WO2019017883A1 - Authentication of entitlement certificates - Google Patents

Authentication of entitlement certificates Download PDF

Info

Publication number
WO2019017883A1
WO2019017883A1 PCT/US2017/042412 US2017042412W WO2019017883A1 WO 2019017883 A1 WO2019017883 A1 WO 2019017883A1 US 2017042412 W US2017042412 W US 2017042412W WO 2019017883 A1 WO2019017883 A1 WO 2019017883A1
Authority
WO
WIPO (PCT)
Prior art keywords
authorisation
requests
certificate
administration
signing authority
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2017/042412
Other languages
French (fr)
Inventor
Joshua S Schiffman
Luke T. MATHER
Christopher C MOHMAN
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hewlett Packard Development Co LP
Original Assignee
Hewlett Packard Development Co LP
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hewlett Packard Development Co LP filed Critical Hewlett Packard Development Co LP
Priority to US16/077,689 priority Critical patent/US11354399B2/en
Priority to PCT/US2017/042412 priority patent/WO2019017883A1/en
Publication of WO2019017883A1 publication Critical patent/WO2019017883A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/45Structures or tools for the administration of authentication
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/604Tools and structures for managing or administering access control systems
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • H04L9/3268Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]

Definitions

  • D2D device to device
  • users or administrators can authorise a set of actions that devices can perform based on user or device policy that dictates the actions such authorisations confer.
  • a service provider device can contact a signing authority to authorise and produce an authentication certificate.
  • the service provider device can access a policy decision point using, for example, an online connection to an infrastructure portal to use authorisation encoding.
  • Figure 1 shows an apparatus for providing a set of certificates that encode authorisations according to an example
  • Figure 2 shows a flow chart of a method for providing a set of certificates that encode authorisations according to an example
  • Figure 3 shows an apparatus according to an example.
  • an example there is provided a method for an entitlement signing workflow to enable an administration device to collect multiple authorisation requests from devices wishing to use certain services or perform certain actions. That is, the administration device can collect multiple requests from devices wishing to obtain permission or authorization to use certain services or perform certain actions. Accordingly, certificates that encode these authorizations can be provided.
  • the requesting device need not have a persistent connection to an infrastructure as the certificate that encodes the permissions for the device can be requested and delivered by way of an administration apparatus that can act as an effective broker between the requesting device and a trusted certificate generating apparatus.
  • authorisation rights or permissions can be encoded in a certificate.
  • the requests for authorisation are tied to an identity of a device through a digital signature. This is done by signing the request with the private key of a device's public key pair. It can then be forwarded from the administration device to a signing authority in a single set
  • the signed requests and their contents which can be authorisation request parameters defining the scope of an authorisation request, can be authenticated and certificates encoding one or more permissions generated for the devices.
  • the certificates can be transmitted to the devices using a different communication path to the one used to deliver the requests to the signing authority (which itself need not be secure as a result of the initial request signing).
  • a request can be made using a low energy radio frequency communication protocol, and delivery of a certificate can be by made using a different radio frequency communication protocol such as WiFi for example.
  • either or both of the request and delivery pathways can use other wireless and/or hardwired communication protocols or methods, near field communication and so on.
  • an authorisation request parameter can provide an indication of the device's desired entitlement to use a service.
  • a parameter can indicate whether read and/or write access to a service is requested, or if a device requests access to or use of a particular node in a network and so on.
  • ASR authorisation signing requests
  • Devices that wish to generate authorisation signing requests (ASR), for use in a protocol using access control under a trusted third-party authority can leverage their pre-existing authenticated identity to sign their requests. These requests can be transferred using any means (manually, over peer-to-peer networks, or over an infrastructure LAN or WLAN connection for example) to a signing authority. The authority can produce signed entitlements and these can be returned to the requesting devices.
  • the disclosed method for provisioning devices with certificates means that a device does not have to have an online connection to an infrastructure portal.
  • the methods are suitable even when a device, or a set of many devices, require signed entitlements and are not in a position to directly connect to a signing authority.
  • the method can be used in scenarios where a service provider device does not have persistent access to a policy decision point, since the device can still benefit from authorization encoding.
  • the process of generating the certificates encoding permissions uses an administration apparatus as an intermediary to enable a device to indirectly make contact with a signing authority.
  • an authorized administrator's device can be used to collect requests from devices and forward the requests to a signing authority. Certificates encoding the permissions that were requested by the device can be generated by the signing authority, and the resulting certificates can then be returned to the requesting devices over a channel, which may or may not be the same as the channel over which the requests were initially communicated.
  • FIG. 1 is a schematic representation of an apparatus for providing a set of certificates encoding one or more authorisations or permissions according to an example.
  • Devices 100 have pre-existing identity certificates that have been signed by a trusted third-party authority.
  • the certificates contains a unique verification key or device key 105 associated with a corresponding signing key.
  • a device wishes to request an authorisation 110, it generates an authorisation request and signs the request with its private signing key.
  • the request can no longer be modified without detection by the authority.
