 |
In the NACHA Certificate Authority Interoperability
pilot we helped Bank of America deploy the
directory infrastructure necessary to support a
public key infrastructure based on the
four-corner model . We developed software to
exchange Certificate Revocation Lists (CRLs)
with other participating banks such as Citibank,
Mellon Bank and Zions Bank. As part of this
pilot we also developed software that enabled
merchants to obtain from their bank, signature
verification and certificate path validation
services that would guarantee the
non-repudiability of digitally signed customer
purchase orders. Our merchant software served as
the backend to SAIC's secure commerce
application. To support interbank online
certificate status, we developed a prototype
implementation of the Online Certificate Status
Protocol (OCSP) that allowed participating banks
to get real time status of public key
certificates. We demonstrated interoperability
of our OCSP implementation with Certco and
Verisign OCSP responders. When combined, these
software elements enabled banks, merchants, and
customers to participate in a 4-corner model of
trust.
|
 |