Patents Assigned to Certco, LLC
  • Patent number: 8032743
    Abstract: A method of managing reliance in an electronic transaction system includes a certification authority issuing a primary certificate to a subscriber and forwarding to a reliance server, information about the issued primary certificate. The reliance server maintains the forwarded information about issued primary certificate. The subscriber forms a transaction and then provides the transaction to a relying party. The transaction includes the primary certificate or a reference thereto. The relying party sends to the reliance server a request for assurance based on the transaction received from the subscriber. The reliance server determines whether to provide the requested assurance based on the information about the issued primary certificate and on the requested assurance. Based on the determining, the reliance server issues to the relying party a secondary certificate providing the assurance to the relying party.
    Type: Grant
    Filed: August 31, 2001
    Date of Patent: October 4, 2011
    Assignee: Certco, LLC
    Inventors: Alan Asay, Paul A. Turner, Frank W. Sudia, Richard Ankney
  • Patent number: 7904722
    Abstract: A system for securely using digital signatures in a commercial cryptographic system that allows industry-wide security policy and authorization information to be encoded into the signatures and certificates by employing attribute certificates to enforce policy and authorization requirements. Verification of policy and authorization requirements is enforced in the system by restricting access to public keys to users who have digitally signed and agreed to follow rules of the system. These rules can also ensure that payment is made for public and private key usage. Additionally, users can impose their own rules and policy requirements on transactions in the system.
    Type: Grant
    Filed: June 1, 2001
    Date of Patent: March 8, 2011
    Assignee: Certco, LLC
    Inventors: Frank W. Sudia, Brian Siritzky
  • Publication number: 20020029337
    Abstract: A system for securely using digital signatures in a commercial cryptographic system that allows industry-wide security policy and authorization information to be encoded into the signatures and certificates by employing attribute certificates to enforce policy and authorization requirements. Verification of policy and authorization requirements is enforced in the system by restricting access to public keys to users who have digitally signed and agreed to follow rules of the system. These rules can also ensure that payment is made for public and private key usage. Additionally, users can impose their own rules and policy requirements on transactions in the system.
    Type: Application
    Filed: June 1, 2001
    Publication date: March 7, 2002
    Applicant: Certco, LLC.
    Inventors: Frank W. Sudia, Brian Siritzky
  • Patent number: 6029150
    Abstract: A method of payment in an electronic payment system wherein a plurality of customers have accounts with an agent. A customer obtains an authenticated quote from a specific merchant, the quote including a specification of goods and a payment amount for those goods. The customer sends to the agent a single communication including a request for payment of the payment amount to the specific merchant and a unique identification of the customer. The agent issues to the customer an authenticated payment advice based only on the single communication and secret shared between the customer and the agent and status information which the agent knows about the merchant and/or the customer. The customer forwards a portion of the payment advice to the specific merchant. The specific merchant provides the goods to the customer in response to receiving the portion of the payment advice.
    Type: Grant
    Filed: October 4, 1996
    Date of Patent: February 22, 2000
    Assignee: Certco, LLC
    Inventor: David William Kravitz
  • Patent number: 6009177
    Abstract: The invention provides a cryptographic system and method with a key escrow feature that uses a method for verifiably splitting users' private encryption keys into components and for sending those components to trusted agents chosen by the particular users, and provides a system that uses modern public key certificate management, enforced by a chip device that also self-certifies. The methods for key escrow and receiving an escrow certificate are also applied herein to a more generalized case of registering a trusted device with a trusted third party and receiving authorization from that party enabling the device to communicate with other trusted devices. Further preferred embodiments provide for rekeying and upgrading of device firmware using a certificate system, and encryption of stream-oriented data.
