Untitled record
Abstract
The invention relates to a method for the anonymized storage of digital data, in the form of a data record (3), wherein the data record (3) is signed by a first data processing system with a secret key to a digital signature (4) of the data set (3) create, the first data processing system transmits the record (3) with its digital signature (4) to a second data processing system, which stores the record (3) and its digital signature (4) at any location, the second data processing system a reference via which the second data processing system can retrieve the data record (3) with the digital signature (4), sends it to the first data processing system.

Term
No projected expiry on record.
- Priority and filed
- Granted
- Today
10 claims: 10 independent, 0 dependent
- 1Verfahren zum anonymisierten Speichern von digitalen Daten, in Form eines Datensatzes (3), dadurch gekennzeichnet, dass der Datensatz (3) durch eine erste Datenverarbeitungsanlage mit einem geheimen Schlüssel signiert wird, um eine digitale Signatur (4) des Datensatzes (3) zu erstellen, die erste Datenverarbeitungsanlage den Datensatz (3) mit dessen digitalen Signatur (4) an eine zweite Datenverarbeitungsanlage überträgt, welche den Datensatz (3) und dessen digitale Signatur (4) an einem beliebigen Speicherort speichert, die zweite Datenverarbeitungsanlage einen Verweis, über welchen die zweite Datenverarbeitungsanlage den Datensatz (3) mit der digitalen Signatur (4) wieder auffinden kann, an die erste Datenverarbeitungsanlage sendet. claims 1. Method for anonymously storing digital data, in the form of a data record (3), characterized, that the data record (3) is signed by a first data processing system with a secret key, to create a digital signature (4) of the data set (3), the first data processing system transmits the data record (3) with its digital signature (4) to a second data processing system, which stores the data record (3) and its digital signature (4) at any storage location, the second data processing system a reference, via which the second data processing system can retrieve the data record (3) with the digital signature (4), sends to the first data processing system.
- 2Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass eine beliebige Datenverarbeitungsanlage einen Verweis und eine digitale Signatur (4) an die zweite Datenverarbeitungsanlage übermittelt, die zweite Datenverarbeitungsanlage die am Ziel des Verweises gespeicherte digitale Signatur (4) mit der übermittelten digitalen Signatur (4) vergleicht, und die zweite Datenverarbeitungsanlage den am Ziel des Verweises gespeicherten Datensatz (3) an die beliebige Datenverarbeitungsanlage übermittelt, wenn die beiden digitalen Signaturen (4) ident sind. Second Method according to claim 1, characterized, that any data processing system transmits a reference and a digital signature (4) to the second data processing system, the second data processing system compares the digital signature (4) stored at the destination of the link with the transmitted digital signature (4), and the second data processing system transmits the data record (3) stored at the destination of the link to the arbitrary data processing system, if the two digital signatures (4) are identical.
- 3Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass eine beliebige Datenverarbeitungsanlage einen Verweis, eine digitale Signatur (4) und einen geänderten Datensatz (3.1) an die zweite Datenverarbeitungsanlage übermittelt, die zweite Datenverarbeitungsanlage die am Ziel des Verweises gespeicherte digitale Signatur (4) und mit der übermittelten digitalen Signatur (4) vergleicht, die zweite Datenverarbeitungsanlage den am Ziel des Verweises gespeicherten Datensatz (3) durch den geänderten Datensatz (3.1) ersetzt, wenn die beiden digitalen Signaturen (4) ident sind. Third Method according to claim 1, characterized, that any data processing system has a reference, transmits a digital signature (4) and a modified data record (3.1) to the second data processing system, the second data processing system compares the digital signature (4) stored at the destination of the link and with the transmitted digital signature (4), the second data processing system replaces the data record (3) stored at the destination of the link with the modified data record (3.1), if the two digital signatures (4) are identical.
- 4Verfahren nach Anspruch 3, dadurch gekennzeichnet, dass die beliebige Datenverarbeitungsanlage zudem die neue digitale Signatur (4.1) des geänderten Datensatzes (3.1) an die zweite Datenverarbeitungsanlage sendet und die zweite Datenverarbeitungsanlage die gespeicherte digitale Signatur (4) durch die neue digitale Signatur (4.1) ersetzt, wenn die beiden digitalen Signaturen (4) ident sind. 4th A method according to claim 3, characterized in that the arbitrary data processing system also sends the new digital signature (4.1) of the changed data set (3.1) to the second data processing system and the second data processing system the stored digital signature (4) by the new digital signature (4.1) replaced if the two digital signatures (4) are identical.
