EP1389752A2

System and method for privilege delegation and control

Abstract

A privilege (20) and associated control attributes (30) are delegated from a security token (10) to another data processing unit, for example a security token or an intelligent device such as a computer system. The privilege (20) may be in the form of an attribute certificate, a key component of a cryptographic key, a complete cryptographic key, digital certificate, digital right, license or loyalty credits. The purpose of the delegation is to allow another data processing unit to act as a surrogate for the security token (10) or to access a resource which requires components from both units before access is permitted. Attributes (30) associated with the delegated privilege (20) control the scope and use of the privilege (20). The delegation may allow the surrogate to perform authentications, access data or resources included on another security token or computer system. Authentications are performed prior to transferring of the delegable privileges.

EP1389752A2, drawing sheet 1
Sheet 1 of 26

Term

Term ended

Projected expiry passed 8 August 2023, 3.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

42 claims: 5 independent, 37 dependent

  1. 1
    A system for delegating a privilege (20) and associated attributes (30) from a security token (10) to at least a first data processing unit (40), said privilege (20) enabling access to at least one resource by said at least a first data processing unit (40) subject to requirements prescribed in said associated attributes (30) comprising:i. said security token (10) including said privilege (20) and said associated attributes (30) and delegation means for delegating said privilege (20) to said at least a first data processing unit (40), ii. said at least a first data processing unit (40) including privilege processing means for implementing said privilege (20) in accordance with said requirements prescribed in said associated attributes (30), iii. communications means for performing data exchanges between said security token (10) and said at least a first data processing unit (40).
  2. 14
    A system for delegating a privilege (20) from a security token (10) to at least a first data processing unit (40), wherein said privilege (20) enables said at least a first data processing unit (40) to perform a function selected from the group consisting of;surrogate operations for said security token (10), terminal activation, personalization of an intelligent device, access to a resource included in or accessible through at least a second data processing unit (50), or loyalty credit management.
  3. 16
    A method for delegating a privilege (20) having associated attributes (30) from a security token (10) to at least a first data processing unit (40), said privilege (20) enabling said at least a first data processing unit (40) to use said privilege (20) subject to requirements prescribed in said associated attributes (30), said method comprising:i. performing (502) a mutual authentication transaction between said security token (10) and said at least a first data processing unit (40), ii. securely transferring (508) said privilege (20) including said associated attributes (30) to said at least a first data processing unit (40), iii. using (524) said privilege (20) as prescribed by said associated attributes (30).
  4. 21
    A privilege delegation system comprising:i. a security token (10) including at least one delegable privilege (20) and attributes associated with said delegable privilege (20), ii. at least a first data processing unit (40) including means to use said privilege (20) subject to requirements prescribed in said associated attributes (30).
  5. 28
    A privilege delegation system comprising:i. a security token (10) including at least a first part of a delegable privilege (20) and attributes associated with said first part of said delegable privilege (20) and transfer means for transferring said first part of said delegable privilege (20) and said attributes to at least a first data processing unit (40), ii. said at least a first data processing unit (40) including a second part of said delegable privilege (20), first combining means for combining said first part of said delegable privilege (20) with said second part of said delegable privilege (20) to form an operable privilege.