System and method of enforcing a computer policy
Abstract
A method and system of enforcing a computer policy uses a central server to manage user profiles, policies and encryption keys. The server securely supplies the keys to client devices only after checking that the policy has been complied with. The checks include both the identity of the user and the machine identity of the client device. The keys are held in a secure environment of the client device, for example in a Trusted Platform Module (TPM), and remain inaccessible at all times to the end user. Theft or loss of a portable client device does not result in any encrypted data being compromised since the keys needed to decrypt that data are not extractable from the secure environment.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A cryptographic method, comprising:
generating a user-specific cryptographic key on a server; storing the user-specific cryptographic key, and policy data for controlling access to the user-specific cryptographic key, on the server; authenticating a user of a client device to the server; authenticating the client device to the server; processing the policy data on the server to determine whether the user is permitted to access the user-specific cryptographic key stored on the server; when permitted by the policy data, securely transmitting the user-specific cryptographic key from the server to the client device; and using the user-specific cryptographic key to perform a cryptographic operation on the client device without disclosing the user-specific cryptographic key to the user.
2 . The method of claim 1 , wherein the cryptographic operation comprises encrypting or decrypting data.
3 . The method of claim 1 , wherein the policy data defines which users can access the user-specific cryptographic key.
4 . The method of claim 1 , wherein the policy data defines which client devices can access the user-specific cryptographic key.
5 . The method of claim 1 , wherein the client device comprises a hardware security module, the method further comprising the client device using the hardware security module to authenticate the client device to the server.
6 . The method of claim 1 , comprising the client device using a hardware security module to perform the cryptographic operation.
7 . The method of claim 6 , wherein the hardware security module is a Trusted Platform Module.
8 . The method of claim 1 , further comprising the client device holding the user-specific cryptographic key in volatile memory and clearing the user-specific cryptographic key from the volatile memory after performing the cryptographic operation.
9 . The method of claim 1 , further comprising the server verifying integrity of the client device.
10 . The method of claim 1 , wherein the server generates the user-specific cryptographic key by generating an asymmetric key pair.
11 . A server configured to:
generate a user-specific cryptographic key; store the user-specific cryptographic key, and policy data for controlling access to the user-specific cryptographic key, on the server; authenticate a client device; authenticate a user of the client device; determine whether the user is permitted by the policy data to access the user-specific cryptographic key; and when permitted by the policy data, transmit the user-specific cryptographic key securely to the client device.
12 . The server of claim 11 , further configured to determine whether the client device is permitted by the policy data to access the user-specific cryptographic key.
13 . The server of claim 11 , further configured to verify integrity of the client device.
14 . The server of claim 11 , configured to generate the user-specific cryptographic key by generating an asymmetric key pair.
15 . The server of claim 11 , wherein the server is a web server.
16 . A system comprising:
a server; and a client device; wherein the server is configured to:
generate a user-specific cryptographic key;
store the user-specific cryptographic key, and policy data for controlling access to the user-specific cryptographic key, on the server;
authenticate the client device;
authenticate a user of the client device;
determine whether the user is permitted by the policy data to access the user-specific cryptographic key; and
when permitted by the policy data, transmit the user-specific cryptographic key securely to the client device, and
wherein the client device is configured to:
receive the user-specific cryptographic key from the server; and
use the user-specific cryptographic key to perform a cryptographic operation without disclosing the user-specific cryptographic key to the user.
17 . The system of claim 16 , wherein the cryptographic operation comprises encrypting or decrypting data.
18 . The server of claim 16 , wherein the client device stores sensitive data and wherein the policy data controls access to the sensitive data on the client device.
19 . The system of claim 16 , wherein the client device comprises a hardware security module, and wherein the server is configured to authenticate the client device by requesting the hardware security module on the client device to compute a signature using a private key belonging to the hardware security module.
20 . The system of claim 16 , wherein the client device is further configured to hold the user-specific cryptographic key in volatile memory, and clear the user-specific cryptographic key from the memory after performing the cryptographic operation.Join the waitlist — get patent alerts
Track US2019089527A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.