Abstract

A relying party that authenticates devices in the field ordinarily receives a full certificate chain and verifies a signature at each link up to a trusted root certificate.  Alternatively, individual certificate records from the chain may be preserved by the issuer, which may be queried by a relying party on each request.  The first approach consumes bandwidth and processor time, and the second adds latency and storage.  To address these deficiencies, this disclosure describes a certificate validation system that carries an encrypted token in the subject name of an intermediate certificate issued to a device.  A leaf certificate generated on the device inherits the token in the issuer name field.  A relying party can therefore decrypt the token, recover the device mapping and the issuer public key, verify the leaf signature, and authenticate the device from the leaf certificate alone.

Creative Commons License

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.

Share

COinS