  • This allows the request to be transported 115 via an administration apparatus 120 to a trusted signing authority 130 using any means since no security requirements need to be placed on the transport mechanism.
  • the requests can take any route from the requesting device to the authority.
  • the authority 130 When the authority 130 receives a request it verifies 135 the correctness of tiie signature as well as whether the auttrorisation(s) requested are acceptable. For example, the authority 130 can determine whether a requested authorisation accords with a set of allowable permissions for the device that may be preconfigured at the authority 130 and which may be periodically updated.
  • the authority If both checks pass, the authority generates a certificate 140 encoding the or each requested authorisation. This certificate can be transported 145, 150 via the administration apparatus 120 back to the requesting device 100 using any transport method.
  • the requesting device Upon receiving the certificate, the requesting device verifies the authority's signature within the certificate and whether the authorisations signed were those requested, if all checks pass, the device has been successfully provisioned with authorisations.
  • FIG. 2 shows a flow chart of a method for providing a set of certificates according to an example.
  • the trusted signing authority apparatus receives a request for authorisation to use or access a service or apparatus (e.g. a printer or network node) via the administration apparatus from the one or more devices.
  • the authority verifies the digital signatures applied to the requests.
  • one or more request parameters are validated.
  • the authority generates the certificates encoding the authorisations for each respective request from the one or more devices.
  • the certificates are transmitted via the administration apparatus back to the one or more devices that made the respective requests.
  • the method for providing a set of certificates encoding authorisations uses an administrator device provisioned with authorisations that allow it to read and write to a security policy nek. by a participating device.
  • These administrator devices can be mobile devices, such as phones and tablets, and can communicate with targets using a protocol such as Bluetooth Low Energy for example, which is a low energy radio frequency communication protocol.
  • the mobile devices may not always have an infrastructure connection available to an administrator portal. Accordingly, using pre-existing authenticated device identities, these devices can generate temporary requests offline. These requests can be collected by, for example, an administrator and transported on foot to an infrastructure connected portal. This portal can men complete the remainder of the process.
  • the method enables a set of requests to be collated and delivered to a signing authority in a single batch.
  • a signing authority may need to walk to an infrastructure connected machine. This is useful in a whole raft of office-of-the-future use cases. It enables a low-effort and seamless workflow for generating and authenticating short-lived entitlements for use in device administration, access and authorization protocols.
  • the method also allows for any transport protocol or method to be used to generate an entitlement signing request and a corresponding certificate.
  • This includes a sneakemet approach that is, the transfer of electronic information by physically moving media comprising the information, such as magnetic tape, flash drives or external hard drives and so on, from one device to another), which in turn enables a bulk collection and collation of requests that can be ferried to an authority in one go.
  • the method is suitable for deployment over a variety of different transport protocols, ranging from full infrastructure communication protocols, to peer-to-peer protocols, to manual transport on a physical device.
  • Examples in the present disclosure can be provided as methods, systems or machine-readable instructions.
  • Such machine-readable instructions may be included on a computer readable storage medium (including but not limited to disc storage, CD-ROM, optical storage, etc.) having computer readable program codes therein or thereon.
  • the machine-readable instructions may, for example, be executed by a device, an administration apparatus, a trusted signing authority apparatus, a general-purpose computer, a special purpose computer, an embedded processor or processors of other programmable data processing devices to realize the functions described in the description and diagrams.
  • a processor or processing apparatus may execute the machine- readable instructions.
  • modules of the administration apparatus or trusted signing authority apparatus may be implemented by a processor executing machine readable instructions stored in a memory, or a processor operating in accordance with instructions embedded in logic circuitry.
  • the term 'processor* is to be interpreted broadly to include a CPU. processing unit, ASIC, logic unit, or programmable gate set etc.
  • the methods and modules may all be performed by a single processor or divided amongst several processors.
  • Such machine-readable instructions may also be stored in a computer readable storage mat can guide the computer or other programmable data processing devices to operate in a specific mode.
  • the instructions may be provided on a non-transitory computer readable storage medium encoded with instructions, executable by a processor.
  • Figure 3 shows an example of an apparatus comprising a processor 350 associated with a memory 352.
  • the memory 352 comprises computer readable instructions 354 which are executable by the processor 350.
  • the instructions 354 comprise: instructions to receive requests;
  • Instruction to verify digital signatures applied to the requests by the devices instructions to validate one or more request parameters
  • Such machine-readable instructions may also be loaded onto a computer or other programmable data processing devices, so that the computer or other programmable data processing devices perform a series of operations to produce computer-implemented processing, thus the instructions executed on the computer or other programmable devices provide an operation for realizing functions specified by flow(s) in the flow charts and/or block(s) in the block diagrams.
  • teachings herein may be implemented in the form of a computer software product, the computer software product being stored in a storage medium and comprising a plurality of instructions for making a computer device implement the methods recited in the examples of the present disclosure.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Software Systems (AREA)
  • Computer Hardware Design (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • General Health & Medical Sciences (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • Automation & Control Theory (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