- 5Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass der geheime Schlüssel der private Schlüssel eines asymmetrischen Schlüsselpaars ist, die erste Datenverarbeitungsanlage zusätzlich zum Datensatz (3) und dessen digitaler Signatur (4) auch den öffentlichen Schlüssel (6) an die zweite Datenverarbeitungsanlage übermittelt, und die zweite Datenverarbeitungsanlage auch den öffentlichen Schlüssel (6) unter dem Verweis an einem beliebigen Speicherort speichert. 5th Method according to Claim 1, characterized in that the secret key is the private key of an asymmetrical key pair, the first data processing system transmits the public key (6) to the second data processing system in addition to the data record (3) and its digital signature (4), and the second data processing system also stores the public key (6) with the reference at any storage location.
- 6Verfahren nach Anspruch 5, dadurch gekennzeichnet, dass eine beliebige Datenverarbeitungsanlage den Verweis und die digitale Signatur (4) an die zweite Datenverarbeitungsanlage übermittelt, die zweite Datenverarbeitungsanlage die am Ziel des Verweises gespeicherte digitale Signatur (4) mit der übermittelten digitalen Signatur (4) vergleicht und die zweite Datenverarbeitungsanlage den am Ziel des Verweises gespeicherten Datensatz (3) an die beliebige Datenverarbeitungsanlage übermittelt, wenn die beiden digitalen Signaturen (4) ident sind. 6th Method according to claim 5, characterized, that any data processing system transmits the reference and the digital signature (4) to the second data processing system, the second data processing system compares the digital signature (4) stored at the destination of the reference with the transmitted digital signature (4) and the second data processing system transmits the data set (3) stored at the destination of the link to the arbitrary data processing system, if the two digital signatures (4) are identical. 9/16 9/16 AT 517 151 B1 2017-11-15 österreichhches AT 517 151 B1 2017-11-15 Austriahches Patentamt Patent Office
- 7Verfahren nach Anspruch 5, dadurch gekennzeichnet, dass eine beliebige Datenverarbeitungsanlage einen Verweis, einen geänderten Datensatz (3.1) und die neue digitale Signatur (4.1) des geänderten Datensatzes (3.1) an die zweite Datenverarbeitungsanlage übermittelt, die zweite Datenverarbeitungsanlage mithilfe des am Ziel des Verweises gespeicherten öffentlichen Schlüssels (6) überprüft, ob die neue digitale Signatur (4.1) des geänderten Datensatz (3.1) mit dem privaten Schlüssel erstellt wurde, die zweite Datenverarbeitungsanlage den am Ziel des Verweises gespeicherten Datensatz (3) durch den geänderten Datensatz (3.1) ersetzt, wenn die Überprüfung erfolgreich ist. 7th Method according to claim 5, characterized, that any data processing system has a reference, transmits a changed data record (3.1) and the new digital signature (4.1) of the changed data record (3.1) to the second data processing system, checks the second data processing system using the public key (6) stored at the destination of the link, whether the new digital signature (4.1) of the changed data record (3.1) was created with the private key, the second data processing system replaces the data record (3) stored at the destination of the link with the modified data record (3.1), if the verification is successful.
- 8Verfahren nach Anspruch 7, dadurch gekennzeichnet, dass die zweite Datenverarbeitungsanlage auch die gespeicherte digitale Signatur (4) durch die neue digitale Signatur (4.1) ersetzt, wenn die Überprüfung erfolgreich ist. 8th. A method according to claim 7, characterized in that the second data processing system also replaces the stored digital signature (4) with the new digital signature (4.1) if the verification is successful.
