WO2010150008A2

Method and system for provision of cryptographic services

Abstract

An encryption service system comprises an API for receiving requests from one or more calling applications. Each request comprises information identifying the operations to be performed on data to be processed and information identifying the origin and target of the data. The encryption service system further comprises a cryptographic server for processing the requests and determining, for each request, an encryption policy to be applied.

WO2010150008A2, drawing sheet 1
Sheet 1 of 6

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

61 claims: 31 independent, 30 dependent

  1. 1
    Claims 1. An encryption service system comprising:a. an application programming interface (API) for receiving encryption/decryption requests from one or more calling applications, each request comprising information identifying an encryption/decryption operation to be performed on specified data, and for sending output data in response to the corresponding encryption/decryption requests;and b. a cryptographic server for determining, for each request, an encryption policy to be applied to the encryption/decryption operation, and for generating said corresponding output data by applying the encryption/decryption operation to the specified data according to the determined encryption policy.
  2. 4
    The system of any preceding claim, wherein the encryption policy is determined at least in part on the basis of the operation to be performed.
  3. 5
    The system of any preceding claim, wherein the requests do not specify an encryption key and/or mechanism for the performance of the encryption/decryption operation.
  4. 6
    The system of any preceding claim, wherein the specified data is included within each request.
  5. 7
    The system of any preceding claim, wherein the operation is an encryption operation, and the encrypted output data comprises managed data.
  6. 9
    The system of any one of claims 1 to 6, wherein the operation is an encryption operation, and the encrypted output data comprises unmanaged data.
  7. 11
    The system of any preceding claim, further comprising a key server operable to receive a key request from the cryptographic server and to reply with an encrypted key.
  8. 14
    The system of any one of claims 9 to 13, wherein the key server is operable to send a query command to the cryptographic server.
  9. 17
    The system of any one of claims 9 to 16, wherein the key server is operable to send an action command to the cryptographic server.
  10. 20
    The system of any preceding claim, wherein the cryptographic server is operable to receive a pre- fetch request from one of said calling applications through the API and to load a defined set of keys into a local key store in response thereto.
  11. 23
    The encryption service system of any preceding claim, wherein the API is operable to allow a calling application to log on prior to requesting encryption/decryption services.
  12. 27
    The system of any one of claims 23 to 26, each when dependent on any one of claims 20 to 22, wherein the defined set of keys are cleared from local store when the corresponding calling application has logged off.
  13. 28
    An encryption service system comprising:a. an application programming interface (API) for receiving encryption/decryption requests from one or more calling applications, each request comprising information identifying an encryption/decryption operation to be performed on specified data;b. a cryptographic server for processing the requests;and c. a key server operable to receive a key request from the cryptographic server and to reply with an encrypted key;wherein the cryptographic server is operable to receive a pre-fetch request from one of said calling applications through the API and to load a defined set of keys from the key server into a local key store in response thereto.
  14. 29
    A calling application operable to request encryption/decryption services from the system of any preceding claim.
  15. 30
    A method of providing an encryption service comprising:a. receiving, at an application programming interface (API), encryption/decryption requests from one or more calling applications, each request comprising information identifying an encryption/decryption operation to be performed on specified input data;b. determining, at the cryptographic server, for each request, an encryption policy to be applied to the encryption/decryption operation;c. at the cryptographic server, for each request, performing the requested encryption/decryption operation on the input data according to the determined encryption policy, to generate corresponding output data;and d. outputting the corresponding output data at the application programming interface (API).
  16. 33
    The method of any one of claims 30 to 32, wherein the encryption policy is determined at least in part on the basis of the operation to be performed
  17. 34
    The method of any one of claims 30 to 33, wherein the requests do not specify an encryption key and/or mechanism for the performance of the encryption/decryption operation.
  18. 35
    The method of any one of claims 30 to 34, wherein the input data is included within each request.
  19. 36
    The method of anyone of claims 30 to 35, wherein the operation is an encryption operation, and the encrypted output data comprises managed data.
  20. 38
    The method of any one of claims 30 to 35, wherein the operation is an encryption operation, and the encrypted output data comprises unmanaged data.
  21. 40
    The method of any one of claims 30 to 39, further comprising receiving, at a key server, a key request from the cryptographic server and replying with an encrypted key.
  22. 43
    The method of any one of claims 40 to 42, further comprising sending, from the key server, a query command to the cryptographic server.
  23. 46
    The method of any one of claims 40 to 45, further comprising sending, from the key server, an action command to the cryptographic server.
  24. 49
    The method of any of claims 40 to 48, further comprising receiving, at the cryptographic server from one of said calling applications, a pre-fetch request and loading a defined set of keys into a local key store in response thereto.
  25. 52
    The method of any one of claims 40 to 51, further comprising a calling application logging on to the cryptographic server prior to requesting encryption services.
  26. 56
    The system of any one of claims 52 to 55, each when dependent on any one of claims 49 to 51, including clearing the defined set of keys from the local store when the corresponding calling application has logged off.
  27. 57
    A method of providing an encryption service comprising:a. receiving, at an application programming interface (API), encryption/decryption requests from one or more calling applications, each request comprising information identifying the operations to be performed on specified data;b. processing the requests at a cryptographic server;and c. receiving a key request from the cryptographic server at a key server, and sending an encrypted key from the key server to the cryptographic server in reply thereto;wherein the method includes receiving a pre-fetch request from one of said calling applications through the API and loading a defined set of keys from the key server into a local key store in response thereto.
  28. 58
    A computer program product comprising program code arranged to perform the method of any one of claims 30 to 57.
  29. 59
    A computer program product comprising program code arranged to perform the method as performed by the API in any one of claims 30 to 57.
  30. 60
    A computer program product comprising program code arranged to perform the method as performed by the cryptographic server in any one of claims 30 to 57.
  31. 61
    A computer program product comprising program code arranged to perform the method as performed by the key server in any one of claims 40 to 57. 
Independent claims31