Can verify that Email sends the method and device of time |
CN106685979B (en) * | 2017-01-09 | 2019-05-28 | 北京信息科技大学 | Security terminal mark and authentication method and system based on STiP model |
KR101976665B1 (en) * | 2017-04-25 | 2019-08-28 | 주식회사 포시에스 | Apparatus and method for processing electronic document information using image outputting apparatus |
US11347454B2 (en) * | 2017-04-27 | 2022-05-31 | Hewlett-Packard Development Company, L.P. | Controller for a fulfilment service operation |
US11544669B2 (en) * | 2017-06-26 | 2023-01-03 | Oracle Financial Services Software Limited | Computing framework for compliance report generation |
CN107241341B (en) * | 2017-06-29 | 2020-07-07 | 北京五八信息技术有限公司 | Access control method and device |
US11487868B2 (en) * | 2017-08-01 | 2022-11-01 | Pc Matic, Inc. | System, method, and apparatus for computer security |
US20190087831A1 (en) | 2017-09-15 | 2019-03-21 | Pearson Education, Inc. | Generating digital credentials based on sensor feedback data |
KR101951270B1 (en) * | 2017-09-28 | 2019-02-22 | 주식회사 스마트솔루션 | System for sending document using messenger authentication server and method thereof |
US10803104B2 (en) | 2017-11-01 | 2020-10-13 | Pearson Education, Inc. | Digital credential field mapping |
US10607291B2 (en) * | 2017-12-08 | 2020-03-31 | Nasdaq Technology Ab | Systems and methods for electronic continuous trading of variant inventories |
US10810350B2 (en) | 2018-01-05 | 2020-10-20 | Jpmorgan Chase Bank, N.A. | System and method for aggregating legal orders |
CN108540528B (en) * | 2018-03-07 | 2021-12-17 | 胡金钱 | Method and system for confirming delivery of electronic document, and computer storage medium |
CN108804238B (en) * | 2018-03-29 | 2022-03-04 | 中国工程物理研究院计算机应用研究所 | Soft bus communication method based on remote procedure call |
CN112260995B (en) * | 2018-03-31 | 2022-05-24 | 华为云计算技术有限公司 | Access authentication method, device and server |
US10742613B2 (en) * | 2018-04-25 | 2020-08-11 | Sap Se | Pluggable framework for AS4 adapter generation |
RU2702505C1 (en) * | 2018-08-07 | 2019-10-08 | Акционерное общество Инжиниринговая компания "АСЭ" (АО ИК "АСЭ") | Electronic document management system |
CN108989055A (en) * | 2018-08-31 | 2018-12-11 | 密信技术(深圳)有限公司 | The signature and encryption method, device and storage medium of compatible files in different types |
CN109150516A (en) * | 2018-08-31 | 2019-01-04 | 密信技术(深圳)有限公司 | The signature and/or encryption method of browser file, device, browser and medium |
KR102158299B1 (en) * | 2019-01-23 | 2020-09-21 | 소프트캠프 주식회사 | System for protecting digital document based on network for business secret |
US10645197B1 (en) * | 2019-04-19 | 2020-05-05 | Clario Tech Limited | Method and a system for a secure link-up to a non-secure synchronous connection and a machine-readable carrier configured for performing the method |
CN111651196A (en) * | 2020-06-24 | 2020-09-11 | 腾讯科技(深圳)有限公司 | Document publishing method, device and server |
KR102337673B1 (en) | 2020-07-16 | 2021-12-09 | (주)휴먼스케이프 | System for verifying data access and Method thereof |
KR102337677B1 (en) | 2020-07-16 | 2021-12-09 | (주)휴먼스케이프 | System for embedding digital verification fingerprint and Method thereof |
JP2022020143A (en) * | 2020-07-20 | 2022-02-01 | 富士通株式会社 | Communication program, communication device and communication method |
TWI759908B (en) * | 2020-10-15 | 2022-04-01 | 威聯通科技股份有限公司 | The method of generating the authorization allow list and the information security system using it |
KR102261527B1 (en) | 2021-01-14 | 2021-06-08 | 성균관대학교산학협력단 | Apparatus and method of controlling torque vectoring for vehicles with inwheel motor |
US11556696B2 (en) * | 2021-03-15 | 2023-01-17 | Avaya Management L.P. | Systems and methods for processing and displaying messages in digital communications |
CN113126936B (en) * | 2021-04-23 | 2022-04-12 | 深圳市爱商在线科技有限公司 | Printing control adaptive to multiple document types |
KR102470713B1 (en) * | 2021-04-29 | 2022-11-25 | (주)소프트제국 | Method and apparatus for providing certificate distribution service based on block chain decentralized identitifier |
