Attribute Certificates for Nonconformant Public Key Infrastructure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Many public key infrastructure (PKI) systems face compatibility issues due to non-conformant public key certificates (PKCs) that lack essential attributes, requiring manual configuration to operate within standard rules, which is undesirable.
Innovation Solution
The use of Attribute Certificates (ACs) to modify non-conformant PKCs, ensuring they adhere to standard rules, thereby allowing PKI engines to process all PKCs without manual configuration, by embedding or retrieving ACs to correct non-compliant attributes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If manual configuration is used to accommodate non-conformant PKCs, then compatibility with non-standard certificates is improved, but operational complexity and time consumption increase
Solution Approach 1:
The PKI engine automatically retrieves and applies attribute certificates to non-conformant PKCs without requiring manual user configuration. The system self-services by detecting missing attributes, fetching appropriate ACs, and applying corrections autonomously, thereby maintaining compatibility while eliminating manual intervention.
Solution Approach 2:
Attribute certificates are retrieved and stored in advance before being needed for certificate validation. The system proactively obtains ACs from specified locations and caches them, so that when non-conformant PKCs are encountered, the necessary corrective attributes are already available for immediate application.
2Adaptability or versatility
If configurability options are provided for each capability, then adaptability to non-conformant PKCs is improved, but ease of operation deteriorates due to manual configuration requirements
Solution Approach 1:
The PKI engine autonomously determines which attribute certificates are needed and retrieves them without user intervention. The system self-configures by automatically identifying missing attributes in non-conformant PKCs, selecting appropriate ACs from stored collections, and applying them to enable seamless operation with diverse certificate formats.
3Reliability
If certificate chains with multiple intermediate CAs are used, then identity verification reliability is improved, but processing complexity increases
Solution Approach 1:
Attribute certificates serve as intermediary elements that bridge the gap between non-conformant PKCs and standard-compliant validation requirements. By introducing ACs as mediators, the system can verify identities in complex certificate chains without requiring manual intervention at each step, thereby maintaining reliability while simplifying processing.
Data Source
AI summary
Method and apparatus are described wherein, in one example embodiment, a public key certificate issued by a certificate authority includes at least one characteristic that conforms to at least one rule established for the operation of a public key infrastructure. An attribute certificate is issued to be used to modify the public key certificate in accordance with information contained in the attribute certificate to create a modified public key certificate wherein the at least one characteristic is modified so as to be non-conformant with the at least one rule. According to one example embodiment, the attribute certificates may be distributed by a certificate authority, or embedded in an application that includes an engine that is used to modify the conforming public key certificate.


