IP Library Patent Application 11570284
Patent Application
App. No. 11/570,284

Computing Device with a Process-Based Keystore and method for Operating a Computing Device

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/570,284
Abstract

A computing device is provided with a key manager which provides a mechanism for distinguishing between authorised use and unauthorized use of a cryptographic key by identifying an owning application for each key, which is authorised by the key manager to freely use a particular key, and is also trusted to ask for explicit confirmation from the user when considered appropriate, such as when the key is used in a signing operation. To allow for sharing of keys between applications, the owning application may be enabled to designate a list of other applications which are also trusted to use the key.

Claims (38)

1 . A computing device arranged to provide secure use of data for cryptographic operations by

a. keeping each item of the said data in a keystore;

b. assigning ownership of items in the keystore to respective processes;

c. enabling respective processes to assign another process as a user of respective items;

d. enabling respective processes to delete or modify respective items; and

e. denying access to items in the keystore to processes that neither own an item nor have been assigned as a user of an item.

2 . A device according to claim 1 wherein access to items in the keystore is controlled by a single keystore process.

3 . A device according to claim 1 wherein the keystore process comprises a server.

4 . A device according to claim 3 wherein the keystore server is arranged to control access to cryptographic data kept in a further device.

5 . A device according to claim 1 wherein the items kept in the keystore include either cryptographic keys or security certificates, or both.

6 . A device according to claim 1 wherein access to items in the keystore is further restricted by a requirement for an authentication of identity from a user of the device.

7 . A device according to claim 6 wherein user authentication is by means of at least one of

a. manual entry of a passphrase or a PIN; or

b. verification of biometric data.

8 . A device according to claim 6 wherein user authentication is valid for a limited period of time.

9 . A device according to claim 8 where the period for which user identification is valid is varied between different processes.

10 . A device according to claim 1 comprising multiple keystores each of which may have access controlled either by separate keystore process or by a central keystore process.

11 . A device according to claim 1 in which the deletion or removal of a process from the device is accompanied by the deletion or removal of all items owned by the said process.

12 . A method of operating a computing device for providing secure use of data for cryptographic operations, the method comprising

a. keeping each item of the said data in a keystore;

b. assigning ownership of items in the keystore to respective processes;

c. enabling respective processes to assign another process as a user of respective items;

d. enabling respective processes to delete or modify respective items; and

e. denying access to items in the keystore to processes that neither own an item nor have been assigned as a user of an item.

13 . A method according to claim 12 wherein access to items in the keystore is controlled by a single keystore process.

14 . A method according to claim 12 wherein the keystore process comprises a server.

15 . A method according to claim 14 wherein the keystore server is arranged to control access to cryptographic data kept in a further device.

16 . A method according to claim 12 wherein the items kept in the keystore include either cryptographic keys or security certificates or both.

17 . A method according to claim 12 wherein access to items in the keystore is further restricted by a requirement for an authentication of identity from a user of the device.

18 . A method according to claim 17 wherein user authentication is by means of at least one of

a. manual entry of a passphrase or a PIN; or

b. verification of biometric data.

19 . A method according to claim 17 wherein user authentication is arranged to be valid for a limited period of time.

20 . A method according to claim 19 wherein the period for which user identification is valid is varied between different processes.

21 . A method according to claim 12 comprising using multiple keystores each of which has access controlled either by a separate keystore process or by a central keystore process.

22 . A method according to claim 12 in which the deletion or removal of a process from the device is accompanied by the deletion or removal of all items owned by the said process.

23 . An operating system for a computing device according to claim 1 .

24 . An operating system for causing a computing device to operate according to the steps of claim 12.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2009
From: SYMBIAN LIMITED; SYMBIAN SOFTWARE LIMITED
To: NOKIA CORPORATION
Reel/Frame 022240/0266 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 19, 2007
From: CLARKE, LEON; HEATH, CRAIG
To: SYMBIAN SOFTWARE LTD.
Reel/Frame 019447/0500 →