CA3123268C

A method of data transfer, a method of controlling use of data and a cryptographic device

Abstract

A method of controlling use of data securely stored in the service provider system comprises issuing a use certificate having an expiry time to the party requesting use of the data. The use certificate must be validated before use of the stored data is granted. This enables the tenant to grant use of the stored data for a limited time period.

CA3123268C, drawing sheet 1
Sheet 1 of 21

Term

10.4 yearsleft in the term

Expires 3 February 2037.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

14 claims: 6 independent, 8 dependent

  1. 1
    A method of controlling use of data, the data being stored in a service provider system in a manner which is accessible to a trusted second security context in the service provider system but secure from the rest of the service provider system, wherein an access control list specifying that a valid use credential must be presented in order to grant a first type of use of the data is stored with the data, wherein the data comprises a cryptographic key Ktenant, and wherein the access control list specifies that the cryptographic key, Ktenant can only be encrypted for storage outside of the second security context by a key which cannot leave the second security context, the method comprising:generating a use credential in a first security context, wherein the use credential comprises: information from which the data corresponding to the use credential can be identified;information from which the expiry of the use credential can be determined;issuing the use credential and information from which the origin of the use credential can be validated;validating the use credential with respect to the access control list, and validating that the use credential has not expired at the second security context;granting the first type of use of the data, in the second security context, on the condition that the use credential is valid and not expired.
  2. 6
    The method of any one of claims 1 to 5, wherein the use credential is a use certificate and further comprising:cryptographically signing the use certificate with a private key K tenant _ signpr!v in the first security context, wherein the information from which the origin of the use certificate can be validated is the signature and wherein the corresponding public key K tenant _ signpub is integrity protected and accessible to the second security context;verifying the use certificate using the public key K ten ant-sign pub at the second security context.
  3. 7
    The method of any one of claims 1 to 6, wherein the information from which the expiry of the use credential can be determined comprises:an expiry time;information identifying a reference time source.
  4. 11
    The method of any one of claims 8 to 10, wherein the method further comprises at least one of a) and b):a) providing the public half of an identity cryptographic key pair ofthe time source to the first security context, together with information validating the origin ofthe identity cryptographic key pair;b) providing the public half of an identity cryptographic key pair ofthe time source to the second security context, together with information validating the origin ofthe identity cryptographic key pair.
  5. 13
    The method of any one of claims 1 to 12, wherein information relating to a start time is included in the use credential.
  6. 14
    A carrier medium comprising computer readable code configured to cause a computer to perform the method as defined in any one of claims 1 to 13.