A method for providing a set of certificates encoding authorisations, the method comprising processing respective ones of multiple authorisation requests at a trusted signing authority apparatus to verify respective digital signatures applied to the requests, the multiple authorisation requests received over a first communication link between the trusted signing authority apparatus and an administration apparatus, validating one or more authorisation request parameters of respective ones of the authorisation requests, generating a certificate encoding an authorisation at the trusted signing authority apparatus and transmitting the generated certificate to the administration apparatus or a requesting apparatus over a second communication fink.

Description

AUTHENTICATION OF ENTITLEMENT CERTIFICATES
BACKGROUND
[0001] In a device to device (D2D) computing environment such as a smart office or home, users or administrators can authorise a set of actions that devices can perform based on user or device policy that dictates the actions such authorisations confer. A service provider device can contact a signing authority to authorise and produce an authentication certificate. The service provider device can access a policy decision point using, for example, an online connection to an infrastructure portal to use authorisation encoding.
BRIEF DESCRIPTION OF THE DRAWINGS
[0002] Various features of certain examples will be apparent from the detailed description which follows, taken in conjunction with the accompanying drawings, which together illustrate, by way of example only, a number of features, and wherein:
[0003] Figure 1 shows an apparatus for providing a set of certificates that encode authorisations according to an example;
[0004] Figure 2 shows a flow chart of a method for providing a set of certificates that encode authorisations according to an example; and
[0005] Figure 3 shows an apparatus according to an example.
DETAILED DESCRIPTION
[0006] In the following description, for purposes of explanation, numerous specific details of certain examples are set forth. Reference in the specification to "an example" or similar language means that a particular feature, structure, or characteristic described in connection with the example is included in at least that one example, but not necessarily in other examples. [0007] According to an example, there is provided a method for an entitlement signing workflow to enable an administration device to collect multiple authorisation requests from devices wishing to use certain services or perform certain actions. That is, the administration device can collect multiple requests from devices wishing to obtain permission or authorization to use certain services or perform certain actions. Accordingly, certificates that encode these authorizations can be provided. The requesting device need not have a persistent connection to an infrastructure as the certificate that encodes the permissions for the device can be requested and delivered by way of an administration apparatus that can act as an effective broker between the requesting device and a trusted certificate generating apparatus.
[0008] Therefore, according to an example, authorisation rights or permissions can be encoded in a certificate. The requests for authorisation are tied to an identity of a device through a digital signature. This is done by signing the request with the private key of a device's public key pair. It can then be forwarded from the administration device to a signing authority in a single set
[0009} In an example, the signed requests and their contents, which can be authorisation request parameters defining the scope of an authorisation request, can be authenticated and certificates encoding one or more permissions generated for the devices. The certificates can be transmitted to the devices using a different communication path to the one used to deliver the requests to the signing authority (which itself need not be secure as a result of the initial request signing). For example, a request can be made using a low energy radio frequency communication protocol, and delivery of a certificate can be by made using a different radio frequency communication protocol such as WiFi for example. Alternatively, either or both of the request and delivery pathways can use other wireless and/or hardwired communication protocols or methods, near field communication and so on.
[0010] In an example, an authorisation request parameter can provide an indication of the device's desired entitlement to use a service. For example, a parameter can indicate whether read and/or write access to a service is requested, or if a device requests access to or use of a particular node in a network and so on. [0011] Devices that wish to generate authorisation signing requests (ASR), for use in a protocol using access control under a trusted third-party authority can leverage their pre-existing authenticated identity to sign their requests. These requests can be transferred using any means (manually, over peer-to-peer networks, or over an infrastructure LAN or WLAN connection for example) to a signing authority. The authority can produce signed entitlements and these can be returned to the requesting devices.
