AU2006201428A1

Secure digital credential sharing arrangement

Abstract

A secure and transparent digital credential sharing arrangement which utilizes one or more cryptographic levels of indirection to obfuscate a sharing entity's credentials 207 from those entities 230 authorized to share the credentials. A security policy table 225 is provided which allows the sharing entity 205 to selectively authorize or revoke digital credential sharing among a plurality of entities 230. Various embodiments of the invention provide for secure storage and retrieval of digital credentials from security tokens such as smart cards. The secure sharing arrangement may be implemented in hierarchical or non-hierarchical embodiments as desired.

AU2006201428A1, drawing sheet 1
Sheet 1 of 1

Term

Term ended

Projected expiry passed 5 April 2026, 0.5 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

39 claims: 7 independent, 32 dependent

  1. 1
    THE CLAIMS DEFINING THE INVENTION ARE AS FOLLOWS:1. A method to securely and selectively share digital credentials among a plurality of separate entities comprising: 5 providing a first credential store having retrievably stored therein a plurality of first entity credentials, . protecting at least a portion of said first entity credentials with first protection means configured to revocably allow said at least a portion of said first entity credentials to be revocably shared with at least a second entity, said 10 first protection means comprising a first secret determinable by at least said second entity, generating said first secret as a function of at least i. a common secret between said first entity and said at least said second entity, and 15 ii. a first entity specific string retrievable by said at least said second entity, and ‘ responsive to at least said first secret, granting said at least a second entity I permission to share said at least a portion of said first entity credentials. 20
  2. 6
    The method according to claim I comprising:5 providing a second credential store having retrievably stored therein a plurality of second entity credentials, protecting at least a portion of said second entity credentials with second protection means configured to revocably allow said at least a portion of said second entity credentials to be revocably shared with said first entity, said second 10 protection means comprising a second secret determinable by at least said first entity, generating said second secret as a function of at least said common secret, and responsive to at least said second secret, granting said at least a first entity permission to share said at least a portion of said second entity credentials.
  3. 15
    15 common secret is stored encoded with said second secret. 15. A system to securely and selectively share digital credentials among a plurality of separate entities comprising:( a first credential store having retrievably stored therein a plurality of first entity 20 credentials, i first protection means for protecting at least a portion of said first entity credentials, said first protection means comprising a first secret determinable by at least a second entity, first revocable means for revocably allowing said at least a portion of said first 25 entity credentials to be shared with at least said second entity, first generating means for generating said first secret as a function of at least: iii. a common secret between said first entity and said at least said second entity, and iv. a first entity specific string retrievable by said at least said second entity, I 30 and 20060405 Sped as filed doc 2006201428 05 Apr 2006 first granting means responsive to at least said first secret for granting said at least a second entity permission to share said at least a portion of said first entity credentials. 5
  4. 33
    A computer program product embodied in a tangible form comprising instructions I ' for a processor to securely and selectively share credentials among a plurality of separate entities, said instructions executable by said processor to;access a first credential store having retrievably stored therein a plurality of first entity credentials, 25 protect at least a portion of said first entity credentials with first protection means . 1 . . . . for revocably allowing said at least a portion of said first entity credentials to be shared with at least a second entity, said first protection means comprising a first secret determinable by at least said second entity, generate said first secret as a function of at least 20060-105 Speci as filed doc I, I 2006201428 05 Apr 2006 ί. a common secret between 'said first entity and said at least said second entity, and ii. a first entity specific string retrievable by said at least said second entity, and 5 responsive to at least said first secret, to grant said at least a second entity permission to share said at .least a portion of said first entity credentials.
  5. 36
    A computer readable medium having stored thereon a data structure comprising:a first field containing data representing an entity specific data string;a second field containing encoded data representing a credential associated with said entity specific data string, and a third field containing data representing a entity specific secret used in encoding 20 at least said second field. '
  6. 38
    A method to securely and selectively share digital credentials among a plurality of separate entities, substantially as hereinbefore described with reference to the accompanying drawings. 20060405 Sped as filed doc 2006201428 05 Apr 2006 - · 29 .
  7. 39
    A system to securely and selectively share digital credentials among a plurality of separate entities, substantially as hereinbefore described and/or illustrated in the accompanying drawings. ,