JP2023018431A (en) | 2021-07-27 | 2023-02-08 | 富士通株式会社 | Information processing program, information processing device, and information processing method |
KR102599089B1 (en) * | 2021-10-06 | 2023-11-03 | 효성티앤에스 주식회사 | Method and apparatus for producing of elecronic document, computer-readable storage medium and computer program |
KR102498461B1 (en) * | 2022-04-25 | 2023-02-13 | 주식회사 디엠테크컨설팅 | Integrated management method using single sign-on manufacturing information integrated management system |
KR102479174B1 (en) * | 2022-07-05 | 2022-12-20 | (주)링크허브 | System for managing secure electronic signature and method thereof |
Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US6327656B2 (en) * | 1996-07-03 | 2001-12-04 | Timestamp.Com, Inc. | Apparatus and method for electronic document certification and verification |
US20090144382A1 (en) * | 2001-01-09 | 2009-06-04 | Benninghoff Iii Charles F | Method for certifying and unifying delivery of electronic packages |
US20100250691A1 (en) * | 1999-07-28 | 2010-09-30 | Rpost International Limited | System and method for verifying delivery and integrity of electronic messages |
EP2595342A2 (en) * | 2009-11-13 | 2013-05-22 | Seiko Instruments Inc. | Long-term signature server, long-term signature terminal, and long-term signature verification server |
US8468089B1 (en) * | 1998-09-21 | 2013-06-18 | International Business Machines Corporation | Method of improving security in electronic transactions |
US20140115074A1 (en) * | 2002-11-26 | 2014-04-24 | Rpost Communications Limited | System for, and method of, providing the transmission, receipt and content of a reply to an electronic message |
Family Cites Families (34)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2887806B2 (en) * | 1989-08-18 | 1999-05-10 | 富士ゼロックス株式会社 | Network system and mail gateway |
JPH0535562A (en) * | 1991-07-31 | 1993-02-12 | Toshiba Corp | Document menaging device for information processing system |
GB2287619A (en) * | 1994-03-03 | 1995-09-20 | Ibm | Security device for data communications networks |
JPH07297822A (en) * | 1994-04-21 | 1995-11-10 | Hitachi Ltd | Message transmission system |
JPH08307448A (en) * | 1995-04-28 | 1996-11-22 | Nippon Telegr & Teleph Corp <Ntt> | Notification method for reception of electronic mail and electronic mail communication system applying the notification method |
JP3453459B2 (en) * | 1995-06-19 | 2003-10-06 | キヤノン株式会社 | E-mail system and control method thereof, and communication terminal device and control method thereof |
US6584565B1 (en) * | 1997-07-15 | 2003-06-24 | Hewlett-Packard Development Company, L.P. | Method and apparatus for long term verification of digital signatures |
JP2000183951A (en) | 1998-12-18 | 2000-06-30 | Pfu Ltd | Encipherment system and recording medium |
US7966372B1 (en) * | 1999-07-28 | 2011-06-21 | Rpost International Limited | System and method for verifying delivery and integrity of electronic messages |
US6775771B1 (en) | 1999-12-14 | 2004-08-10 | International Business Machines Corporation | Method and system for presentation and manipulation of PKCS authenticated-data objects |
GB2361081A (en) * | 2000-04-07 | 2001-10-10 | Digitalsecu Co Ltd | Apparatus and method for storing log files on a once only recordable medium |
JP2002082880A (en) * | 2000-06-28 | 2002-03-22 | Oregadare Inc | Method and system for managing message transmission and reception |
US20020059525A1 (en) * | 2000-11-10 | 2002-05-16 | Estes Timothy A. | Authenticating the contents of e-documents |
US8179555B2 (en) | 2002-03-08 | 2012-05-15 | Hewlett-Packard Development Company, L.P. | Printing and finishing capability for customized document production system and method |
JP4001047B2 (en) * | 2003-04-23 | 2007-10-31 | 村田機械株式会社 | Relay device |
JP2005108063A (en) * | 2003-10-01 | 2005-04-21 | Hitachi Ltd | Electronic local government shared server using encryption data converter, and electronic local government terminal using encryption data decoding device |
KR100579147B1 (en) | 2004-01-29 | 2006-05-12 | (주)드림투리얼리티 | A system for verifying forged electronic documents of electronic document and a method using thereof |