[0012] The disclosed method for provisioning devices with certificates means that a device does not have to have an online connection to an infrastructure portal. The methods are suitable even when a device, or a set of many devices, require signed entitlements and are not in a position to directly connect to a signing authority.
[0013] The method can be used in scenarios where a service provider device does not have persistent access to a policy decision point, since the device can still benefit from authorization encoding. The process of generating the certificates encoding permissions uses an administration apparatus as an intermediary to enable a device to indirectly make contact with a signing authority.
[0014] In an example, an authorized administrator's device can be used to collect requests from devices and forward the requests to a signing authority. Certificates encoding the permissions that were requested by the device can be generated by the signing authority, and the resulting certificates can then be returned to the requesting devices over a channel, which may or may not be the same as the channel over which the requests were initially communicated.
[0015] Figure 1 is a schematic representation of an apparatus for providing a set of certificates encoding one or more authorisations or permissions according to an example. Devices 100 have pre-existing identity certificates that have been signed by a trusted third-party authority. The certificates contains a unique verification key or device key 105 associated with a corresponding signing key. When a device wishes to request an authorisation 110, it generates an authorisation request and signs the request with its private signing key. Thus, the request can no longer be modified without detection by the authority. This allows the request to be transported 115 via an administration apparatus 120 to a trusted signing authority 130 using any means since no security requirements need to be placed on the transport mechanism. The requests can take any route from the requesting device to the authority.
(0016] When the authority 130 receives a request it verifies 135 the correctness of tiie signature as well as whether the auttrorisation(s) requested are acceptable. For example, the authority 130 can determine whether a requested authorisation accords with a set of allowable permissions for the device that may be preconfigured at the authority 130 and which may be periodically updated.
[0017] If both checks pass, the authority generates a certificate 140 encoding the or each requested authorisation. This certificate can be transported 145, 150 via the administration apparatus 120 back to the requesting device 100 using any transport method.
[0018] Upon receiving the certificate, the requesting device verifies the authority's signature within the certificate and whether the authorisations signed were those requested, if all checks pass, the device has been successfully provisioned with authorisations.
[0019] Figure 2 shows a flow chart of a method for providing a set of certificates according to an example. At block 200 the trusted signing authority apparatus receives a request for authorisation to use or access a service or apparatus (e.g. a printer or network node) via the administration apparatus from the one or more devices. At block 210 the authority verifies the digital signatures applied to the requests. At block 220 one or more request parameters are validated. At block 230 the authority generates the certificates encoding the authorisations for each respective request from the one or more devices. At block 240 the certificates are transmitted via the administration apparatus back to the one or more devices that made the respective requests.
[0020] In an example, the method for providing a set of certificates encoding authorisations uses an administrator device provisioned with authorisations that allow it to read and write to a security policy nek. by a participating device. These administrator devices can be mobile devices, such as phones and tablets, and can communicate with targets using a protocol such as Bluetooth Low Energy for example, which is a low energy radio frequency communication protocol. The mobile devices may not always have an infrastructure connection available to an administrator portal. Accordingly, using pre-existing authenticated device identities, these devices can generate temporary requests offline. These requests can be collected by, for example, an administrator and transported on foot to an infrastructure connected portal. This portal can men complete the remainder of the process.
