Attribute Certificates for Nonconformant Public Key Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Many public key infrastructure (PKI) systems face compatibility issues due to non-conformant public key certificates (PKCs) that lack essential attributes, requiring manual configuration to operate within standard rules, which is undesirable.

Innovation Solution

The use of Attribute Certificates (ACs) to modify non-conformant PKCs, ensuring they adhere to standard rules, thereby allowing PKI engines to process all PKCs without manual configuration, by embedding or retrieving ACs to correct non-compliant attributes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual configuration is used to accommodate non-conformant PKCs, then compatibility with non-standard certificates is improved, but operational complexity and time consumption increase

Engineering Contradiction:
Improvecompatibility with non-conformant PKCsVSAvoidmanual configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The PKI engine automatically retrieves and applies attribute certificates to non-conformant PKCs without requiring manual user configuration. The system self-services by detecting missing attributes, fetching appropriate ACs, and applying corrections autonomously, thereby maintaining compatibility while eliminating manual intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Attribute certificates are retrieved and stored in advance before being needed for certificate validation. The system proactively obtains ACs from specified locations and caches them, so that when non-conformant PKCs are encountered, the necessary corrective attributes are already available for immediate application.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If configurability options are provided for each capability, then adaptability to non-conformant PKCs is improved, but ease of operation deteriorates due to manual configuration requirements

Engineering Contradiction:
Improveaccommodation of non-conformant performanceVSAvoidmanual configuration burden
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The PKI engine autonomously determines which attribute certificates are needed and retrieves them without user intervention. The system self-configures by automatically identifying missing attributes in non-conformant PKCs, selecting appropriate ACs from stored collections, and applying them to enable seamless operation with diverse certificate formats.

Inventive Principle:
Principle #25Self-service

3Reliability

If certificate chains with multiple intermediate CAs are used, then identity verification reliability is improved, but processing complexity increases

Engineering Contradiction:
Improveidentity verification trustworthinessVSAvoidcertificate path validation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Attribute certificates serve as intermediary elements that bridge the gap between non-conformant PKCs and standard-compliant validation requirements. By introducing ACs as mediators, the system can verify identities in complex certificate chains without requiring manual intervention at each step, thereby maintaining reliability while simplifying processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8341400B2Method and apparatus for achieving nonconformant public key infrastructures
Publication Date: 2012.12.25 ADOBE INC
  • US8341400B2 patent drawing
  • US8341400B2 patent drawing
  • US8341400B2 patent drawing

AI summary

Method and apparatus are described wherein, in one example embodiment, a public key certificate issued by a certificate authority includes at least one characteristic that conforms to at least one rule established for the operation of a public key infrastructure. An attribute certificate is issued to be used to modify the public key certificate in accordance with information contained in the attribute certificate to create a modified public key certificate wherein the at least one characteristic is modified so as to be non-conformant with the at least one rule. According to one example embodiment, the attribute certificates may be distributed by a certificate authority, or embedded in an application that includes an engine that is used to modify the conforming public key certificate.