    Type: Grant
    Filed: February 19, 1997
    Date of Patent: December 28, 1999
    Assignee: Certco LLC
    Inventor: Frank Wells Sudia
  • Patent number: 5995625
    Abstract: A method of unwrapping wrapped digital data that is unusable while wrapped, includes obtaining an acceptance phrase from a user; deriving a cryptographic key from the acceptance phrase; and unwrapping the package of digital data using the derived cryptographic key. The acceptance phrase is a phrase entered by a user in response to information provided to the user. The information and the acceptance phrase can be in any appropriate language. The digital data includes, alone or in combination, any of: software, a cryptographic key, an identifying certificate, an authorizing certificate, a data element or field of an identifying or authorizing certificate, a data file representing an images, data representing text, numbers, audio, and video.
    Type: Grant
    Filed: March 24, 1997
    Date of Patent: November 30, 1999
    Assignee: Certco, LLC
    Inventors: Frank W. Sudia, Alan Asay, Ernest F. Brickell, Richard Ankney, Peter C. Freund, Marcel M. Yung, David W. Kravitz
  • Patent number: 5903882
    Abstract: A method of managing reliance in an electronic transaction system includes a certification authority issuing a primary certificate to a subscriber and forwarding to a reliance server, information about the issued primary certificate. The reliance server maintains the forwarded information about issued primary certificate. The subscriber forms a transaction and then provides the transaction to a relying party. The transaction includes the primary certificate or a reference thereto. The relying party sends to the reliance server a request for assurance based on the transaction received from the subscriber. The reliance server determines whether to provide the requested assurance based on the information about the issued primary certificate and on the requested assurance. Based on the determining, the reliance server issues to the relying party a secondary certificate providing the assurance to the relying party.
    Type: Grant
    Filed: December 13, 1996
    Date of Patent: May 11, 1999
    Assignee: Certco, LLC
    Inventors: Alan Asay, Paul A. Turner, Frank W. Sudia, Richard Ankney
  • Patent number: 5872849
    Abstract: The invention provides a cryptographic system and method with a key escrow feature that uses a method for verifiably splitting users' private encryption keys into components and for sending those components to trusted agents chosen by the particular users, and provides a system that uses modern public key certificate management, enforced by a chip device that also self-certifies. The methods for key escrow and receiving an escrow certificate are also applied herein to a more generalized case of registering a trusted device with a trusted third party and receiving authorization from that party enabling the device to communicate with other trusted devices.
    Type: Grant
    Filed: February 19, 1997
    Date of Patent: February 16, 1999
    Assignee: CertCo LLC
    Inventor: Frank Wells Sudia
  • Patent number: 5867578
    Abstract: A multi-step digital signature system and method is provided having a distributed root certifying authority 20. Messages received at the root certifying authority 20 are distributed to root certifying authority members 22-30 who attach partial signatures to the message using root key fragments. In the system and method provided, the system adapts to system events such as the addition or removal of key fragment holders, the need to modify key fragments, etc., by changing key fragments.
    Type: Grant
    Filed: August 19, 1996
    Date of Patent: February 2, 1999
    Assignee: CertCo LLC
    Inventors: Ernest F. Brickell, Frank W. Sudia, David William Kravitz, Peter C. Freund, Patrick J. Angeles
  • Patent number: 5857022
    Abstract: The invention provides a cryptographic system and method with a key escrow feature that uses a method for verifiably splitting users' private encryption keys into components and for sending those components to trusted agents chosen by the particular users, and provides a system that uses modern public key certificate management, enforced by a chip device that also self-certifies. In a preferred embodiment of this invention, the chip encrypts or decrypts only if certain conditions are met, namely, (1) if a valid "sender certificate" and a valid "recipient certificate" are input, where "valid" means that the particular user's private decryption key is provably escrowed with a specified number of escrow agents and that the master escrow center is registered and certified by the chip manufacturer, and (2) if a valid Message Control Header is generated by the sender and validated by the recipient, thereby giving authorized investigators sufficient information with which to request and obtain the escrowed keys.
