US20110296173A1

Method and apparatus for achieving nonconformant public key infrastructures

Claim Score by NHIP

Read claim 1, the broadest

Abstract

Method and apparatus are described wherein, in one example embodiment, a public key certificate issued by a certificate authority includes at least one characteristic that conforms to at least one rule established for the operation of a public key infrastructure. An attribute certificate is issued to be used to modify the public key certificate in accordance with information contained in the attribute certificate to create a modified public key certificate wherein the at least one characteristic is modified so as to be non-conformant with the at least one rule. According to one example embodiment, the attribute certificates may be distributed by a certificate authority, or embedded in an application that includes an engine that is used to modify the conforming public key certificate.

US20110296173A1, drawing sheet 1
Sheet 1 of 7

Term

0 yearsto projected expiry

Projected expiry 10 October 2026, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

21 claims: 4 independent, 17 dependent

  1. 1
    Broadest claimClaim Score 76, broad(NHIP)A method comprising:receiving a public key certificate that conforms to a rule of a public key infrastructure, the rule being applicable to process the public key certificate, the public key certificate including a compliant attribute that complies with the rule;receiving an attribute certificate issued by a certificate authority, the attribute certificate referencing the public key certificate and including a supplemental attribute usable to render the public key certificate non-conformant with the rule of the public key infrastructure;and modifying the public key certificate based on the supplemental attribute included in the attribute certificate, the modified public key certificate being non-conformant with the rule.
  2. 5
    A non-transitory machine-readable storage medium comprising instructions that, when executed by one or more processors of a machine, cause the machine to perform operations comprising:receiving a public key certificate that conforms to a rule of a public key infrastructure, the rule being applicable to process the public key certificate, the public key certificate including a compliant attribute that complies with the rule;receiving an attribute certificate issued by a certificate authority, the attribute certificate referencing the public key certificate and including a supplemental attribute usable to render the public key certificate non-conformant with the rule of the public key infrastructure;and modifying the public key certificate based on the supplemental attribute included in the attribute certificate, the modified public key certificate being non-conformant with the rule.
  3. 11
    A system comprising:a processor configured to access an attribute certificate issued by a certificate authority, the attribute certificate referencing a public key certificate that conforms to a rule of a public key infrastructure, the rule being applicable to process the public key certificate, the public key certificate including a compliant attribute that complies with the rule, the attribute certificate including a supplemental attribute usable to render the public key certificate non-conformant with the rule of the public key infrastructure;and a network interface device configured to provide the attribute certificate to another system that is configured to modify the public key certificate based on the supplemental attribute included in the attribute certificate, the modified public key certificate being non-conformant with the rule.
  4. 17
    A method comprising:receiving a public key certificate that is compatible with one or more rules established to govern an operation of a public key infrastructure, the public key certificate including a compliant attribute that complies with the one or more rules, the one or more rules being applicable to process the public key certificate;storing an attribute certificate issued by a certificate authority, the attribute certificate referencing the public key certificate and including a supplemental attribute usable to render the public key certificate non-conformant with the one or more rules;and modifying the public key certificate based on the supplemental attribute included in the attribute certificate, the modified public key certificate being non-conformant with the one or more rules.