[0021] According to an example, the method enables a set of requests to be collated and delivered to a signing authority in a single batch. Thus, only one member of an IT department, for example, may need to walk to an infrastructure connected machine. This is useful in a whole raft of office-of-the-future use cases. It enables a low-effort and seamless workflow for generating and authenticating short-lived entitlements for use in device administration, access and authorization protocols. The method also allows for any transport protocol or method to be used to generate an entitlement signing request and a corresponding certificate. This includes a sneakemet approach (that is, the transfer of electronic information by physically moving media comprising the information, such as magnetic tape, flash drives or external hard drives and so on, from one device to another), which in turn enables a bulk collection and collation of requests that can be ferried to an authority in one go.
[0022] The method is suitable for deployment over a variety of different transport protocols, ranging from full infrastructure communication protocols, to peer-to-peer protocols, to manual transport on a physical device.
[0023] Examples in the present disclosure can be provided as methods, systems or machine-readable instructions. Such machine-readable instructions may be included on a computer readable storage medium (including but not limited to disc storage, CD-ROM, optical storage, etc.) having computer readable program codes therein or thereon.
[0024] The present disclosure is described with reference to flow charts and/or block diagrams of the method, devices and systems according to examples of the present disclosure. Although the flow diagrams described above show a specific order of execution, the order of execution may differ from that which is depicted. Bocks described in re!ation to one flow chart may be combined with those of another flow chart, in some examples, some blocks of the flow diagrams may not be necessary and/or additional blocks may be added. It shall be understood that each flow and/or block in the flow charts and/or block diagrams, as well as combinations of the flows and/or diagrams in the flow charts and/or block diagrams can be realized by machine readable instructions.
[0025] The machine-readable instructions may, for example, be executed by a device, an administration apparatus, a trusted signing authority apparatus, a general-purpose computer, a special purpose computer, an embedded processor or processors of other programmable data processing devices to realize the functions described in the description and diagrams. In particular, a processor or processing apparatus may execute the machine- readable instructions. Thus, modules of the administration apparatus or trusted signing authority apparatus may be implemented by a processor executing machine readable instructions stored in a memory, or a processor operating in accordance with instructions embedded in logic circuitry. The term 'processor* is to be interpreted broadly to include a CPU. processing unit, ASIC, logic unit, or programmable gate set etc. The methods and modules may all be performed by a single processor or divided amongst several processors.
[0026] Such machine-readable instructions may also be stored in a computer readable storage mat can guide the computer or other programmable data processing devices to operate in a specific mode.
[0027] For example, the instructions may be provided on a non-transitory computer readable storage medium encoded with instructions, executable by a processor.
[0028] Figure 3 shows an example of an apparatus comprising a processor 350 associated with a memory 352. The memory 352 comprises computer readable instructions 354 which are executable by the processor 350. The instructions 354 comprise: instructions to receive requests;
Instruction to verify digital signatures applied to the requests by the devices; instructions to validate one or more request parameters);
Instructions to generate certificates; and
instructions to transmit certificates.
[0029] Such machine-readable instructions may also be loaded onto a computer or other programmable data processing devices, so that the computer or other programmable data processing devices perform a series of operations to produce computer-implemented processing, thus the instructions executed on the computer or other programmable devices provide an operation for realizing functions specified by flow(s) in the flow charts and/or block(s) in the block diagrams.
[0030] Further, the teachings herein may be implemented in the form of a computer software product, the computer software product being stored in a storage medium and comprising a plurality of instructions for making a computer device implement the methods recited in the examples of the present disclosure.
[0031] While the method, apparatus and related aspects have been described with reference to certain examples, various modifications, changes, omissions, and substitutions can be made without departing from the spirit of the present disclosure. In particular, a feature or block from one example may be combined with or substituted by a feature/block of another example.
[0032] The word "comprising" does not exclude the presence of elements other than those listed in a claim, "a" or "an" does not exclude a plurality, and a single processor or other unit may fulfil the functions of several units recited in the claims.
[0033] The features of any dependent claim may be combined with the features of any of the independent claims or other dependent claims.

