Abstract
A relying party that authenticates devices in the field ordinarily receives a full certificate chain and verifies a signature at each link up to a trusted root certificate. Alternatively, individual certificate records from the chain may be preserved by the issuer, which may be queried by a relying party on each request. The first approach consumes bandwidth and processor time, and the second adds latency and storage. To address these deficiencies, this disclosure describes a certificate validation system that carries an encrypted token in the subject name of an intermediate certificate issued to a device. A leaf certificate generated on the device inherits the token in the issuer name field. A relying party can therefore decrypt the token, recover the device mapping and the issuer public key, verify the leaf signature, and authenticate the device from the leaf certificate alone.
Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 License.
Recommended Citation
Belsare, Aditya Sanjay and Gaur, Vikram, "Leaf Certificate Validation for High-Volume Services Using an Encrypted Device Mapping Token Carried in the Certificate Issuer Name", Technical Disclosure Commons, ()
https://www.tdcommons.org/dpubs_series/12053