    Type: Grant
    Filed: February 19, 1997
    Date of Patent: January 5, 1999
    Assignee: CertCo LLC
    Inventor: Frank Wells Sudia
  • Patent number: 5850451
    Abstract: The invention provides a cryptographic system and method with a key escrow feature that uses a method for verifiably splitting users' private encryption keys into components and for sending those components to trusted agents chosen by the particular users, and provides a system that uses modern public key certificate management, enforced by a chip device that also self-certifies. In a preferred embodiment of this invention, the chip encrypts or decrypts only if certain conditions are met, namely, (1) if a valid "sender certificate" and a valid "recipient certificate" are input, where "valid" means that the particular user's private decryption key is provably escrowed with a specified number of escrow agents and that the master escrow center is registered and certified by the chip manufacturer, and (2) if a valid Message Control Header is generated by the sender and validated by the recipient, thereby giving authorized investigators sufficient information with which to request and obtain the escrowed keys.
    Type: Grant
    Filed: February 19, 1997
    Date of Patent: December 15, 1998
    Assignee: CertCo LLC
    Inventor: Frank Wells Sudia
  • Patent number: 5841865
    Abstract: The invention provides a cryptographic system and method with a key escrow feature that uses a method for verifiably splitting users' private keys into components and for sending those components to trusted agents chosen by the particular users, and provides a system that uses a modern public key certificate management, enforced by a chip device that also self-certifies. A preferred embodiment of this invention provides a method for generating verifiably trusted communications among a plurality of users, comprising the steps of escrowing at a trusted escrow center a plurality of asymmetric cryptographic keys to be used by a plurality of users; verifying each of said plurality of keys at the escrow center; certifying the authorization of each of said plurality of keys upon verification; and initiating a communication from each of said plurality of users using a respective one of said plurality of keys contingent upon certification.
    Type: Grant
    Filed: April 11, 1997
    Date of Patent: November 24, 1998
    Assignee: CertCo LLC
    Inventor: Frank Wells Sudia
  • Patent number: 5799086
    Abstract: A cryptographic system with key escrow feature that uses a method for verifiably splitting user's private encryption keys into components and for sending those components to trusted agents chosen by the particular users is provided. The system uses public key certificate management, enforced by a chip device that also self-certifies. The methods for key escrow and receiving an escrow certificate are applied to register a trusted device with a trusted third party and to receive authorization from that party enabling the device to communicate with other trusted devices. The methods for key escrow also provide assurance that a trusted device will engage in electronic transactions in accordance with predetermined rules.
    Type: Grant
    Filed: February 19, 1997
    Date of Patent: August 25, 1998
    Assignee: CertCo LLC
    Inventor: Frank Wells Sudia
  • Patent number: 5659616
    Abstract: A system for securely using digital signatures in a commercial cryptographic system that allows industry-wide security policy and authorization information to be encoded into the signatures and certificates by employing attribute certificates to enforce policy and authorization requirements. In addition to value limits, cosignature requirements and document type restrictions that can be placed on transactions, an organization can enforce with respect to any transaction geographical and temporal controls, age-of-signature limitations, preapproved counterparty limitations and confirm-to requirements by using attribute certificates for the transacting user. Restrictions on distribution of certificates can be set using attribute certificates. Certificates can be used also to ensure key confinement and non-decryption requirements of smartcards in this system.
    Type: Grant
    Filed: July 16, 1996
    Date of Patent: August 19, 1997
    Assignee: Certco, LLC
    Inventor: Frank Wells Sudia
  • Patent number: RE36918
    Abstract: A method, using a public-key cryptosystem, for enabling a predetermined entity to monitor communications of users .[.suspected of unlawful activities while protecting the privacy of law-abiding users.]., wherein each user is assigned a pair of matching secret and public keys. According to the method, each user's secret key is broken into shares. Then, each user provides a plurality of "trustees" pieces of information. The pieces of information provided to each trustee enable that trustee to verify that such information includes a "share" of a secret key of some given public key. Each trustee can verify that the pieces of information provided include a share of the secret key without interaction with any other trustee or by sending messages to the user. Upon a predetermined request or condition, e.g., a court order authorizing the entity to monitor the communications of a user .[.suspected of unlawful activity.]., the trustees reveal to the entity the shares of the secret key of such user.
    Type: Grant
    Filed: September 12, 1995
    Date of Patent: October 17, 2000
    Assignee: CertCo LLC
    Inventor: Silvio Micali