摘要:
A system and method are disclosed for facilitating access to a plurality of certificate-related and other services including certificate validation. A seller is provided with digital signature messaging software for accessing these services. Two preferred implementations are disclosed for integrating a seller's existing Web server and applications with this software. The first preferred implementation is referred to as 'passive integration' because it requires little or no modification to a seller's existing e-commerce Web application. In this first implementation, the seller's Web site is preferably provided with five additional components: a Web filter (302) for redirecting HTTP requests, a second Web server (220) for parsing the redirected HTTP requests, a servlet that runs applications (310) based on the requested URL, a filter engine (306) that identifies pages from a buyer that require the buyer's signature as well as pages that require access to system services, and a bank interface (222) that receives requests to access system services from the filter engine, and processes those requests. The second preferred implementation is referred to as 'active integration' because it requires the seller to rewrite code of its Web applications to provide the functionality necessary to access system services. In active integration, the seller's Web site is preferably provided with the bank interface described above but the functionality provided by the other digital signature messaging software components is instead provided by modifying directly the seller's Web application.
摘要:
A system and method for facilitating electronic commerce by securely providing certificate-related and other services including certificate validation and warranty is disclosed. Services are preferably provided in a four-corner trust model, (see figure 1). The four-corner model comprises a buyer (106) or subscribing customer, and a seller (108) or relying customer, who engage in an on-line transaction. The buyer is a customer of a first financial institution (102) or issuing participant, which is a certificate authority and issues a hardware token including a private key and a signed digital certificate. The seller is a customer of a second financial institution (104) or relying participant, which is a certificate authority and issues a hardware token including a private key and a signed digital certificate. The system also includes a root certificate authority that operates a certificate authority that issues digital certificates to the issuing and relying participants. Each participant and the root entity are preferably provided with a transaction coordinator that provides a single consistent interface for certificate-status messages and requests, as well as messages and requests relating to other services.
摘要:
A system and method for facilitating electronic commerce by securely providing certificate-related and other services including certificate validation and warranty is disclosed. Services are preferably provided in a four-corner trust model, (see figure 1). The four-corner model comprises a buyer (106) or subscribing customer, and a seller (108) or relying customer, who engage in an on-line transaction. The buyer is a customer of a first financial institution (102) or issuing participant, which is a certificate authority and issues a hardware token including a private key and a signed digital certificate. The seller is a customer of a second financial institution (104) or relying participant, which is a certificate authority and issues a hardware token including a private key and a signed digital certificate. The system also includes a root certificate authority that operates a certificate authority that issues digital certificates to the issuing and relying participants. Each participant and the root entity are preferably provided with a transaction coordinator that provides a single consistent interface for certificate-status messages and requests, as well as messages and requests relating to other services.