CA2400940C

Controlling access to a resource by a program using a digital signature

Abstract

A computer system has a resource, a verification unit and an execution engine for running a body of program codehaving an associated signature. A cryptographic key is associated with the resource and when the code is to be loaded into theexecution engine a verification operation is run on the signature using the cryptographic key associated with the resource. Theexecution engine is separate from the resource and when access to the resource is required by the code in the execution engine afurther verification operation is conducted on the signature using the cryptographic key associated with the resource. Access to theresource by the code depends upon the result of the verification operation.

CA2400940C, drawing sheet 1
Sheet 1 of 11

Term

Term ended

Expired 20 February 2021, 5.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

19 claims: 10 independent, 9 dependent

  1. 1
    CA 02400940 2006-12-06 CLAIMS:1. A method for controlling access by a body of code to a resource (100), the resource being held within and managed by a secure computer system, the method comprising the steps of: (i) attaching a signature to said code;(ii) providing a cryptographic key bound to said resource;(iii) conducting a verification operation on said signature using said cryptographic key;(iv) and controlling access to the resource by the code in dependence upon the result of said verification operation.
  2. 4
    A method as claimed in any of claims 1 to 3 further comprising:CA 02400940 2006-12-06 providing an execution engine (200) separate from said resource (100) for executing said code (22);and step (iii) comprises loading said code into said execution engine in response to said signature being verified.
  3. 5
    A method as claimed in any of claims 2 to 4 wherein:said resource (100) has a plurality of associated keys (102);step (ii) comprises conducting a verification operation on each said signature (24, 28) using each said cryptographic key (102) associated with said resource (100);and step (iii) comprises allowing said code access to said resource in response to any 10 one of said signatures being verified.
  4. 6
    A method as claimed in any of claims 2 to 4 wherein:said resource (100) has a plurality of associated keys (102);step (ii) comprises conducting a verification operation on each said signature (24, 28) using each said cryptographic key (102) associated with said resource (100);and step (iii) comprises allowing said code access to said resource only in response to all of said signatures being verified.
  5. 10
    A method as claimed in any of claims 7 or 8 wherein:said resource (100) has a plurality of associated keys (102);step (iv) comprises conducting a verification operation on each said signature (24,28) using each said cryptographic key (102) associated with said resource (100);and step (v) comprises allowing said code access to said resource in response to any one of said signatures being verified.
  6. 11
    A method as claimed in any of claims 7 or 8 wherein:said resource (100) has a plurality of associated keys (102);CA 02400940 2006-12-06 step (iv) comprises conducting a verification operation on each said signature (24,28) using each said cryptographic key (102) associated with said resource (100);and step (v) comprises allowing said code access to said resource only in response to all of said signatures being verified.
  7. 12
    A method as claimed in any of claims 1 to 11 wherein the or each said key (102) is configured to authorise preselected actions on said resource (100).
  8. 13
    A method as claimed in any of claims 1 to 11 wherein:the or each said key (102) is configured to authorise preselected actions on said resource (100);and following verification ofthe or one ofthe signatures by a said key associated with said resource, access to said resource by said code (22) is allowed only in relation to those preselected actions associated with said key.
  9. 14
    A method as claimed in any of claims 1 to 13 comprising:providing said code (22) with first and second signatures (24, 28);associating a cryptographic key (402) for said second signature with said first signature;step (ii) comprises conducting a verification operation on said first signature (24) using said cryptographic key (108) associated with said resource (100), and conducting a verification operation on said second signature (28) using said cryptographic key (402) associated with said first signature (24);and step (iii) comprises allowing said code access to said resource in response to both of said signatures being verified.
  10. 17
    A computer system for implementing the method of any of claims 1 to 16 comprising:verification means for verifying a digital signature associated with a body of program code;and a resource having a cryptographic key bound thereto;wherein said verification means is operable to use said cryptographic key to verify said digital signature thereby to allow access ofthe code to said resource in dependence upon the verification.