- 9Verfahren nach Anspruch 1, dadurch gekennzeichnet, dass der geheime Schlüssel der private Schlüssel eines asymmetrischen Schlüsselpaars ist, eine beliebige Datenverarbeitungsanlage einen Verweis und einen öffentlichen Schlüssel (6) an die zweite Datenverarbeitungsanlage übermittelt, die zweite Datenverarbeitungsanlage die am Ziel des Verweises gespeicherte digitale Signatur (4) mit dem übermittelten öffentlichen Schlüssel (6) überprüft und die zweite Datenverarbeitungsanlage den am Ziel des Verweises gespeicherten Datensatz (3) an die beliebige Datenverarbeitungsanlage übermittelt, wenn die Überprüfung ergibt, dass der Datensatz (3) mit dem privaten Schlüssel des asymmetrischen Schlüsselpaars signiert wurde. 9th Method according to claim 1, characterized, that the secret key is the private key of an asymmetric key pair, any data processing system transmits a reference and a public key (6) to the second data processing system, the second data processing system checks the digital signature (4) stored at the destination of the link with the transmitted public key (6) and the second data processing system transmits the data set (3) stored at the destination of the link to the arbitrary data processing system, if the review shows that the record (3) was signed with the private key of the asymmetric key pair.
- 10Verfahren nach Anspruch 9, dadurch gekennzeichnet, dass die beliebige Datenverarbeitungsanlage zusätzlich einen geänderten Datensatz (3.1) und dessen neue digitale Signatur (4.1) an die zweite Datenverarbeitungsanlage übermittelt, die zweite Datenverarbeitungsanlage die am Ziel des Verweises gespeicherte digitale Signatur (4) und die neue digitale Signatur (4.1) mit dem übermittelten öffentlichen Schlüssel (6) überprüft und die zweite Datenverarbeitungsanlage den am Ziel des Verweises gespeicherten Datensatz (3) und dessen gespeicherte digitale Signatur (4) durch den geänderten Datensatz (3.1) und dessen neue digitale Signatur (4.1) ersetzt, wenn die Überprüfung ergibt, dass der Datensatz (3) und der Datensatz (3.1) mit dem privaten Schlüssel des asymmetrischen Schlüsselpaars signiert wurden. 10th Method according to claim 9, characterized, that the arbitrary data processing system additionally transmits a changed data record (3.1) and its new digital signature (4.1) to the second data processing system, the second data processing system checks the digital signature (4) stored at the destination of the link and the new digital signature (4.1) with the transmitted public key (6), and the second data processing system checks the record (3) stored at the destination of the link and its stored digital signature (4) replaced by the modified data set (3.1) and its new digital signature (4.1), if the review shows the record (3) and the record (3.1) were signed with the private key of the asymmetric key pair. Hierzu 6 Blatt Zeichnungen
Independent claims10
126 paragraphs in 1 section, as filed
The invention relates to a method for the anonymous storage of data and authorized access to this data. Data stored on a server, in the cloud or on a private computer can be retrieved over a network, especially the Internet. These data are anonymous if they can not be assigned to the owner of the data by anyone, in particular not by the operator of the server, the user of the private computer or other network users. However, the server must be able to locate this data as needed and to identify and authorize the rightful owner and / or user of the data, without revealing his anonymity and granting access to the data as part of the authorization, as well as advantageously authorized user to modify this data.
In the prior art asymmetric cryptosystems are known in which the encrypted communication is made possible via a network in which the communicating users do not have a common secret key with which the message can be decoded. These asymmetric cryptosystems are used for private-public-key encryption, private-public-key authentication, and for creating and validating digital signatures.
A private-public-key encryption method is an asymmetric encryption method, so a cryptographic method to use a public key to convert a plain text into a ciphertext from which the plaintext can be recovered with a secret key. The private-public-key encryption method is used for secure communication, whereby the secret key must be kept secret and it must not be possible with reasonable effort to calculate it from the public key. The public key must be accessible to anyone who wants to send an encrypted message to the owner of the secret key. It will usually be ensured eg via a private-public-key infrastructure, that the public key is really assigned to the recipient. The receiver must therefore known, or be attributable to the public key.
Private Public Key Authentication is an authentication method by which a user can prove his identity using a key pair consisting of a private and a public key.
