Patent · US Active

Separating authorization identity from policy enforcement identity

US8448228B2 · kind B2 · utility

4Cited by
3References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 29, 2010
Grant dateMay 21, 2013
Priority date
Expiry dateNov 30, 2031

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2463/101
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

The present invention extends to methods, systems, and computer program products for separating authorization identity from policy enforcement identity. Embodiments of the invention extend the consumption phase for protected information. Two identities, an authorization identity and a policy enforcement identity, are used for acquiring, issuing and enforcing usage license instead of one identity certificate. The authorization identity is used to evaluate against usage policy. The authorization identity is similar to identification information in an identity certificate. The policy enforcement identity is used to ensure the confidentiality of granted permissions and content key. The policy enforcement identity enforces a usage license on an authorization principal's (e.g., recipient's) machine. The policy enforcement identity's enforcement of a usage license is similar use of a cryptographic key in an identity certificate.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.