A system and method for issuing a cryptographic certificate includes describing one or more prerequisite condition on the cryptographic certificate. The one or more prerequisite conditions comprise membership in one or more prerequisite group of entities. An entity may be a participant, a resource or a privilege, etc. The present invention also requires naming one or more target groups of entities on the cryptographic certificate. One or more prerequisite group stakeholder that authorizes an entity in the one or more prerequisite group of entities to be added as members in another group of entities sign the cryptographic certificate. The cryptographic certificate is also signed by one or more target group stakeholders that authorizes an entity to be added as a member of the one or more target groups. Exemplary prerequisite conditions relate to one or more of a membership in another group of entities, a physical characteristic, a temporal characteristic, a location characteristic or a position characteristic, among others.
System And Method For Accessing Information Resources Using Cryptographic Authorization Permits
Reynolds Wiliam Beckwith - Great Falls VA, US Jeffrey Grant Marshall - Herndon VA, US Jeffrey William Chilton - Reston VA, US
Assignee:
Objective Interface Systems, Inc. - Herndon VA
International Classification:
H04L 9/32 G06F 21/00
US Classification:
713167, 726 17, 713189
Abstract:
A system and method for securing information associates a party with a node that communicates messages over one or more channels based on a channel access privilege. One or more authorities sign a cryptographic authorization permit (CAP) to authorize the channel access privilege, which can be a write privilege or a read privilege. In one embodiment, the authorization for the channel access privilege is based on a public key issued by an authority and the CAP comprises a cryptographic certificate digitally signed by the authority.
Reynolds William Beckwith - Great Falls VA, US Jeffrey William Chilton - Reston VA, US Jeffrey Grant Marshall - Leesburg VA, US
Assignee:
Objective Interface Systems, Inc. - Herndon VA
International Classification:
H04L 12/26
US Classification:
3702301
Abstract:
A system and method for communicating data between two nodes defines a plurality of separate partitions on each node and assigns one or more subjects to at least one of the plurality of the separate partitions. The subjects in each node communicate data with each other over one or more channels. For communicating the data, the present invention separates data communications on a channel from that of other channels. More specifically, each node runs under the control of a separation kernel (SK) that partitions the nodes to define the subjects according to an SK configuration data. A partitioning communication system (PCS) separates the communications channels according to a PCS configuration data.
Reynolds Beckwith - Great Falls VA, US Jeffrey Chilton - Reston VA, US Jeffrey Marshall - Leesburg VA, US
Assignee:
Objective Interface Systems, Inc. - Herndon VA
International Classification:
H04L 12/28
US Classification:
370351000
Abstract:
A system and method for communicating data between two nodes defines a plurality of separate partitions on each node and assigns one or more subjects to at least one of the plurality of the separate partitions. The subjects in each node communicate data with each other over one or more channels. For communicating the data, the present invention separates data communications on a channel from that of other channels. More specifically, each node runs under the control of a separation kernel (SK) that partitions the nodes to define the subjects according to an SK configuration data. A partitioning communication system (PCS) separates the communications channels according to a PCS configuration data.
Reynolds William Beckwith - Great Falls VA, US Jeffrey William Chilton - Reston VA, US Jeffrey Grant Marshall - Leesburg VA, US
Assignee:
Objective Interface Systems, Inc. - Herndon VA
International Classification:
G06F 15/16
US Classification:
709217
Abstract:
A system and method for communicating data between two nodes defines a plurality of separate partitions on each node and assigns one or more subjects to at least one of the plurality of the separate partitions. The subjects in each node communicate data with each other over one or more channels. For communicating the data, the present invention separates data communications on a channel from that of other channels. More specifically, each node runs under the control of a separation kernel (SK) that partitions the nodes to define the subjects according to an SK configuration data. A partitioning communication system (PCS) separates the communications channels according to a PCS configuration data.
System And Method For Accessing Information Resources Using Cryptographic Authorization Permits
Reynolds William Beckwith - Great Falls VA, US Jeffrey Grant Marshall - Herndon VA, US Jeffrey William Chilton - Reston VA, US
Assignee:
Objective Interface Systems, Inc. - Herndon VA
International Classification:
H04L 9/32
US Classification:
713167
Abstract:
A system and method for securing information associates a party with a node that communicates messages over one or more channels based on a channel access privilege. One or more authorities sign a cryptographic authorization permit (CAP) to authorize the channel access privilege, which can be a write privilege or a read privilege. In one embodiment, the authorization for the channel access privilege is based on a public key issued by an authority and the CAP comprises a cryptographic certificate digitally signed by the authority.