In public-key authentication, the public key is freely accessible and can eg be deposited on the server. The private key is kept secret and eg only on your own computer or a secret external storage medium (eg Smart card), which he may never leave, saved. The calculation of the private key from the public is not possible with reasonable effort. For authentication, a date is encrypted on the user side using the private key, which is then decrypted and verified on the server side with the user's public key stored there. The public key must in turn be clearly attributable to the user, the user is therefore identifiable by the public key.
A digital signature, also digital signature method, is an asymmetric cryptosystem in which a transmitter using a secret signature key (the private key) to a digital message (i.e. H. to any data) a value and encrypted using the private key and a suitable signature algorithm. The resulting date is called digital signature. This date allows anyone to use the public verification key (the public key) to verify the undeniable authorship and integrity of the signature and thus the state of the message at the time the signature was generated. In order to be able to assign a signature created with a signature key to a person, the associated verification key, the public key, must be unequivocally assigned to this person.
/ 16
<img file="AT517151B1_D0001.tif" />
AT 517 151 B1 2017-11-15 Austriahches
Patent Office A disadvantage of the known methods is that they do not take place anonymously, since the public keys must be assignable to the owners of the keys.
US 2012198234 A1 describes a system to ensure the integrity of downloaded data sets. The data record is signed with the private key of a host computer and sent to the browser application, which saves it. Thereafter, the browser application receives the public key of the host computer to verify the integrity of the record. The method is thus used to check whether a record is complete or unchanged.
US 8429232 B1 describes a method of using digital signatures to distinguish in emails whether they come from a trusted organization or not. The digital signature can be contained in the email body in the header or an embedded link. The digital signature is verified by the recipient or Internet service provider, which can be used for spam filtering.
WO 2012108869 A1 describes networked communication modules which have each stored a signature of a data record with a private key, the communication modules being authenticated by an authentication module on the basis of the signatures.
None of the cited prior art documents shows a method for the anonymized storage of data.
The object of the invention is to enable the anonymous storage of data in a network, with only authorized access to this data, for example by the owner of the data, may be possible and unauthorized access to the data detected and the data before can be protected, or the access and the access rights of others can be set by the owner, without the data can be assigned to the owner of others.
According to the invention it is proposed that the owner of the record signed the record with a private key, but the identity of the user not with the associated public key together, for example advertised via a private public key infrastructure. After generating the digital signature, the data record with the digital signature of the data record is stored anonymously in a data store. All accesses to the data store can in the proposed method anonymous, eg with the help of an anonymization service. The data store returns the user after successful filing a link to the record, which is to be kept by him for later access to the record.
In a first variant of the invention, the user also preserves the digital signature of the data record. To retrieve the data, the user sends the link and the digital signature of the record to the data store. The data store compares the digital signature of the record to which the link points and the transmitted digital signature. If they match, the datastore authorizes access and submits the record to the user. In this case, the record stored by the data store can only be found by the data store itself via the link and not directly by the owner or other users who are in possession of the link. In addition, the datastore can not determine the true identity of the creator of the signature using the dataset and the digital signature because the association of the identity of the owner of the public key with whose associated private key the digital signature was generated is not made public.
The advantage of this is that the storage and access of the data is anonymous, since the data store is not able to assign records to a user. Even the assignment of records to each other, so the assignment which records belong to the same anonymous owner is not possible because the digital signature of each record is different and from the digital signature of the private key is not determinable. It is also possible for the user to use a separate key pair for each record.
2/16
<img file="AT517151B1_D0002.tif" />
AT 517 151 B1 2017-11-15 Austrian
Patent Office In order to share the record with other users, the owner may pass the link to the record and the digital signature of the record to other users so that they also have access to the record.
To distinguish the access of another user from the access of the owner, the invention provides that the private key is part of an asymmetric key pair, with the public key all made with the associated private key digital signatures are validated.
In order to allow other users only read access to the record, the invention provides that the owner in addition to the record and its digital signature and the public key transmitted to the data store, the public key is stored by the data store under the link, or sent by the owner each time the record is changed. However, in this case as well, the linking of the identity of the owner of the public key with whose associated private key the digital signature was generated is not made public and also not communicated to the data store. The data store subsequently transmits the data record to all users who are in possession of the link and the digital signature stored in the data store for the data record. In this case, however, a change of the data record is only permissible if a new digital signature is generated for this purpose and the new digital signature of the changed data record can be validated by the data store with the public key stored in the data memory, or the public key is sent by the owner and Both the stored digital signature and the new digital signature can be validated.
