Revocation status using other credentials
First Claim
1. A method of providing revocation status of at least one associated credential stored on a first device, the method comprising:
- providing information about a primary credential stored on a second device separate from the first device, the primary credential being cryptographically independent of the at least one associated credential, in that there is no secret associated with one of the primary credential and the at least one associated credential that is used to form a cryptogram that is necessary to establish trust in the other of the primary credential and the at least one associated credential;
binding the at least one associated credential to the primary credential; and
based on revocation of the primary credential, causing the at least one associated credential to also be deemed revoked.
2 Assignments
0 Petitions
Accused Products
Abstract
Providing revocation status of at least one associated credential includes providing a primary credential that is at least initially independent of the associated credential, binding the at least one associated credential to the primary credential, and deeming the at least one associated credential to be revoked if the primary credential is revoked. Providing revocation status of at least one associated credential may also include deeming the at least one associated credential to be not revoked if the primary credential is not revoked. Binding may be independent of the contents of the credentials and may be independent of whether any of the credentials authenticate any other ones of the credentials. The at least one associated credential may be provided on an integrated circuit card (ICC). The ICC may be part of a mobile phone or a smart card.
35 Citations
20 Claims
-
1. A method of providing revocation status of at least one associated credential stored on a first device, the method comprising:
-
providing information about a primary credential stored on a second device separate from the first device, the primary credential being cryptographically independent of the at least one associated credential, in that there is no secret associated with one of the primary credential and the at least one associated credential that is used to form a cryptogram that is necessary to establish trust in the other of the primary credential and the at least one associated credential; binding the at least one associated credential to the primary credential; and based on revocation of the primary credential, causing the at least one associated credential to also be deemed revoked. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8)
-
-
9. A method of providing revocation status of at least one associated credential of a plurality of associated credentials, the method comprising:
-
providing information about a primary credential that is cryptographically independent of the at least one associated credential, in that there is no secret associated with one of the primary credential and the at least one associated credential that is used to form a cryptogram that is necessary to establish trust in the other of the primary credential and the at least one associated credential; binding the plurality of associated credentials to the primary credential; and based on revocation of the primary credential, causing the at least one associated credential to also be deemed revoked; wherein revocation statuses of the plurality of associated credentials collectively vary according to revocation status of the primary credential. - View Dependent Claims (10, 11, 12, 13, 14)
-
-
15. A method of providing revocation status of at least one associated credential, the method comprising:
-
providing information about a primary credential that is cryptographically independent of the associated credential, in that there is no secret associated with one of the primary credential and the at least one associated credential that is used to form a cryptogram that is necessary to establish trust in the other of the primary credential and the at least one associated credential; binding the at least one associated credential to the primary credential; authenticating the primary credential; and based on revocation of the primary credential, causing the at least one associated credential to also be deemed revoked. - View Dependent Claims (16, 17, 18, 19, 20)
-
Specification