KR101006322B1 (en) * | 2004-04-08 | 2011-01-06 | 인터내셔널 비지네스 머신즈 코포레이션 | Method and system for linking certificates to signed files |
ATE342625T1 (en) * | 2004-08-31 | 2006-11-15 | Opportunity Solutions As | DEVICE FOR HANDLING EMAIL IN A MULTI-USER ENVIRONMENT |
KR100653512B1 (en) | 2005-09-03 | 2006-12-05 | 삼성에스디에스 주식회사 | System for managing and storaging electronic document and method for registering and using the electronic document performed by the system |
JP2007179145A (en) * | 2005-12-27 | 2007-07-12 | Brother Ind Ltd | Address information search system and address information search program |
KR100816184B1 (en) * | 2006-08-10 | 2008-03-21 | 한국전자거래진흥원 | System of electronic document repository which guarantees authenticity of the electronic document and issues certificates and method of registering, reading, issuing, transferring, a certificate issuing performed in the system |
WO2008078366A1 (en) * | 2006-12-22 | 2008-07-03 | Fujitsu Limited | Data verifying device, data verifying method, and data verifying program |
US20080168536A1 (en) * | 2007-01-10 | 2008-07-10 | Rueckwald Mark C | System and methods for reduction of unwanted electronic correspondence |
CN101017544B (en) * | 2007-02-15 | 2010-12-01 | 江苏国盾科技实业有限责任公司 | Conflated seal affix authentication method having electronic seal digital certification |
WO2008120334A1 (en) * | 2007-03-28 | 2008-10-09 | Fujitsu Limited | Certificate verification method and certificate verification apparatus |
KR100978906B1 (en) * | 2007-09-12 | 2010-08-31 | 정보통신산업진흥원 | System for managing electric filing document, and application method therefor, and the recording media storing the program performing the said method |
KR100969313B1 (en) * | 2007-09-12 | 2010-07-09 | 정보통신산업진흥원 | Method for issuing certificate of electric filing document, and system for storing certificate of electric filing document therefor, and the recording media storing the program performing the said method |
KR100932266B1 (en) * | 2007-10-12 | 2009-12-16 | 주식회사 하나은행 | How to provide electronic document relay service |
US8739292B2 (en) * | 2008-03-04 | 2014-05-27 | Apple Inc. | Trust exception management |
US8732452B2 (en) * | 2008-06-23 | 2014-05-20 | Microsoft Corporation | Secure message delivery using a trust broker |
JP2010093354A (en) * | 2008-10-03 | 2010-04-22 | Sanyo Electric Co Ltd | Communication device |
US8255685B2 (en) * | 2009-03-17 | 2012-08-28 | Research In Motion Limited | System and method for validating certificate issuance notification messages |
KR20120005363A (en) * | 2010-07-08 | 2012-01-16 | 정보통신산업진흥원 | Electronic document distribution system, and electronic document distribution method |
-
2010
- 2010-12-21 KR KR20100131935A patent/KR20120005363A/en active Search and Examination
- 2010-12-21 KR KR20100131936A patent/KR20120005364A/en active Search and Examination
-
2011
- 2011-07-07 KR KR1020110067185A patent/KR101266086B1/en active IP Right Grant
- 2011-07-07 KR KR20110067188A patent/KR101364612B1/en active IP Right Grant
- 2011-07-08 CN CN201180043451.8A patent/CN103124981B/en not_active Expired - Fee Related
- 2011-07-08 SG SG2013001870A patent/SG187006A1/en unknown
- 2011-07-08 EP EP11803832.2A patent/EP2602758B1/en not_active Not-in-force
- 2011-07-08 WO PCT/KR2011/005039 patent/WO2012005555A2/en active Application Filing
- 2011-07-08 EP EP11803841.3A patent/EP2592594B1/en not_active Not-in-force
- 2011-07-08 SG SG2013001862A patent/SG187005A1/en unknown
- 2011-07-08 US US13/808,573 patent/US20130110919A1/en not_active Abandoned
- 2011-07-08 WO PCT/KR2011/005027 patent/WO2012005546A2/en active Application Filing
- 2011-07-08 US US13/808,576 patent/US9143358B2/en not_active Expired - Fee Related
- 2011-07-08 JP JP2013518281A patent/JP2013535858A/en active Pending
- 2011-07-08 SG SG10201505317XA patent/SG10201505317XA/en unknown
- 2011-07-08 JP JP2013518282A patent/JP2013535859A/en active Pending
- 2011-07-08 CN CN201180035945.1A patent/CN103080958B/en not_active Expired - Fee Related
-
2016
- 2016-07-08 JP JP2016135934A patent/JP2016195440A/en active Pending