If there is a change in the data set, in principle there are two possibilities to store the changed data record, namely with the original digital signature of the data record or with the new digital signature of the changed data record.
If the digital signature of a record is changed by a user, this is no longer accessible by other users who are in possession of the link and the original digital signature. In this case, access can only be granted to the old version of the data record if it is kept available, for example, by means of a versioning system.
Of course, it is up to the owner, or the user making the change eg using a versioning system free to save the changed record as a separate record, so with its own link and digital signature, so that the original record and the changed record exist in parallel.
Important to note is that the subject method only data access, the authorization of access to the data, and thus regulates the flow of information between users via the data memory. If someone gains access to the location of the data record while bypassing the data memory, this person knows both the data records and the digital signatures.
Data security can be achieved if the record is additionally encrypted by the owner. In order to allow the data access by another user, they must subsequently also be in possession of the key, which is not known to the data store.
Another possibility is that the record is encrypted by the data store when filing and decrypted in transmission again. The encryption can be done with any encryption method independent of the proposed authorization mechanism.
The invention and the exemplary variants or extensions according to the invention are illustrated by means of drawings:
Fig. 1: shows schematically the inventive method for storing a data set.
3/16
<img file="AT517151B1_D0003.tif" />
AT 517 151 B1 2017-11-15 Austriahches
Patent Office Fig. 2: shows schematically a preferred variant of the method according to the invention for accessing a data record.
Fig. 3: shows schematically a preferred variant of the method according to the invention for changing a data record.
4:
FIG. 5:
6:
7:
8:
9:
Fig. 10 Fig. 11
Schematically shows the inventive method for storing a record with different access rights.
Schematically shows the inventive method for accessing a record with different access rights.
Schematically shows a first variant of the method according to the invention for changing a data record with different access rights.
Schematically shows a second variant of the method according to the invention for changing a data record with different access rights.
Schematically shows a third variant of the method according to the invention for changing a data record with different access rights and a versioning of the record.
Schematically shows the structure of a system for implementing the method according to the invention.
Schematically shows a second preferred variant of the method according to the invention for accessing a data record.
Schematically shows a fourth preferred variant of the method according to the invention for changing a data record.
In Figs. 1, 2 and 3, the basic principle of the subject invention is illustrated. FIG. 1 shows the method for anonymously storing a data set 3.
The owner 2 of the record 3 signs the record 3 in the first step with his private key, thus obtaining the digital signature 4 of the record 3.
In the second step, the owner 2 sends the data record 3 and the digital signature 4 to the data memory 1.
In the third step, the data memory 1 stores the data record 3 and the digital signature 4 at a memory location 1.1.
In the fourth step, the address which the data memory 1 needs in order to find the data record 3 and its digital signature 4 at the respective memory location 1.1 is sent in the form of the link 5 from the data memory 1 to the owner 2.
In the fifth step, the owner 2 stores the link 5 and the digital signature 4 at a local memory location 2.1 determined by him.
In Fig. 2, the method for calling a record 3 by the owner 2 is shown.
In the first step, the owner loads the digital signature 4 and the link 5 from the local memory location 2.1 and transmits them to the data memory 1.
In the second step, the data memory 1 retrieves the data stored under link 5 and compares whether the transmitted digital signature 4 matches the stored digital signature 4.
If yes, the data memory 1 in the third step sends the record 3 to the owner 2, if no access is denied.
In Fig. 3, the method for changing a record 3 is shown, in which instead of the existing record 3, a new or changed record 3.1 is stored.
In the first step, the owner 2 creates the new data record 3.1 and signs it with his private key in order to obtain the new digital signature 4.1 of the new data record 3.1.
4/16
<img file="AT517151B1_D0004.tif" />
AT 517 151 B1 2017-11-15 Austriahches
Patent Office
In the second step, the owner loads the digital signature 4 and the link 5 from the memory location 2.1 and transmits them to the data memory 1 together with the new digital signature 4.1 and the new data record 3.1.
In the third step, the data memory 1 retrieves the data stored under link 5 and compares whether the transmitted digital signature 4 matches the stored digital signature 4.
