IP Library Granted Patent US 12,069,040
Granted Patent B2
US 12,069,040 · App. 16/957,693 · Granted Aug 20, 2024

Credential dependency encoding and verification based on other credential resources

Inventor: Ned M. Smith (Beaverton, OR)
Assignee: Intel Corporation
H04L63/0823H04L63/20H04L67/142H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,069,040
App. No.
16/957,693
Granted
Aug 20, 2024
Kind
B2
Abstract

Various systems and methods of establishing and providing credential dependency information in RESTful transactions are described. In an example, accessing credential resource dependencies may be performed by a credential management service (CMS) or other server, with operations including: receiving a request for a credential resource in a Representation State Transfer (RESTful) communication; identifying the credential resource which has a credential path that indicates a dependency associated with a credential; identifying dependency characteristics of the credential resource, based on the dependency; populating the credential resource to include a dependent credential, based on the dependency characteristics; and transmitting the populated credential resource in response to the request. In further examples, the credential resource and the credential path within the credential resource may be established, such as by defining paths to trust anchor entries, or dependencies to a trusted computing key of a trusted computing module that attests to trust properties.

Claims (51)

1. A device, comprising:

processing circuitry; and

a memory device including instructions embodied thereon, wherein the instructions, which when executed by the processing circuitry, configure the processing circuitry to perform operations comprising:

receiving a request for a credential resource;

identifying the credential resource stored at a first location, the credential resource comprising data that includes at least one authentication credential and a credential path that indicates a dependency to an entity at a second location associated with the at least one authentication credential, wherein the credential path links to at least one dependent authentication credential at the second location, and wherein the respective authentication credentials comprise a key or a certificate used to attest to one or more trust properties;

identifying dependency characteristics of the credential resource, based on the dependency indicated in the credential path;

retrieving the at least one dependent authentication credential from the second location indicated in the credential path, wherein the at least one dependent authentication credential is retrieved based on a type of the dependency and at least one trust anchor specified by the credential path;

populating the credential resource to include data from the at least one dependent authentication credential, wherein the at least one dependent authentication credential is populated in the credential resource based on the dependency characteristics including a use and format of the at least one dependent authentication credential; and

transmitting the populated credential resource in response to the request; wherein the credential resource includes an end-entity key, and wherein the dependency indicated in the credential path is linked to a trusted computing key of a trusted computing module that attests to trust properties of the end-entity key.

2. The device of claim 1 , wherein the operations of identifying the dependency characteristics of the credential resource include:

identifying a plurality of credential dependencies indicated in the credential path;

wherein the credential path includes references to respective authentication credentials of the plurality of credential dependencies.

3. The device of claim 1 , wherein the at least one authentication credential comprises at least one certificate, and wherein the dependency characteristics are produced based on an end-entity credential depending on a sub-certificate authority credential and the sub-certificate authority credential depending on a root-certificate authority credential.

4. The device of claim 1 , wherein the request for the credential resource includes a query for the credential path, and wherein the at least one dependent authentication credential populated in the credential resource is selected based on the query.

5. The device of claim 1 , wherein the dependency characteristics include reason properties for respective dependent authentication credentials, and wherein the reason properties indicate the use and format of the respective dependent authentication credentials.

6. The device of claim 1 , wherein the credential resource includes an array including a plurality of credential entries, and wherein the plurality of credential entries are linked to a plurality of credentials identified in the credential path.

7. The device of claim 1 , wherein the credential resource is a collection resource that includes an array of credential resource links, and wherein the respective credential resource links are linked to a plurality of credentials identified in the credential path.

8. The device of claim 1 , the operations further comprising:

establishing the credential resource, including establishing credential properties and establishing the credential path within the credential resource, wherein the credential path includes one or more paths defined for each of the credential properties.

9. The device of claim 8 , wherein the operations of establishing the credential path include identifying multiple link dependencies to respective trust anchor entries, and wherein the one or more paths define the multiple link dependencies to the respective trust anchor entries.

10. The device of claim 1 , wherein the operations are performed as operations of a Credential Management Service (CMS), and wherein the CMS operates according to an Open Connectivity Foundation (OCF) specification.

