EP1423765A2

Apparatus for and method of controlling propagation of decryption keys

Abstract

A security system for controlling access to encrypted information, comprising: a memory for storing at least one decryption key for use in decrypting an encrypted item of information, the decryption key being associated with a security code which can be used to determine whether the security system is authorized to send encrypted copies of the decryption key to others. If the security system is authorized to send an encrypted copy of the decryption key, it encrypts the decryption key and propagates the encrypted copy of the decryption key. Each time the security system propagates a decryption key, it includes as part of the decryption key an identifier indicating the identity of a sender's key. A user can append a control word against their identity in the decryption key to instruct the security system to initiate a message to them or an agent informing them of the propagation of the key and giving information concerning that propagation.

Term

Term ended

Projected expiry passed 22 August 2022, 4.1 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

17 claims: 10 independent, 7 dependent

  1. 1
    Claims of equivalent WO 03021400 A2 CLAIMS 1. A security system for controlling access to encrypted information, comprising a hardware device (32) for storing at least one data unit comprising a decryption key (54) and an associated security code (52), in which the decryption key (54) is used in decrypting an encrypted item of information and the security code (52) controls the number of times that the decryption key can be propagated, and the hardware device examines the security code to determine whether it is authorised to send encrypted copies of the decryption key to others.
  2. 4
    A security system as claimed in any one of the preceding claims, in which the hardware device (32) sends the decryption key within a data unit (40) and each time the hardware device sends a data unit (40) to another entity, it modifies the security code and sends the modified security code as part of the encrypted data unit.
  3. 6
    A security system as claimed in any one of the preceding claims in which the decryption key is stored within the hardware device.
  4. 7
    A security system as claimed in any one of the preceding claims, in which the hardware device is removable from a data processor.
  5. 8
    A security system as claimed in any one of the preceding claims, in which the hardware device (32) is in the form of a user unit, which, in use, a user interfaces with a data processor (20) to establish communication therewith when the user wishes to use the data processor to access encrypted information and breaks the communication between the user unit and the data processor when the user has finished.
  6. 9
    A security system as claimed in any one of the preceding claims, in which each time the hardware device (32) propagates one of the data units comprising a decryption key, it includes as part of the data unit an identifier indicating the identity of the sender's key.
  7. 12
    A security system comprising a plurality of hardware devices as claimed in any one of the preceding claims, and in which the data unit is passed from hardware device to hardware device.
  8. 13
    A security system as claimed in any one of the preceding claims, in which a user's private key is stored within their own hardware device, such that the encrypted data unit can only be decrypted when the hardware device is in operation.
  9. 14
    A security system as claimed in any of the preceding claims, wherein the hardware device includes a data processor such that all encryption and decryption of the data units is performed within the hardware device.
  10. 15
    A method of controlling the propagation of decryption keys for allowing access to encrypted data, comprising the steps of storing at least one data unit on a hardware device, the at least one data unit comprising a decryption key, including a propagation control word with the decryption key in the data unit, and in response to an instruction to send the data unit to a specified recipient, checking the status of the control word to determine if propagation is allowed, and if so, modifying the control word and encrypting the data unit comprising the control word and decryption key with a recipient's public key and sending the data unit.