IL160709A

Apparatus for and method of controlling propagation of decryption keys

Abstract

A security system for controlling access to encrypted information, comprising: a memory for storing at least one decryption key for use in decrypting an encrypted item of information, the decryption key being associated with a security code which can be used to determine whether the security system is authorized to send encrypted copies of the decryption key to others. If the security system is authorized to send an encrypted copy of the decryption key, it encrypts the decryption key and propagates the encrypted copy of the decryption key. Each time the security system propagates a decryption key, it includes as part of the decryption key an identifier indicating the identity of a sender's key. A user can append a control word against their identity in the decryption key to instruct the security system to initiate a message to them or an agent informing them of the propagation of the key and giving information concerning that propagation.

IL160709A, drawing sheet 1
Sheet 1 of 6

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

34 claims: 4 independent, 30 dependent

  1. 1
    WHAT IS CLAIMED IS:1. A security system for controlling access to encrypted information, comprising: a hardware device for storing at least one decryption key for use in decrypting an encrypted item of information, the decryption key being associated with a security code which is used by the hardware device to determine whether it is authorized to send encrypted copies of the decryption key to others, wherein if the hardware device is authorized to send an encrypted copy of the decryption key, it encrypts the decryption key and propagates the encrypted copy of the decryption key, wherein each time the hardware device propagates a decryption key, it includes as part of the decryption key an identifier indicating the identity of a sender’s key, and wherein a user appends a control word against their identity in the decryption key to instruct the hardware device to initiate a message to them or an agent informing them of the propagation of the key and giving information concerning that propagation.
  2. 13
    A method of controlling the propagation of a decryption key that allows access to encrypted data, the method comprising the steps of:associating the propagation control word with a decryption key for an item of data, and in response to an instruction to send the key to a specified recipient, checking the status of the control word to determine if propagation is allowed, and if so, modifying the control word and encrypting the control word and decryption key with a recipient’s public key and sending the encrypted key, including as part of the decryption key an identifier indicating the identity of a sender’s key, and appending a control word against a user’s identity in the decryption key to instruct a hardware device to initiate a message to them or an agent informing them of the propagation of the key and giving information concerning that propagation.
  3. 16
    A security system for controlling access to encrypted information by a plurality of users, comprising a hardware device for storing at least one data unit comprising a decryption key and an associated security code, in which the decryption key is used in decrypting an encrypted item of information and the security code controls the number of times that the decryption key can be propagated, and the hardware device examines the security code which code includes a group code as an indication of an acceptable range of recipients to determine whether it is authorized to send encrypted copies of the decryption key to those recipients, wherein if the hardware device is authorized to send an encrypted copy of the decryption key, it encrypts the decryption key and propagates the encrypted copy of the decryption key.
  4. 30
    A method of controlling the propagation of decryption keys to a plurality of users for allowing access to encrypted data, comprising the steps of storing at least one data unit on a hardware device, the at least one data unit comprising a decryption key, including a propagation control word with the decryption key in the data unit, and in response to an instruction to send the data unit to a specified recipient, checking the status of the control word to determine if propagation is allowed, including checking that the specified recipient is within an acceptable range of recipients indicated as a group code in the control word, and if so, modifying the control word and encrypting the data unit comprising the control word and decryption key with a recipient's public key and sending the data unit.