Claims

1. A method for providing a set of certificates encoding authorisations, the method comprising: processing respective ones of multiple authorisation requests at a trusted signing authority apparatus to verify respective digital signatures appiied to the requests, the multiple authorisation requests received over a first communication link between the trusted signing authority apparatus and an administration apparatus; validating one or more authorisation request parameters of respective ones of the authorisation requests; generating a certificate encoding an authorisation at the trusted signing authority apparatus; and transmitting the generated certificate to the administration apparatus or a requesting apparatus over a second communication link.
2. A method as claimed in claim 1, wherein an authorisation request parameter comprises an indication of a device's desired entitlement to use a service.
3. A method as claimed in claim 1, wherein processing respective ones of multiple authorisation requests at the trusted signing authority apparatus to verify respective digital signatures appiied to the requests further comprises verifying a digital signature of an authorisation request appiied to the authorisation using a private key of a device public key pair.
4. A method as claimed in claim 1 , further comprising signing an identity certificate for a device.
5. A method as claimed in claim 1, further comprising collating a set of generated certificates for transmission to the administration apparatus.
6. An administration apparatus to: receive an authorisation request from a device; collate the authorisation request with multiple other such requests from respective other devices to form a set of authorisation requests; and transmit the set of authorisation requests to a trusted signing authority apparatus.
7. An administration apparatus as claimed in claim 6, wherein the administration apparatus is provisioned with authorisation read and write to a security policy of a device.
8. An administration apparatus as claimed in claim 6, the administration apparatus to receive a certificate encoding an authorisation from the trusted signing authority apparatus; and transmit the certificate to the device.
9. A device comprising a processor to: generate an authorisation request for a certificate encoding an authorisation; and transmit the authorisation request to an administration device.
10. A device as claimed in claim 9, the processor to: apply a digital signature to the authorisation request using a private key of a device public key pair.
11. A device as claimed in claim 9, the device to: receive a certificate encoding an authorisation.
12. A device as claimed in claim 11 , the device to receive the certificate from the administration apparatus or a trusted signing authority apparatus.
13. A machine-readable storage medium encoded with instructions for providing a set of certificates encoding authorisations, the instructions executable by a processor of a trusted signing authority apparatus to cause the apparatus to: process respective ones of multiple authorisation requests to verify respective digital signatures applied to the requests, the multiple authorisation requests received over a first communication link between the trusted signing authority apparatus and an administration apparatus; validate one or more authorisation request parameters of respective ones of the authorisation requests; generate a certificate encoding an authorisation; and transmit the generated certificate to the administration apparatus or a requesting apparatus over a second communication link.
14. A machine-readable storage medium encoded with instructions as claimed in claim 13, comprising instructions further executable to: verify a digital signature of an authorisation request applied to the authorisation request using a private key of a device public key pair.
15. A machine-readable storage medium encoded with instructions as claimed in claim 13, comprising instructions further executable to: collate a set of generated certificates for transmission to the administration apparatus.
PCT/US2017/042412 2017-07-17 2017-07-17 Authentication of entitlement certificates Ceased WO2019017883A1 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
US16/077,689 US11354399B2 (en) 2017-07-17 2017-07-17 Authentication of entitlement certificates
PCT/US2017/042412 WO2019017883A1 (en) 2017-07-17 2017-07-17 Authentication of entitlement certificates

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/US2017/042412 WO2019017883A1 (en) 2017-07-17 2017-07-17 Authentication of entitlement certificates

Publications (1)

Publication Number Publication Date
WO2019017883A1 true WO2019017883A1 (en) 2019-01-24

Family

ID=65016087

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2017/042412 Ceased WO2019017883A1 (en) 2017-07-17 2017-07-17 Authentication of entitlement certificates

Country Status (2)

Country Link
US (1) US11354399B2 (en)
WO (1) WO2019017883A1 (en)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040025022A1 (en) * 2000-09-21 2004-02-05 Yach David P Code signing system and method
US20100150353A1 (en) * 2008-12-11 2010-06-17 International Business Machines Corporation Secure method and apparatus to verify personal identity over a network
US20110247055A1 (en) * 2008-06-02 2011-10-06 Microsoft Corporation Trusted device-specific authentication
US20140164764A1 (en) * 2012-12-11 2014-06-12 Rawllin International Inc. Assignment of digital signature and qualification for related services
RU2522024C2 (en) * 2012-10-15 2014-07-10 Общество С Ограниченной Ответственностью "Лаборатория Эландис" Method of signing electronic documents with analogue-digital signature with additional verification

