WO2009141784A1

Identity-based encryption of data items for secure access thereto

Abstract

The invention uses the concept of identity-based encryption in the context of data-centric protection of electronic health records, where each data item is encrypted by using its own identifier as a public key. The corresponding decryption keys are managed by special trusted entities, which distribute the keys to authorized parties and provide logging facilities. This approach has the particular advantage that emergency access mechanisms can 5 be implemented in a secure and extremely efficient way. In contrast to previous approaches, itrequires no large-scale distribution of secret decryption keys. Furthermore, the scheme allows limiting the impact of a compromised decryption key, as one keycan onlybe used to decrypt one single document.

WO2009141784A1, drawing sheet 1
Sheet 1 of 2

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

11 claims: 3 independent, 8 dependent

  1. 1
    CLAIMS:1. A method of encrypting a data item (100) having an identifier (101) identifying the data item (100), the method comprising encrypting (103), using a symmetric encryption key (102), the data item (100) to obtain an encrypted data item (104), and encrypting (105), using the identifier (101) of the data item (100) as an encryption key, the symmetric encryption key (102) to obtain an encrypted encryption key (106).
  2. 2
    A method of decrypting an encrypted data item (104), the encrypted data item (104) being encrypted (103) using an encryption key (102), the encryption key (102) being encrypted (106), the method comprising providing a decryption key (201) for decrypting the encrypted encryption key (106), using the provided decryption key (201) for decrypting (202) the encrypted encryption key (106) to obtain the encryption key (102), and using the obtained encryption key (102) for decrypting (203) the encrypted data item (104) to obtain the data item (100).
  3. 9
    A method of digital rights management, DRM, the method comprising encrypting (103), using a symmetric encryption key (102), a data item (100) having an identifier (101) identifying the data item (100), to obtain an encrypted data item (104), and encrypting (105), using the identifier (101) of the data item (100) as an encryption key, the symmetric encryption key (102) to obtain an encrypted encryption key (106), receiving a request for a license to be issued to a requester to decrypt the encrypted data item (104), verifying whether the requester is properly authenticated, providing, if the requester is properly authenticated, a license including a decryption key (201) for decrypting the encrypted encryption key (106), logging data on the requester and the license, and issuing the license to the requester.