GB2400699A

Secure provision of data using trusted authorities and encryption

Abstract

To control access to target data whilst relieving the data provider (30) of policing obligations, the data provider (30) provides the target data in encrypted form to a requesting party (20) as part of a data set with which first and second trusted authorities (40,45) are associated in a non-subvertible manner. Recovery of the target data in clear by the party (20) requires the first trusted authority (40) to verify that a specific individual is a professional accredited with it, the second trusted authority (45) to verify that a particular organisation (50) is accredited with it, the particular organisation (50) to verify that the specific individual is engaged by it, and at least one of the particular organisation (50) and the first trusted authority (40) to verify that the party (20) is the specific individual. Various ways of encrypting the target data are provided, the preferred ways being based on Identifier-Based Encryption schemas.

GB2400699A, drawing sheet 1
Sheet 1 of 28

Term

Term ended

Projected expiry passed 2 April 2024, 2.5 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

40 claims: 7 independent, 33 dependent

  1. 1
    CLAIMS 1. A method of recovering target data provided in encrypted form to a party as part of a data set with which first and second trusted authorities are associated in a non-subvertible manner, the method comprising:providing a first element to the party after the first trusted authority has verified that a specific individual is a professional accredited with it;providing a second element to the party after both the second trusted authority has verified that a particular organisation is accredited with it, and said particular organisation has verified that said specific individual is engaged by it;and the party using both said elements to recover the target data in clear;at least one of the particular organisation and the first trusted authority ensuring that its verification is for said party as said specific individual before providing the corresponding element.
  2. 14
    A secure data-provision method comprising providing target data from a data provider to a party purporting to be a specific, professionally-accredited, individual engaged by a specific accredited organisation, the target data being provided in encrypted form as part of a data set that comprises:a first item encrypted, according to an Identifier-Based Encryption, IBE, scheme, in dependence on encryption parameters comprising a first encryption key string that identifies said specific individual, and public data of a first trusted authority competent in respect of professional accreditations;and a second item encrypted according to an IBE scheme, in dependence on encryption parameters comprising a second encryption key string that identifies said specific organisation, and public data of a second trusted authority competent in respect of accreditations of organisations;recovery of the target data in clear requiring decryption of both the first and second items.
  3. 19
    A secure data-provision method comprising providing target data from a data provider to a party purporting to be a specific, professionally-accredited, individual engaged by a specific accredited organisation, the target data being provided in encrypted form as part of a data set that comprises:a first item encrypted using both a first encryption key string that identifies said specific individual, and public data of a first trusted authority competent in respect of professional accreditations;and a second item encrypted using both a second encryption key string that identifies said specific organisation, and public data of a second trusted authority competent in respect of accreditations of organisations;recovery of the target data in clear requiring decryption of both the first and second items.
  4. 20
    A system for recovering target data provided in encrypted form to a party as part of a data set with which first and second trusted authorities are associated in a non-subvertible manner, the system comprising:a first computing entity, associated with the first trusted authority, for providing a first element to the party after verifying that a specific individual is a professional accredited with it;a second computing entity associated with the second trusted authority;a third computing entity, associated with a particular organisation, for providing a second element to the party after the second computing entity has verified that said particular organisation is accredited with it, and the third computing entity has verified that said specific individual is engaged by it;and a fourth computing entity, associated with said party, for decrypting the target data using the first and second elements;at least one of the first and third computing entities being arranged to ensure that its verification is for said party as said specific individual before providing the corresponding element to the party.
  5. 29
    Apparatus for the secure provision of target data to a party purporting to be a specific, professionally-accredited, individual engaged by a specific accredited organisation, the apparatus comprising an encryption subsystem for generating a data set including the target data in encrypted form, the encryption subsystem comprising:first encryption means for encrypting a first item, according to an Identifier-Based Encryption, IBE, scheme, based on encryption parameters comprising a first encryption key string that identifies said specific individual, and public data of a first trusted authority competent in respect of professional accreditations;second encryption means for encrypting a second item, according to an IBE scheme, based on encryption parameters comprising a second encryption key string that identifies said specific organisation, and public data of a second trusted authority competent in respect of accreditations of organisations;and means for forming the data set using at least the encrypted first and second items;the recovery of the target data in clear requiring decryption of both the first and second items.
  6. 34
    A computing entity for recovering target data provided in encrypted form as part of an data set that comprises first and second encrypted items both of which must be decrypted to recover the target data, the first item being encrypted in dependence on encryption parameters comprising a first encryption key string that identifies a specific individual and first public data, and the second item being encrypted in dependence on a second encryption key string that identifies a specific organisation and second public data; the entity comprising:5 first means for requesting either a first decryption key corresponding to the first encryption key string, or the first item in decrypted form, from a first trusted authority which is competent in respect of the accreditation of professionals and holds first private data related to the first public data, the first means being arranged to provide the first encryption key string to the first trusted authority when making its 10 request and being further arranged to authenticate the entity with the first trusted authority and to receive the first decryption key, or the first item, securely from the first trusted authority;second means for requesting either a second decryption key corresponding to the second encryption key string, or the second item in decrypted form, from an organisation 15 accredited by a second trusted authority which holds second private data related to the second public data, the second means being arranged to provide the second encryption key string to the organisation when making its request and being further arranged to authenticate the entity with the organisation and receive the second decryption key, or the second item, from the organisation;20 third means for using the first decryption key, or the first item, provided by the first trusted authority and the second decryption key, or the second item, provided by the organisation, to recover the target data.
  7. 36
    A computing entity for recovering target data provided in encrypted form as part of an data set that comprises first and second encrypted items both of which must be decrypted to recover the target data; the first item being encrypted in dependence on a first encryption 30 key string that identifies a specific individual, and first public data; and the second item being encrypted in dependence on a second encryption key that identifies a specific organisation and said specific individual, and second public data; the entity comprising:- first means for requesting either a first decryption key corresponding to the first encryption key, or the first item in decrypted form, from a first trusted authority which is competent in respect of the accreditation of professionals and holds first private data related to the first public data, the first means being arranged to provide the first encryption key string, or the first item, to the first trusted authority when making its request;- second means for requesting either a second decryption key corresponding to the second encryption key string, or the second item in decrypted form, from an organisation accredited by a second trusted authority which holds second private data related to the second public data, the second means being arranged to provide the second encryption key string to the organisation when making its request;and - third means for using the first decryption key, or the first item, provided by the first trusted authority and the second decryption key, or the second item, provided by the organisation, to recover the target data;at least one of the first means and the second means being arranged to authenticate the entity to the first trusted authority or said organisation as the case may be and to receive input therefrom in a secure manner.