IP Library Granted Patent US 12,355,757
Granted Patent B2
US 12,355,757 · App. 18/541,973 · Granted Jul 8, 2025

Credential dependency encoding and verification based on other credential resources

Inventor: Ned M. Smith (Beaverton, OR)
Assignee: Intel Corporation
H04L63/0823H04L63/20H04L67/142H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,757
App. No.
18/541,973
Granted
Jul 8, 2025
Kind
B2
Abstract

Various systems and methods of establishing and providing credential dependency information in RESTful transactions are described. In an example, accessing credential resource dependencies may be performed by a credential management service (CMS) or other server, with operations including: receiving a request for a credential resource in a Representation State Transfer (RESTful) communication; identifying the credential resource which has a credential path that indicates a dependency associated with a credential; identifying dependency characteristics of the credential resource, based on the dependency; populating the credential resource to include a dependent credential, based on the dependency characteristics; and transmitting the populated credential resource in response to the request. In further examples, the credential resource and the credential path within the credential resource may be established, such as by defining paths to trust anchor entries, or dependencies to a trusted computing key of a trusted computing module that attests to trust properties.

Claims (37)

1. A device, comprising:

circuitry to provide a plurality of layers, including a first, higher-layer trusted computing security component and a second, lower-layer trusted computing security component, the lower-layer trusted computing security component operable at a lower layer relative to the higher-layer trusted computing security component, wherein the lower-layer trusted computing security component is an embedded certificate authority (ECA), and wherein the ECA is dependent on a certificate authority; and

a memory device including instructions embodied thereon, wherein the instructions, which when executed by the circuitry, configure the circuitry to:

receive a certificate signing request at the lower-layer trusted computing security component, the certificate signing request provided from the higher-layer trusted computing security component;

validate information in the certificate signing request, wherein to validate includes:

verification that a signature of the certificate signing request was created using a key issued by the lower-layer trusted computing security component; and

verification of an identifier in the certificate signing request;

issue a signed certificate in response to validating information in the certificate signing request, the signed certificate to be signed using a key of the lower-layer trusted computing security component; and

provide the signed certificate to the higher-layer trusted computing security component,

wherein the signed certificate is used by the device to verify that the lower-layer trusted computing security component has established trust in the higher-layer trusted computing security component, and

wherein the signed certificate is used by the device to sign an attribute certificate which includes attestation information that pertains to a layer-specific end-entity certificate.

2. The device of claim 1 , wherein a consumer of an ECA-issued certificate traces trust dependencies through a plurality of layers to a trust anchor.

3. The device of claim 2 , wherein the trust anchor is a manufacturer root certificate authority (CA).

4. The device of claim 1 , wherein the circuitry is implemented via a System on a Chip (SoC).

5. At least one non-transitory machine-readable medium comprising instructions that, when executed by circuitry of a device, cause the circuitry to perform operations to:

receive a certificate signing request at a first, lower-layer trusted computing security component, the certificate signing request provided from a second, higher-layer trusted computing security component, the lower-layer trusted computing security component to operate at a lower layer relative to the higher-layer trusted computing security component, wherein the lower-layer trusted computing security component is an embedded certificate authority (ECA), and wherein the ECA is dependent on a certificate authority;

validate information in the certificate signing request, wherein to validate includes:

verification that a signature of the certificate signing request was created using a key issued by the lower-layer trusted computing security component; and

verification of an identifier in the certificate signing request;

issue a signed certificate in response to validating information in the certificate signing request, the signed certificate to be signed using a key of the lower-layer trusted computing security component; and

provide the signed certificate to the higher-layer trusted computing security component;

wherein the signed certificate is used by the device to verify that the lower-layer trusted computing security component has established trust in the higher-layer trusted computing security component, and

wherein the signed certificate is used by the device to sign an attribute certificate which includes attestation information that pertains to a layer-specific end-entity certificate.

6. The at least one non-transitory machine-readable medium of claim 5 , wherein a consumer of an ECA-issued certificate traces trust dependencies through a plurality of layers to a trust anchor.

7. The at least one non-transitory machine-readable medium of claim 6 , wherein the trust anchor is a manufacturer root certificate authority (CA).

8. The at least one non-transitory machine-readable medium of claim 5 , wherein the circuitry is implemented via a System on a Chip (SoC).