If yes, in the fourth step, the data memory 1 replaces the data record 3 stored under link 5 and its digital signature 4 with the new data record 3.1 and its new digital signature 4.1. If not, the replacement of the record 3 is denied.
Preferably, the owner 2 does not have to manually carry out the steps described by him, but is supported by a software (application, application or app). In particular, loading and storing data from or at the storage location 2.1, the signing of the records 3 and the sending and receiving of data to and from the data storage 1 by the software are automated. It is also conceivable that the owner 2 is entirely an automated application which can store, retrieve and modify its data records 3 by the method according to the invention with the aid of the data memory 1.
FIG. Figures 4, 5 and 6 illustrate the method of the invention, which is extended by an exemplary way of defining different access rights to allow controlled access by multiple users. In this case, in addition to the digital signature 4 belonging to the private key of the owner 2 public key 6 is stored in the data memory 1. The public key 6 is able to validate the digital signatures of the private key in the sense of an asymmetric encryption method. Public in this context does not mean that the identity of the owner 2 can be determined on the basis of the public key 6.
FIG. 4 shows the method for anonymously storing a data record 3 with its digital signature 4 and the public key 6.
The owner 2 of the record 3 signs the record 3 in the first step with his private key, thus obtaining the digital signature 4 of the record 3.
In the second step, the public key 6 of the possession 2 is added to the data record 3 and the data record 3, the digital signature 4 and the public key 6 are sent to the data memory 1.
In the third step, the data memory 1 stores the data packet from data record 3, its digital signature 4 and the public key 6 at a memory location 1.1.
In the fourth step, the address which the data memory 1 needs to locate the data packet at the respective memory location 1.1 is sent in the form of the link 5 from the data memory 1 to the owner 2.
In the fifth step, the owner 2 stores the link 5 and the digital signature 4 at a local memory location 2.1 determined by him.
In the sixth step, the link 5 and the digital signature 4 are transmitted either by the owner 2 or the data memory 1 to one or more users 22, depending on the implementation.
In Fig. 5, the method for calling a record 3 by the owner 2 or another user 22 is shown.
In the first step, the owner 2 or the user 22 transmits the digital signature 4 and the link 5 to the data memory 1.
In the second step, the data memory 1 retrieves the data stored under link 5 and compares whether the transmitted digital signature 4 matches the stored digital signature 4.
If yes, the data memory 1 in the third step sends the record 3 to the owner 2 or user 22, if no access is denied.
5/16
<img file="AT517151B1_D0005.tif" />
AT 517 151 B1 2017-11-15 Austriahches
Patent Office A first variant of the method for changing a data record 3 is shown in FIG. 6, in which a new or changed data record 3.1 is stored instead of the existing data record 3 and the access of a user 22 to the changed data record 3.1.
In the first step, the owner 2 creates the new data record 3.1 and signs it with his private key in order to obtain the new digital signature 4.1 of the new data record 3.1.
In the second step, the owner loads the link 5 and optionally the digital signature 4 from the memory location 2.1 and transmits it to the data memory 1 together with the new digital signature 4.1 and the new data record 3.1.
In the optional third step, the data memory 1 retrieves the data stored under the link 5 and compares whether the transmitted digital signature 4 matches the stored digital signature 4.
In the fourth step, the data memory 1 validates the new digital signature 4.1 of the new data record 3.1 with the public key 6 stored in the data memory 1. If step three has been executed, step four is only executed if the transmitted digital signature 4 contains the stored digital signature 4, otherwise the change will be denied.
If the validation is successful, the data memory 1 replaces in the fifth step the data record 3 stored under the link 5 and its digital signature 4 by the new data record 3.1 and its new digital signature 4.1. If not, the replacement of the record 3 is denied.
In the sixth step, the user 22 transmits the digital signature 4 known to him and the link 5 to the data memory 1.
In the seventh step, the data memory 1 retrieves the data stored under the link 5 and compares whether the transmitted digital signature 4 matches the stored digital signature 4.1.
- Since the check fails, access by the user 22 is denied.
The user 22 only has access to the record 3.1 when he receives the new digital signature 4.1 depending on the implementation of the owner 2 or the data memory 1. The owner 2 replaces the digital signature 4 stored at the storage location 2.1 for the link 5 with the new digital signature 1.
