EP3269079B1

Systems and methods for organizing devices in a policy hierarchy

Abstract

This record has no abstract on file.

EP3269079B1, drawing sheet 1
Sheet 1 of 12

Term

Projected expiry 14 March 2036.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Projected expiry

14 claims: 2 independent, 12 dependent

  1. 1
    A method for organizing devices in a policy hierarchy, executed by a processor, the method comprising:creating a first node (1010);assigning a first policy (115) to the first node (1010);creating a second node (1020), the second node (1020) referencing the first node (1010) as a parent node such that the second node (1020) inherits the first policy (115) of the first node (1010);assigning a second policy (115) to the second node (1020) such that the second node (1020) is assigned the first policy (115) and the second policy;registering a first device (150a, 150b) to the first node (1010) such that the first device (150a, 150b) is bound by the first policy (115) of the first node (1010);registering a second device (150a, 150b) to the second node (1020) such that the second device (150a, 150b) is bound by the first and second policies of the second node (1020);and receiving an encryption key having a key attribute (160);wherein the first policy (115) and the second policy (115) dictate acceptability of an encryption key based on security and cryptographic considerations of the encryption key.
  2. 8
    A system for organizing devices in a policy hierarchy, the system comprising:a memory;and a processor configured to: create a first node (1010);assign a first policy to the first node (1010);create a second node (1020), the second node (1020) referencing the first node (1010) as a parent node such that the second node (1020) inherits the first policy of the first node (1010);receive an encryption key;assign a second policy (115) to the second node (1020) such that the second node (1020) is assigned the first policy (115) and the second policy;register a first device (150a, 150b) to the first node (1010) such that the first device (150a, 150b) is bound by the first policy (115) of the first node (1010);register a second device (150a, 150b) to the second node (1020) such that the second device (150a, 150b) is bound by the first and second policies of the second node (1020);and determine acceptability of the security and cryptographic considerations of the encryption key based on at least the first policy.