EP3675415B1

A method of controlling use of data and a cryptographic device

Abstract

This record has no abstract on file.

EP3675415B1, drawing sheet 1
Sheet 1 of 20

Term

10.4 yearsleft in the term

Expires 3 February 2037.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

15 claims: 3 independent, 12 dependent

  1. 1
    A method of controlling use of data, the data being stored in a service provider system (3) in a manner which is accessible to a trusted second security context (7) in the service provider system (3) but secure from the rest of the service provider system, wherein an access control list specifying that a valid use credential must be presented in order to grant a first type of use of the data is stored with the data, wherein the data comprises a cryptographic key K tenant , and wherein the access control list specifies that the cryptographic key, K tenant can be stored outside the second security context only when encrypted for storage by a key which cannot leave the second security context, the method comprising:generating a use credential in a first security context (5), wherein the use credential comprises: information from which the data corresponding to the use credential can be identified;information from which the expiry of the use credential can be determined;issuing the use credential and information from which the origin of the use credential can be validated;validating the use credential with respect to the access control list, and validating that the use credential has not expired at the second security context (7);granting the first type of use of the data, in the second security context (7), on the condition that the use credential is valid and not expired.
  2. 6
    The method of any one of claims 1 to 5, wherein the use credential is a use certificate and further comprising:cryptographically signing the use certificate with a private key K tenant-sign priv in the first security context (5), wherein the information from which the origin of the use certificate can be validated is the signature and wherein the corresponding public key K tenant-signpub is integrity protected and accessible to the second security context (7);verifying the use certificate using the public key K tenant-signpub at the second security context.
  3. 7
    The method of any one of claims 1 to 6, wherein the information from which the expiry of the use credential can be determined comprises:an expiry time;information identifying a reference time source (2).
  4. 10
    The method of any of claims 1 to 9, wherein the generating a use credential in a first security context (5) comprises:selecting a reference time source (2);requesting a current time stamp from the reference time source (2);sending a message comprising the current time stamp from the reference time source to a tenant system (1), together with information from which an origin of the message can be validated, wherein the first security context (5) is in the tenant system (1);validating the origin of the message;and calculating an expiry time based on the current time stamp.
  5. 11
    The method of any of claims 8 to 10, wherein the message further comprises information relating to the current configuration of the reference time source (2).
  6. 12
    The method of any of claims 8 to 11, wherein the method further comprises at least one of a) and b):a) providing the public half of an identity cryptographic key pair of the time source to the first security context, together with information validating the origin of the identity cryptographic key pair;b) providing the public half of an identity cryptographic key pair of the time source to the second security context, together with information validating the origin of the identity cryptographic key pair.
  7. 14
    The method of any of claims 1 to 13, wherein information relating to a start time is included in the use credential.
  8. 15
    A carrier medium comprising computer readable code configured to cause a computer to perform the method of any of claims 1 to 14.