In Fig. 7, a second variant of the method for changing a record 3 is shown, in which instead of the existing record 3, a new or changed record 3.1 is stored and the access of a user 22 takes place on the changed record 3.1.
In the first step, the owner 2 creates the new data record 3.1 and signs it with his private key in order to obtain the new digital signature 4.1 of the new data record 3.1.
In the second step, the owner loads the link 5 and optionally the digital signature 4 from the memory location 2.1 and transmits it to the data memory 1 together with the new digital signature 4.1 and the new data record 3.1.
In the optional third step, the data memory 1 retrieves the data stored under the link 5 and compares whether the transmitted digital signature 4 matches the stored digital signature 4.
In the fourth step, the data memory 1 validates the new digital signature 4.1 of the new data record 3.1 with the public key 6 stored in the data memory 1. If step three has been executed, step four is only executed if the transmitted digital signature 4 contains the stored digital signature 4, otherwise the change will be denied.
If the validation is successful, the data memory 1 replaces in the fifth step the data record 3 stored under the link 5 with the new data record 3.1, but not its digital signature 4.
In the sixth step, the user 22 transmits the digital signature 4 known to him
6/16
<img file="AT517151B1_D0006.tif" />
AT 517 151 B1 2017-11-15 Austriahches
Patent Office and link 5 to the data store 1.
In the seventh step, the data memory 1 retrieves the data stored under link 5 and compares whether the transmitted digital signature 4 matches the stored digital signature 4.
Since the check is successful, the data memory 1 transmits the new data record 3.1 to the user 22.
In this variant, the stored in the data memory 1 digital signature 4 is no longer valid for the new data set 3.1, but this has no effect on the access method according to the invention, since the validity of the stored in the data memory 1 4 signature for in the data memory. 1 stored record 3, 3.1 does not have to be given.
In FIG. 8th an alternative variant of the method according to the invention is shown, in which a versioning of the data set takes place. In this variant, the original record (3) is not replaced by the new record (3.1), but both any number of records (3, 3.1) or any number of versions of the record (3) are stored under the link (5) from the data memory (1), each record (3, 3.1) or each version of the record (3) has its own unique digital signature (4, 4.1) has. The owner 2 resp. A user 22 receives in succession that record (3, 3.1) whose digital signature (4, 4.1) he transmits with the link (5) to the data memory (1).
In Fig. 9, an exemplary computer system for implementing the invention is shown. The owner 2 or user 22 have a terminal 12 which is able to perform an encryption of data, that is, at least one arithmetic unit and a memory. The terminal 12 is for example a computer, laptop or mobile phone.
The data memory 1 has an application which is executed by a computing unit, in particular that of a server 11. The terminals 12 are connected via a wired or wireless network, in particular the Internet with the server 11 in data connection, or can produce such as needed. The server 11 either has its own memory 11.1, for example in the form of hard disks in which the data of the data memory 1 are stored. Alternatively or additionally, the server 11 is in data communication with at least one external memory 13 via a network, or can establish such a data connection if required. The external memory 13 may be the memory of another server, a terminal or the cloud.
For example, the external memory 13 may also be the memory of the terminal 12 of the owner 2. The advantage of this is that the data record 3 actually remains at the memory location 2.1 of the owner, the access being made via the data memory 1. Thus, users 22 can access the data record 3 via the data memory 1 without having a direct data connection to the terminal 12 of the owner 2. The owner 2 has so independent of the data store 1 control of his record 3 and, for example, the data stored by the data store 1 on its location 2.1 (record 3, digital signature 4) at any time, or move, so they can not be found via the link 5 are.
FIG. 10 shows an alternative access method to the stored data record 3, in which the private key 6 is part of an asymmetrical key pair, that is to say has a public key 6 that can be uniquely assigned to it.
Transfers any data processing system, for example, that of the owner 2 or a user 22, a reference (link 5) and a public key 6 to the second data processing system, which operates the data memory 1, the second data processing system checks the digital signature 4 stored at the destination of the link with the transmitted public key 6 and the second data processing system transmits the data record 3 stored at the destination of the link to the arbitrary data processing system, if the review shows that the record 3 was signed with the private key of the asymmetric key pair. Thus, everyone has access to the record 3, which is in possession of the link (links 5) and has the public key 6 of the key pair.
