Nova Patents
EP4040713A1

Cypher gateway system

Abstract

In a first security domain (610) of a cypher gateway system (600), a computer converts a message (M) into an encyphered form that is associated with a first public key and a first private key. In a second security domain (620) of the system, the computer creates a second public key and a second private key. The computer places arguments to a channel (632) that is shared with both domains. A first argument shows knowledge of the message and shows properties of the message; a second argument shows that knowledge of the second private key implies knowledge of the message. A gateway (630) intercepts the placements, verifies the properties of the message using the first argument, and observes that the message verifiably communicated to an owner of the second private key. The gateway then enforces (636) a policy to determine at least one action.

EP4040713A1, drawing sheet 1
Sheet 1 of 535

Term

10.2 yearsto projected expiry

Projected expiry 25 November 2036, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

13 claims: 6 independent, 7 dependent

  1. 1
    A computer-implemented method for use in a cypher gateway system (600), the method comprising:within a first security domain (610), converting a message (M) into an encyphered form associated with a first public key and a first private key;within a second security domain (620), creating a second public key and a second private key;placing, on a shared channel (632) of the first security domain (610) and of the second security domain (630), a first argument (S) showing knowledge of the message and showing properties of the message;placing, on the shared channel, a second argument (T) showing that knowledge of the second private key implies knowledge of the message (M);at a gateway (630): intercepting the send that was placed on the shared channel (632);verifying the properties of the message (M) using the first argument;observing that the message (M) is verifiably communicated to an owner of the second private key;and enforcing (636) a policy to determine at least one action.
  2. 7
    Method according to any of the preceding claims, wherein in the obtaining step, the second public key identifies the recipient of the message (M) and wherein in the observing step, it is observed that the message (M) is verifiably communicated to the recipient.
  3. 8
    Method according to any of the preceding claims, wherein intercepting and verifying is performed without accessing the message.
  4. 9
    Method according to any of the preceding claims, wherein observing that the message is verifiably communicated comprises:transforming a first secret (166) including confidential data into a first public representation of the first secret;executing at least one instruction on the first secret (166) to obtain a second secret (148);transforming the second secret into a second public representation of the second secret;generating (142) an instruction statement that conveys a relation between the first public representation of the first secret and the second public representation of the second secret;generating a first gestalt statement (124, 126) characterizing a first gestalt relation between a first plurality of piece-secrets, the first gestalt relation defining a manner in which the first plurality of piece-secrets combine to provide the first secret;generating a second gestalt statement characterizing a second gestalt relation between a second plurality of piece-secrets, the second gestalt relation defining a manner in which the second plurality of piece-secret combine to provide the second secret;providing the instruction statement, the first gestalt statement, and the second gestalt statement to enable verification of application of the instruction statement and the relation between the first secret and the second secret;and performing an action in response to the verification of the application, wherein the action is related to the confidential data.
  5. 12
    A computer program product including instructions recorded on a non-transitory computer readable storage medium, which, when executed by at least one process, are configured to cause at least one processor to perform a method according to any of claims 1 to 11.
  6. 13
    A computer system adapted to perform a method according to any of claims 1 to 11.