9. A method performed by a device, comprising:

receiving a certificate signing request at a first, lower-layer trusted computing security component of the device, the certificate signing request provided from a second, higher-layer trusted computing security component of the device, the lower-layer trusted computing security component to operate at a lower layer relative to the higher-layer trusted computing security component, wherein the lower-layer trusted computing security component is an embedded certificate authority (ECA), and wherein the ECA is dependent on a certificate authority;

validating information in the certificate signing request, wherein the validating includes:

verifying that a signature of the certificate signing request was created using a key issued by the lower-layer trusted computing security component; and

verifying an identifier in the certificate signing request;

issuing a signed certificate in response to validating information in the certificate signing request, the signed certificate to be signed using a key of the lower-layer trusted computing security component; and

providing the signed certificate to the higher-layer trusted computing security component;

wherein the signed certificate is used by the device to verify that the lower-layer trusted computing security component has established trust in the higher-layer trusted computing security component, and

wherein the signed certificate is used by the device to sign an attribute certificate which includes attestation information that pertains to a layer-specific end-entity certificate.

10. The method of claim 9 , wherein a consumer of an ECA-issued certificate traces trust dependencies through a plurality of layers to a trust anchor.

11. The method of claim 10 , wherein the trust anchor is a manufacturer root certificate authority (CA).

Continuity (3)
Continuation 16957693
Provisional Application 62639849 · Mar 7, 2018
Related Publication 20240163274A1 · May 16, 2024
References Cited (34)
US 10277406B1 · Veladanda · 2019 [cited by examiner]
US 10764064B2 · Hennessy · 2020 [cited by examiner]
US 20040088578A1 · Chao et al. · 2004 [cited by applicant]
US 20100082975A1 · Metke et al. · 2010 [cited by applicant]
US 20130151552A1 · Sugawara et al. · 2013 [cited by applicant]
US 20130160101A1 · Hakola et al. · 2013 [cited by applicant]
US 20130246646A1 · Iliev et al. · 2013 [cited by applicant]
US 20140281502A1 · Keung Chan et al. · 2014 [cited by applicant]
US 20150381776A1 · Seed et al. · 2015 [cited by applicant]
US 20160156621A1 · Thom · 2016 [cited by examiner]
US 20160277391A1 · Choyi et al. · 2016 [cited by applicant]
US 20160306966A1 · Srivastava · 2016 [cited by examiner]
US 20160366183A1 · Smith et al. · 2016 [cited by applicant]
US 20170302459A1 · Fenner et al. · 2017 [cited by applicant]
US 20170373843A1 · Benson · 2017 [cited by examiner]
US 20180004503A1 · Olmstedthompson · 2018 [cited by applicant]
US 20180375852A1 · Thom · 2018 [cited by examiner]
US 20200366668A1 · Smith · 2020 [cited by applicant]
WO WO2019172959A1 · 2019 [cited by applicant]
Jemal H. Abawajy et al., “An Online Credential Management Service for InterGrid Computing,” 2008, pp. 101-106. (Year: 2008). [cited by examiner]
Anca-Andreea Ivan et al., “Using Views for Customizing Reusable Components in Component-Based Frameworks,” 2003, pp. 1-11. (Year: 2003). [cited by examiner]
“U.S. Appl. No. 16/957,693, Final Office Action mailed Apr. 21, 2023”, 22 pgs. [cited by applicant]
“U.S. Appl. No. 16/957,693, Non Final Office Action mailed Sep. 13, 2023”, 24 pgs. [cited by applicant]
“U.S. Appl. No. 16/957,693, Non Final Office Action mailed Sep. 16, 2022”, 18 pgs. [cited by applicant]
“U.S. Appl. No. 16/957,693, Preliminary Amendment Filed Jun. 24, 2020”, 8 pgs. [cited by applicant]
“U.S. Appl. No. 16/957,693, Response filed Jun. 28, 2023 to Final Office Action mailed Apr. 21, 2023”, 12 pgs. [cited by applicant]
“U.S. Appl. No. 16/957,693, Response filed Dec. 7, 2023 to Non Final Office Action mailed Sep. 13, 2023”, 12 pgs. [cited by applicant]
“U.S. Appl. No. 16/957,693, Response filed Dec. 16, 2022 to Non Final Office Action mailed Sep. 16, 2022”, 11 pgs. [cited by applicant]
“International Application Serial No. PCT/US2018/053456, International Preliminary Report on Patentability mailed Sep. 17, 2020”, 9 pgs. [cited by applicant]
“International Application Serial No. PCT/US2018/053456, International Search Report mailed Jan. 7, 2019”, 4 pgs. [cited by applicant]
“International Application Serial No. PCT/US2018/053456, Written Opinion mailed Jan. 7, 2019”, 7 pgs. [cited by applicant]
“U.S. Appl. No. 16/957,693, Notice of Allowance mailed Apr. 17, 2024”, 16 pgs. [cited by applicant]
Feng, Xinyang, “Research on Application of RDFa in RESTful Web Services”, (2012), 266-269. [cited by applicant]
Stroiriski, Andrzej, “RESTful Web Service Mining: simple algorithm supporting resource-oriented systems”, (2014), 694-695. [cited by applicant]