7/16
<img file="AT517151B1_D0007.tif" />
AT 517 151 B1 2017-11-15 [0061] In FIG. 11 the method of altering the alternative access method to the stored data record 3 is shown, in which the private key is part of an asymmetrical key pair, that is, has a public key that can be uniquely assigned to it. The arbitrary data processing system (for example, that of the owner 2) transmits the public key 6, a modified data record 3.1 and its new digital signature 4.1 to the second data processing system in addition to the link (link 5). The second data processing system checks the stored at the destination of the reference digital signature 4 and the new digital signature 4.1 with the transmitted public key 6 and replaces the stored at the destination of the reference record 3 and its stored digital signature 4 by the modified data set 3.1 and its new digital Signature 4.1, if the review shows that record 3 and record 3.1 were signed with the private key of the asymmetric key pair. The access according to the alternative access method of FIG. 11 is still possible because the review of the new digital signature 4.1 to the changed record 3.1 with the public key 6 continues to be successful. It is advantageous that with the possession of the public key 6 has access to all records 3 and changed records 3.1, which were signed with the associated private key and the link 5 has one. This method has some drawback with respect to anonymization when the public key is attributable to a person, but we simplify the sharing of records 3 with others. Another disadvantage is that the access authorization by other users 22, which are in the possession of the public key 6 and the link 5, can not be denied without additional measures again.
The modification method shown in FIG. 11 can also be combined, for example, with the access method of FIG. 2, so that the data record 3 is transmitted only if the link 5 and the digital signature currently stored for the data record are sent to the data memory 1 are sent and a change of the record 3 according to the method of FIG. 11 takes place.
In a further variant of the subject invention, it is provided that the data memory 1 stores the record 3 and its digital signature 4 at a link 5 at the storage location 1.1 and each transmits the record 3 of the link 5 is transmitted to the data memory 1. However, a change of the data record 3 is only possible if access is made by the owner 2, for example according to FIG. 3 the digital signature 4 is sent or if according to FIG. 11 a new record 3.1, the digital signature 4.1 and the public key 6 are sent.
In a further variant, it is provided that the filing of a record 3 and the change access of the owner 2 is carried out as already described, but the transmission of the record 3 to other users 22 by other criteria. Advantageously, the public keys of any number of users 22 can be additionally stored under the link 5 to the record 3. The data record 3 is transmitted to everyone who transmits the link 5 and his public key, as long as this public key is stored with the record 3. A change of the data set 3 is possible depending on the implementation only if, according to FIG. 3 the digital signature 4 is sent or if according to FIG. 11 a new data record 3.1, the digital signature 4.1 and the public key 6 are sent, wherein the stored digital signature 4 and the digital signature 4.1 were created with the private key associated with the public key 6.
8.16
<img file="AT517151B1_D0008.tif" />
AT 517 151 B1 2017-11-15 Austriahches
Patent Office
14 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| DE10234815A1 | Cites | Germany | Search report |
| US2005138046A1 | Cites | United States of America | Search report |
| WO2007079792A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO2012108869A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| US2012198234A1 | Cites | United States of America | Search report |
| US8429232B1 | Cites | United States of America | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 503292015 | Austria | A | |
| AT20150050329 | – | – | – |
Numbers
- Publication
- 517151
- Publication, DOCDB
- 517151
- Publication, EPODOC
- AT517151B
- Application
- 50329
- Application, DOCDB
- 503292015
- Application, EPODOC
- AT20150050329
Titles2
- English
- Method for authorizing access to anonymously stored data
- German
- Verfahren zur Autorisierung des Zugriffs auf anonymisiert gespeicherte Daten
Classification
- CPC, 10
- H04L9/3247
- H04L9/0894
- G06F15/16
- G06F21/00
- G06F21/30
- H04L9/08
- H04L9/30
- H04L9/32
- H04L63/08
- H04L63/10
- IPC, 6
- H04L9 32
- G06F15 16
- G06F21 30
- H04L9 08
- H04L9 30
- H04L29 06