Inventors:
Kenneth W. Aull - Fairfax VA, US
Erik J. Bowman - McLean VA, US
James B. Rekas - Arlington VA, US
Assignee:
Northrop Grumman Systems Corporation - Falls Church VA
International Classification:
G06F 21/00
US Classification:
713156, 726 8, 713157, 713168, 713171, 713175, 380285, 455111, 705 59, 709224
Abstract:
What is disclosed is a system and method that allows a secondary certificate authority to rely on one or more existing primary certificate authorities to establish identity of a user and provide identity certificates. The secondary certificate authority applies business rules to those identity certificates to establish a community of privilege, and then issues and maintains new privilege certificates without issuing new private keys or smart cards. The new privilege certificates bind the original identity, the sponsor, i. e. , the primary certificate authority, and the privilege. The new privilege certificates can be used on a Public Key Infrastructures (PKI) transaction basis, for example, to grant access to unclassified and Multi-Level Secure (MLS) resources without further reference to the existing primary certificate authorities.