发明名称 METHOD AND APPARATUS FOR EXTERNAL ORGANIZATION PATH LENGTH VALIDATION WITHIN A PUBLIC KEY INFRASTRUCTURE (PKI)
摘要 A method and apparatus for external organization (EO) path length (EOPL) validation are provided. A relying party node (RPN) stores a current EO path length constraint (EOPLC) value, and an EOPL counter that maintains a count of an actual external organization path length. The RPN obtains a chain of certificates that link a subject node (SN) to its trust anchor, and processes the certificates in the chain. When a certificate has a lower EOPLC than the current EOPLC value, the RPN replaces the current EOPLC value with the lower EOPLC. When the certificate currently being evaluated includes an enabled EO flag, the RPN increments the EOPL counter by one. The EOPL validation fails when the EOPL counter is greater than the current EOPLC value, and is successful when the last remaining certificate in the chain is processed without having the EOPL counter exceed the current EOPLC value.
申请公布号 WO2010039355(A2) 申请公布日期 2010.04.08
申请号 WO2009US54757 申请日期 2009.08.24
申请人 MOTOROLA, INC.;METKE, ANTHONY, R.;EASTLAKE, DONALD, E. III 发明人 METKE, ANTHONY, R.;EASTLAKE, DONALD, E. III
分类号 H04L9/30 主分类号 H04L9/30
代理机构 代理人
主权项
地址