US2011078776A1PendingUtilityA1

Secure digital credential sharing arrangement

Assignee: BOYER JOHN JULES ALEXANDERPriority: Apr 6, 2005Filed: Aug 12, 2010Published: Mar 31, 2011
Est. expiryApr 6, 2025(expired)· nominal 20-yr term from priority
G06F 21/6245H04L 9/0836H04L 63/0428H04L 63/065H04L 63/062H04L 9/321H04L 63/104G06F 21/31G06F 2221/2147G06F 21/602
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A secure and transparent digital credential sharing arrangement which utilizes one or more cryptographic levels of indirection to obfuscate a sharing entity's credentials from those entities authorized to share the credentials. A security policy table is provided which allows the sharing entity to selectively authorize or revoke digital credential sharing among a plurality of entities. Various embodiments of the invention provide for secure storage and retrieval of digital credentials from security tokens such as smart cards. The secure sharing arrangement may be implemented in hierarchical or non-hierarchical embodiments as desired.

Claims

exact text as granted — not AI-modified
1 - 37 . (canceled) 
     
     
         38 . A method for sharing digital credentials, comprising:
 providing, in a computer readable storage medium, a first credential store having retrievably stored therein a plurality of credentials of a first entity;   sharing, with a second entity, a portion of the credentials of the first entity in response to a first secret that is generated using a common secret shared by the first entity and the second entity and using a first entity specific string retrievable by the second entity; and   providing the second entity with access rights to the portion of the credentials of the first entity that are shared with the second entity.   
     
     
         39 . The method according to  claim 38  wherein the portion of the credentials of the first entity is encoded using an algorithm which incorporates the first entity secret. 
     
     
         40 . The method according to  claim 38 , further comprising:
 combining the first entity specific string with the common secret.   
     
     
         41 . The method according to  claim 40  wherein combining includes at least one of: a hash operation, a concatenation operation, an exclusive OR operation and a symmetric cryptographic operation. 
     
     
         42 . The method according to  claim 38 , further comprising:
 encrypting the common secret with the first entity specific string.   
     
     
         43 . The method according to  claim 38  wherein first entity specific string includes at least one of: a user identifier, an IP address, a MAC address, random string, an identification number assigned to a security token, a static password, a hash of a static password, a passphrase, a PIN, and a cryptogram generated by a symmetric or asymmetric key. 
     
     
         44 . The method according to  claim 38 , further comprising:
 storing a plurality of credentials of the second entity;   sharing, with the first entity, a portion of the credentials of the second entity in response to a second secret that is generated using the common secret; and   providing the first entity with access rights to the portion of the credentials of the second entity that are shared with the first entity.   
     
     
         45 . The method according to  claim 44 , wherein the second secret is a function of the common secret and of a second entity specific string retrievable by the first entity. 
     
     
         46 . The method according to  claim 44  wherein the first secret and the second secret incorporate at least one level of indirection therebetween. 
     
     
         47 . The method according to  claim 44  wherein the first secret and the second secret incorporate a hierarchical structure and wherein the first secret may be used to derive said second secret but not vice versa. 
     
     
         48 . The method according to  claim 47  wherein the second secret is protected with the first secret. 
     
     
         49 . The method according to  claim 44  wherein the first secret and the second secret incorporate a hierarchical structure and wherein the second secret may be used to derive the first secret but not vice versa. 
     
     
         50 . The method according to  claim 49  wherein the first secret is protected with the second secret. 
     
     
         51 . The method according to  claim 43  wherein, on the second entity side, the common secret is stored encoded with said second secret. 
     
     
         52 . Computer software, provided in a computer-readable medium, that shares digital credentials, the software comprising:
 executable code that shares a portion of credentials of a first entity with a second entity in response to a first secret that is generated using a common secret shared by the first entity and the second entity and using a first entity specific string retrievable by the second entity; and   executable code that provides the second entity with access rights to the portion of the credentials of the first entity that are shared with the second entity.   
     
     
         53 . Computer software according to  claim 52  wherein the portion of the credentials of the first entity is encoded using an algorithm which incorporates the first entity secret. 
     
     
         54 . Computer software according to  claim 52 , further comprising:
 executable code that combines the first entity specific string with the common secret.   
     
     
         55 . Computer software according to  claim 54  wherein combining includes at least one of:
 a hash operation, a concatenation operation, an exclusive OR operation and a symmetric cryptographic operation. 
 
     
     
         56 . Computer software according to  claim 52 , further comprising:
 executable code that encrypts the common secret with the first entity specific string.   
     
     
         57 . Computer software according to  claim 52  wherein first entity specific string includes at least one of: a user identifier, an IP address, a MAC address, random string, an identification number assigned to a security token, a static password, a hash of a static password, a passphrase, a PIN, and a cryptogram generated by a symmetric or asymmetric key. 
     
     
         58 . Computer software according to  claim 52 , further comprising:
 executable code that stores a plurality of credentials of the second entity;   executable code that shares a portion of the credentials of the second entity with the first entity in response to a second secret that is generated using the common secret; and   executable code that provides the first entity with access rights to the portion of the credentials of the second entity that are shared with the first entity.   
     
     
         59 . Computer software according to  claim 58 , wherein the second secret is a function of the common secret and of a second entity specific string retrievable by the first entity. 
     
     
         60 . Computer software according to  claim 58  wherein the first secret and the second secret incorporate at least one level of indirection therebetween. 
     
     
         61 . Computer software according to  claim 58  wherein the first secret and the second secret incorporate a hierarchical structure and wherein the first secret may be used to derive said second secret but not vice versa. 
     
     
         62 . Computer software according to  claim 61  wherein the second secret is protected with the first secret. 
     
     
         63 . Computer software according to  claim 58  wherein the first secret and the second secret incorporate a hierarchical structure and wherein the second secret may be used to derive the first secret but not vice versa. 
     
     
         64 . Computer software according to  claim 63  wherein the first secret is protected with the second secret. 
     
     
         65 . Computer software according to  claim 57  wherein, on the second entity side, the common secret is stored encoded with said second secret.

Join the waitlist — get patent alerts

Track US2011078776A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.