Family Cites Families (16)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2378010A (en) * 2001-07-27 2003-01-29 Hewlett Packard Co Mulit-Domain authorisation and authentication
US8312262B2 (en) 2004-04-30 2012-11-13 Qualcomm Incorporated Management of signing privileges for a cryptographic signing service
US8090939B2 (en) * 2005-10-21 2012-01-03 Hewlett-Packard Development Company, L.P. Digital certificate that indicates a parameter of an associated cryptographic token
JP2011515743A (en) 2008-03-04 2011-05-19 アップル インコーポレイテッド Managing code entitlements for software developers in a secure operating environment
US8776186B2 (en) 2011-10-04 2014-07-08 Cleversafe, Inc. Obtaining a signed certificate for a dispersed storage network
US9613052B2 (en) * 2012-06-05 2017-04-04 International Business Machines Corporation Establishing trust within a cloud computing system
US9208350B2 (en) * 2013-01-09 2015-12-08 Jason Allen Sabin Certificate information verification system
US9223789B1 (en) * 2013-03-14 2015-12-29 Amazon Technologies, Inc. Range retrievals from archived data objects according to a predefined hash tree schema
JP2015115893A (en) * 2013-12-13 2015-06-22 富士通株式会社 COMMUNICATION METHOD, COMMUNICATION PROGRAM, AND RELAY DEVICE
GB2532926A (en) * 2014-11-27 2016-06-08 Ibm Managing time-dependent electronic files
US9838204B2 (en) 2015-05-14 2017-12-05 Verizon Patent And Licensing Inc. IoT communication utilizing secure asynchronous P2P communication and data exchange
MX373229B (en) * 2015-09-23 2020-04-27 Viasat Inc Speeding up online certificate status verification with an online suggestion service.
US10075549B2 (en) * 2016-01-25 2018-09-11 Quest Software Inc. Optimizer module in high load client/server systems
US10027491B2 (en) * 2016-03-30 2018-07-17 Airwatch Llc Certificate distribution using derived credentials
US11146406B2 (en) * 2017-07-26 2021-10-12 Hewlett-Packard Development Company, L.P. Managing entitlement
US11153100B2 (en) * 2019-11-18 2021-10-19 Microsoft Technology Licensing, Llc Achieving certificate pinning security in reduced trust networks

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20040025022A1 (en) * 2000-09-21 2004-02-05 Yach David P Code signing system and method
US20110247055A1 (en) * 2008-06-02 2011-10-06 Microsoft Corporation Trusted device-specific authentication
US20100150353A1 (en) * 2008-12-11 2010-06-17 International Business Machines Corporation Secure method and apparatus to verify personal identity over a network
RU2522024C2 (en) * 2012-10-15 2014-07-10 Общество С Ограниченной Ответственностью "Лаборатория Эландис" Method of signing electronic documents with analogue-digital signature with additional verification
US20140164764A1 (en) * 2012-12-11 2014-06-12 Rawllin International Inc. Assignment of digital signature and qualification for related services

Also Published As

Publication number Publication date
US11354399B2 (en) 2022-06-07
US20210200856A1 (en) 2021-07-01

Similar Documents

Publication Publication Date Title
EP3499847B1 (en) Efficient validation of transaction policy compliance in a distributed ledger system
CN116170803B (en) System and method for securely managing vehicle information
JP5944501B2 (en) Facilitating group access control for data objects in peer-to-peer overlay networks
KR102089833B1 (en) Secure wireless charging
CN104021333B (en) Mobile security watch bag
CN103209160B (en) A kind of authentication method and system towards heterogeneous network
CN112543927B (en) Equipment upgrading method and related equipment
CN111639327B (en) An open platform authentication method and device
CN114175578B (en) Share private information securely
CN114008968B (en) System, method, and storage medium for licensing authorization in a computing environment
CN113901432B (en) Blockchain identity authentication method, device, storage medium and computer program product
CN115758444A (en) Method and system for realizing block chain
CN109479049A (en) System, apparatus and method for key supply commission
Feng et al. Blockchain enabled zero trust based authentication scheme for railway communication networks
CN111049806B (en) Joint authority control method and device, electronic equipment and storage medium
CN105099673A (en) Authorization method, method and device for requesting authorization
US20190026458A1 (en) Remote processing of credential requests
CN110516417B (en) A kind of authority verification method and device for smart contract
CN117121435A (en) Connection elastic multi-factor authentication
CN116074023A (en) An authentication method and communication device
CN110278084A (en) EID method for building up, relevant device and system
CN113329003B (en) An access control method, user equipment and system for the Internet of Things
CN109840766B (en) Equipment control method and related equipment thereof
CN112235290A (en) Block chain-based Internet of things equipment management method and first Internet of things equipment
CN114499999B (en) Identity authentication methods, devices, platforms, vehicles, equipment and media

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17917949

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17917949

Country of ref document: EP

Kind code of ref document: A1