Patent Citations (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US6327656B2 (en) * | 1996-07-03 | 2001-12-04 | Timestamp.Com, Inc. | Apparatus and method for electronic document certification and verification |
US8468089B1 (en) * | 1998-09-21 | 2013-06-18 | International Business Machines Corporation | Method of improving security in electronic transactions |
US20100250691A1 (en) * | 1999-07-28 | 2010-09-30 | Rpost International Limited | System and method for verifying delivery and integrity of electronic messages |
US20090144382A1 (en) * | 2001-01-09 | 2009-06-04 | Benninghoff Iii Charles F | Method for certifying and unifying delivery of electronic packages |
US20140115074A1 (en) * | 2002-11-26 | 2014-04-24 | Rpost Communications Limited | System for, and method of, providing the transmission, receipt and content of a reply to an electronic message |
EP2595342A2 (en) * | 2009-11-13 | 2013-05-22 | Seiko Instruments Inc. | Long-term signature server, long-term signature terminal, and long-term signature verification server |
Cited By (19)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20130305041A1 (en) * | 2012-05-08 | 2013-11-14 | Hagai Bar-El | Method, device, and system of secure entry and handling of passwords |
US9124419B2 (en) * | 2012-05-08 | 2015-09-01 | Discretix Technologies Ltd. | Method, device, and system of secure entry and handling of passwords |
US10491379B2 (en) | 2012-05-08 | 2019-11-26 | Arm Limited | System, device, and method of secure entry and handling of passwords |
US20140082095A1 (en) * | 2012-09-17 | 2014-03-20 | Helen Y. Balinsky | Workflow monitoring |
US11212363B2 (en) | 2016-02-08 | 2021-12-28 | Microstrategy Incorporated | Dossier interface and distribution |
US20170228412A1 (en) * | 2016-02-10 | 2017-08-10 | Red Hat, Inc. | Certificate based expiration of file system objects |
US11777919B2 (en) | 2016-02-10 | 2023-10-03 | Red Hat, Inc. | Certificate based expiration of file system objects |
US10791109B2 (en) * | 2016-02-10 | 2020-09-29 | Red Hat, Inc. | Certificate based expiration of file system objects |
CN109314712A (en) * | 2016-07-01 | 2019-02-05 | 高通股份有限公司 | It is routed based on encryption Partial Blind Signature and the multi-hop secure content for being embedded in clause |
US11012826B2 (en) | 2016-10-04 | 2021-05-18 | Samsung Electronics Co., Ltd | Method and apparatus for transmitting a mission critical data message in a communication system |
US10986471B2 (en) * | 2016-10-04 | 2021-04-20 | Samsung Electronics Co., Ltd. | Method and apparatus for transmitting a mission critical data message in a communication system |
US20190289439A1 (en) * | 2016-10-04 | 2019-09-19 | Samsung Electronics Co Ltd | Method and apparatus for transmitting a mission critical data message in a communication system |
US11126665B1 (en) | 2017-04-18 | 2021-09-21 | Microstrategy Incorporated | Maintaining dashboard state |
EP3806012A1 (en) * | 2019-10-09 | 2021-04-14 | Fujitsu Limited | Identity verification purogram, management apparatus, and method for identity verification |
EP3806005A1 (en) * | 2019-10-09 | 2021-04-14 | Fujitsu Limited | Identity verification program, control apparatus, and method for identity verification |
CN112651008A (en) * | 2019-10-09 | 2021-04-13 | 富士通株式会社 | Computer-readable recording medium, management apparatus and method for authentication |
US11799653B2 (en) | 2019-10-09 | 2023-10-24 | Fujitsu Limited | Computer-readable recording medium, management apparatus, and method for identity verification |
CN113591439A (en) * | 2020-04-30 | 2021-11-02 | 北京字节跳动网络技术有限公司 | Information interaction method and device, electronic equipment and storage medium |
US11706170B2 (en) | 2020-04-30 | 2023-07-18 | Beijing Bytedance Network Technology Co., Ltd. | Collaborative editing method of an electronic mail, electronic device, and storage medium |
Also Published As
Publication number | Publication date |
---|---|
KR20120005393A (en) | 2012-01-16 |
US9143358B2 (en) | 2015-09-22 |
EP2592594B1 (en) | 2016-08-17 |
EP2592594A4 (en) | 2014-05-14 |
EP2602758B1 (en) | 2016-08-24 |