11. A method for accessing credential resource dependencies using operations performed by a device comprising:

receiving a request for a credential resource;

identifying the credential resource stored at a first location, the credential resource comprising data that includes at least one authentication credential and a credential path that indicates a dependency to an entity at a second location associated with the at least one authentication credential, wherein the credential path links to at least one dependent credential at the second location, and wherein the respective authentication credentials comprise a key or a certificate used to attest to one or more trust properties;

identifying dependency characteristics of the credential resource, based on the dependency indicated in the credential path;

retrieving the at least one dependent authentication credential from the second location indicated in the credential path, wherein the at least one dependent authentication credential is retrieved based on a type of the dependency and at least one trust anchor specified by the credential path;

populating the credential resource to include data from the at least one dependent authentication credential, wherein the at least one dependent authentication credential is populated in the credential resource based on the dependency characteristics including a use and format of the at least one dependent authentication credential; and

transmitting the populated credential resource in response to the request; wherein the credential resource includes an end-entity key, and wherein the dependency indicated in the credential path is linked to a trusted computing key of a trusted computing module that attests to trust properties of the end-entity key.

12. The method of claim 11 , wherein the operations of identifying the dependency characteristics of the credential resource include:

identifying a plurality of credential dependencies indicated in the credential path;

wherein the credential path includes references to respective authentication credentials of the plurality of credential dependencies.

13. The method of claim 11 , wherein the at least one authentication credential comprises at least one certificate, and wherein the dependency characteristics are produced based on an end-entity credential depending on a sub-certificate authority credential and the sub-certificate authority credential depending on a root-certificate authority credential.

14. The method of claim 11 , wherein the request for the credential resource includes a query for the credential path, and wherein the at least one dependent authentication credential populated in the credential resource is selected based on the query.

15. The method of claim 11 , wherein the dependency characteristics include reason properties for respective dependent authentication credentials, and wherein the reason properties indicate the use and format of the respective dependent authentication credentials.

16. The method of claim 11 , wherein the credential resource includes an array including a plurality of credential entries, and wherein the plurality of credential entries are linked to a plurality of credentials identified in the credential path.

17. The method of claim 11 , wherein the credential resource is a collection resource that includes an array of credential resource links, and wherein the respective credential resource links are linked to a plurality of credential identified in the credential path.

18. The method of claim 11 , the operations further comprising:

establishing the credential resource, including establishing credential properties and establishing the credential path within the credential resource, wherein the credential path includes one or more paths defined for each of the credential properties.

19. The method of claim 18 , wherein the operations of establishing the credential path include identifying multiple link dependencies to trust anchor entries, wherein the one or more paths define the multiple link dependencies to the trust anchor entries.

20. The method of claim 11 , wherein the operations are performed as operations of a Credential Management Service (CMS), and wherein the CMS operates according to an Open Connectivity Foundation (OCF) specification.

21. At least one non-transitory machine-readable storage medium including instructions, wherein the instructions, when executed by a processing circuitry of a device, cause the processing circuitry to perform operations comprising:

receiving a request for a credential resource;

identifying the credential resource stored at a first location, the credential resource comprising data that includes at least one authentication credential and a credential path that indicates a dependency to an entity at a second location associated with the at least one authentication credential, wherein the credential path links to at least one dependent credential at the second location, and wherein the respective authentication credentials comprise a key or a certificate used to attest to one or more trust properties;

identifying dependency characteristics of the credential resource, based on the dependency indicated in the credential path;

retrieving the at least one dependent authentication credential from the second location indicated in the credential path, wherein the at least one dependent authentication credential is retrieved based on a type of the dependency and at least one trust anchor specified by the credential path;

populating the credential resource to include data from the at least one dependent authentication credential, wherein the at least one dependent authentication credential is populated in the credential resource based on the dependency characteristics including a use and format of the at least one dependent authentication credential; and

transmitting the populated credential resource in response to the request; wherein the credential resource includes an end-entity key, and wherein the dependency indicated in the credential path is linked to a trusted computing key of a trusted computing module that attests to trust properties of the end-entity key.

22. The machine-readable storage medium of claim 21 , the operations further comprising:

identifying a plurality of credential dependencies indicated in the credential path;

wherein the credential path includes references to respective authentication credentials of the plurality of credential dependencies.

23. The machine-readable storage medium of claim 21 , wherein the device is operable for executing the operations as a function of a Credential Management Service (CMS), and wherein the CMS operates according to an Open Connectivity Foundation (OCF) specification.

Continuity (2)
Provisional Application 62639849 · Mar 7, 2018
Related Publication 20200366668A1 · Nov 19, 2020
Cited By (1)
US 12,526,318