05164988 is referenced by 195 patents and cites 17 patents.

Device A in a public key cryptographic network will be constrained to continue to faithfully practice a security policy dictated by a network certification center, long after device A's public key PUMa has been certified. If device A alters its operations from the limits encoded in its configuration vector, for example by loading a new configuration vector, device A will be denied participation in the network. To accomplish this enforcement of the network security policy dictated by the certification center, it is necessary for the certification center to verify at the time device A requests certification of its public key PUMa, that device A is configured with the currently authorized configuration vector. Device A is required to transmit to the certification center a copy of device A's current configuration vector, in an audit record. the certification center then compares device A's copy of the configuration vector with the authorized configuration vector for device A stored at the certification center. If the comparison is satisfactory, then the certification center will issue the requested certificate and will produce a digital signiture dSigPRC on a representation of device A's public key PUMa, using the certification center's private certification key PRC. Thereafter, if device A attempts to change its configuration vector, device A's privacy key PRMa corresponding to the certified public key PUMa, will automatically become unavailable for use in communicating in the network.

Title
Method to establish and enforce a network cryptographic security policy in a public key cryptosystem
Application Number
7/786227
Publication Number
5164988
Application Date
October 31, 1991
Publication Date
November 17, 1992
Inventor
John D Wilkins
Somerville
VA, US
William S Rohland
Charlotte
NC, US
William C Martin
Concord
NC, US
Rostislaw Prymak
Dumfries
VA, US
An V Le
Manassas
VA, US
Donald B Johnson
Manassas
VA, US
Stephen M Matyas
Manassas
VA, US
Agent
John E Hoel
Assignee
International Business Machines Corporation
NY, US
IPC
H04K 1/00
View Original Source