CN103080958B (en) | 2016-12-07 |
US20130117400A1 (en) | 2013-05-09 |
KR101364612B1 (en) | 2014-02-20 |
CN103080958A (en) | 2013-05-01 |
JP2013535858A (en) | 2013-09-12 |
SG187005A1 (en) | 2013-02-28 |
WO2012005546A3 (en) | 2012-05-31 |
SG187006A1 (en) | 2013-02-28 |
JP2013535859A (en) | 2013-09-12 |
CN103124981B (en) | 2016-12-07 |
EP2602758A4 (en) | 2014-01-22 |
WO2012005555A3 (en) | 2012-05-31 |
KR20120005364A (en) | 2012-01-16 |
CN103124981A (en) | 2013-05-29 |
KR20120005392A (en) | 2012-01-16 |
WO2012005555A2 (en) | 2012-01-12 |
SG10201505317XA (en) | 2015-08-28 |
EP2602758A2 (en) | 2013-06-12 |
JP2016195440A (en) | 2016-11-17 |
EP2592594A2 (en) | 2013-05-15 |
KR20120005363A (en) | 2012-01-16 |
KR101266086B1 (en) | 2013-05-27 |
WO2012005546A2 (en) | 2012-01-12 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US20130110919A1 (en) | Method for creating/issuing electronic document distribution certificate, method for verifying electronic document distribution certificate, and system for distributing electronic document | |
US6553493B1 (en) | Secure mapping and aliasing of private keys used in public key cryptography | |
CA2492986C (en) | System and method for a remote access service enabling trust and interoperability when retrieving certificate status from multiple certification authority reporting components | |
US9628281B2 (en) | Server generating basic signature data using signing target data, electronic signature value and timestamp | |
US20090006860A1 (en) | Generating multiple seals for electronic data | |
WO2012114602A1 (en) | Long-term-signature terminal, long-term-signature server, long-term-signature terminal program, and long-term-signature server program | |
US20090006842A1 (en) | Sealing Electronic Data Associated With Multiple Electronic Documents | |
US20100169218A1 (en) | Secure authentication of lectronic prescriptions | |
US7058619B2 (en) | Method, system and computer program product for facilitating digital certificate state change notification | |
CN109861996B (en) | Block chain-based relationship proving method, device, equipment and storage medium | |
US20160352523A1 (en) | Method for conversion of an original paper document into an authenticated original electronic information object | |
US20090003588A1 (en) | Counter Sealing Archives of Electronic Seals | |
KR20040078693A (en) | Method for storage and transport of an electronic certificate | |
US20090006258A1 (en) | Registration Process | |
CN103384983A (en) | Long-term-signature terminal, long-term-signature server, long-term-signature terminal program, and long-term-signature server program | |
KR20210060356A (en) | Authentication Data Feed for Smart Contract using Public Key Infrastructure | |
Pinkas et al. | Cms advanced electronic signatures (cades) | |
JP2003198539A (en) | Electronic authentication system and electronic authentication method | |
KR100760028B1 (en) | Long-term verification method and system for certificate of the electronic signature | |
CN113472814B (en) | Automatic management method for realizing IP object filing | |
WO2009101478A2 (en) | Sealing electronic data | |
CN115130147A (en) | Copyright declaration method and copyright declaration device based on block chain | |
Da Silva | DOCUMENT OWNER | |
CN112818405A (en) | Data processing method and device of block chain and readable storage medium | |
Pinkas et al. | RFC 5126: CMS Advanced Electronic Signatures (CAdES) |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
AS | Assignment |
Owner name: NATIONAL IT INDUSTRY PROMOTION AGENCY, KOREA, REPU Free format text: ASSIGNMENT OF ASSIGNORS INTEREST;ASSIGNORS:AN, DAE SEOB;LEE, JUNG GU;KONG, SEONG PIL;AND OTHERS;REEL/FRAME:029607/0580 Effective date: 20130102 |
|
AS | Assignment |
Owner name: KOREA INTERNET & SECURITY AGENCY, KOREA, REPUBLIC Free format text: ASSIGNMENT OF ASSIGNORS INTEREST;ASSIGNOR:NATIONAL IT INDUSTRY PROMOTION AGENCY;REEL/FRAME:038653/0073 Effective date: 20160516 |
|
STCB | Information on status: application discontinuation |
Free format text: ABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTION |