IP Library Granted Patent US 10,560,274
Granted Patent B2
US 10,560,274 · App. 15/177,391 · Granted Feb 11, 2020

Credential-based authorization

Inventors: Jan Camenisch (Thalwil, CH); Daniel Kovacs (Adliswil, CH); Kai Samelin (Rueschlikon, CH); Dieter M. Sommer (Zurich, CH)
Assignee: International Business Machines Corporation
H04L9/3263H04L9/14H04L9/30H04L63/0823H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,560,274
App. No.
15/177,391
Granted
Feb 11, 2020
Kind
B2
Abstract

Methods and systems are provided for demonstrating authorization to access a resource to a verifier computer controlling access to the resource. The method comprises, at a user computer, storing an attribute credential certifying a set of attributes; and communicating with a revocation authority computer to obtain an auxiliary credential, bound to the attribute credential, certifying a validity status for each attribute in the attribute credential. The method further comprises, at the user computer, communicating with the verifier computer to prove possession of the attribute credential and the auxiliary credential such that the verifier computer can determine whether at least one attribute in the attribute credential, certified as valid by the auxiliary credential, satisfies an access condition for the resource.

Claims (41)

1. A method comprising, at a user computer:

storing an attribute credential certifying a set of attributes, the set of attributes being a plurality of attributes;

communicating with a revocation authority computer to obtain an auxiliary credential, cryptographically bound to said attribute credential, certifying a validity status for each attribute in the attribute credential, wherein said auxiliary credential certifies, for each attribute of the plurality of attributes, validity status data indicating whether that attribute is valid or invalid, and wherein, through use of the auxiliary credential, attributes in the attribute credential can be revoked individually, leaving others still valid, without requiring re-issue of the attribute credential as a whole;

communicating with a verifier computer to prove possession of said attribute credential and said auxiliary credential such that the verifier computer is configured to determine whether at least one attribute in the attribute credential, certified as valid by the auxiliary credential, satisfies an access condition for a resource; and

accessing the resource in response to the verifier computer permitting access to the resource.

2. A method as claimed in claim 1 wherein the step of communicating with the verifier computer includes:

receiving from the verifier computer an access policy message indicating said access condition; and

proving to the verifier computer that at least one attribute in the attribute credential is certified as valid by the auxiliary credential and satisfies said access condition.

3. A method as claimed in claim 2 including, at the user computer:

generating a cryptographic proof demonstrating that at least one attribute in the attribute credential is certified as valid by the auxiliary credential and satisfies said access condition; and

sending the cryptographic proof to the verifier computer.

4. A method as claimed in claim 1 including, at the user computer, periodically communicating with the revocation authority computer to obtain said auxiliary credential.

5. A method as claimed in claim 1 , wherein the user computer proves possession of said attribute credential to the verifier computer in response to at least one attribute in the attribute credential being certified as invalid by the auxiliary credential.

6. The method of claim 1 , wherein the auxiliary credential is cryptographically bound to the attribute credential such that the auxiliary credential can only be validly used with the corresponding attribute credential.

7. A computer program product comprising a computer readable storage medium having program instructions embodied therein, the program instructions being executable by a user computer storing an attribute credential, certifying a set of attributes, the set of attributes being a plurality of attributes, to cause the user computer to:

communicate with a revocation authority computer to obtain an auxiliary credential, cryptographically bound to said attribute credential, certifying a validity status for each attribute in the attribute credential, wherein said auxiliary credential certifies, for each attribute of the plurality of attributes, validity status data indicating whether that attribute is valid or invalid, and wherein, through use of the auxiliary credential, attributes in the attribute credential can be revoked individually, leaving others still valid, without requiring re-issue of the attribute credential as a whole;

communicate with a verifier computer to prove possession of said attribute credential and said auxiliary credential such that the verifier computer is configured to determine whether at least one attribute in the attribute credential, certified as valid by the auxiliary credential, satisfies an access condition for a resource; and

accessing the resource in response to the verifier computer permitting access to the resource.

8. A computer program product as claimed in claim 7 wherein said program instructions are executable by the user computer to cause the user computer, in response to receipt from the verifier computer of an access policy message indicating said access condition, to prove to the verifier computer that at least one attribute in the attribute credential is certified as valid by the auxiliary credential and satisfies said access condition.

9. A computer program product as claimed in claim 8 wherein said program instructions are executable by the user computer to cause the user computer to:

generate a cryptographic proof demonstrating that at least one attribute in the attribute credential is certified as valid by the auxiliary credential and satisfies said access condition; and

send the cryptographic proof to the verifier computer.

10. A computer program product as claimed in claim 7 wherein said program instructions are executable by the user computer to cause the user computer to periodically communicate with the revocation authority computer to obtain said auxiliary credential.

11. A computer program product as claimed in claim 7 , wherein said program instructions are executable by the user computer to cause the user computer to prove possession of said attribute credential to the verifier computer in response to at least one attribute in the attribute credential being certified as invalid by the auxiliary credential.

12. A computer program product as claimed in claim 7 , wherein the auxiliary credential is cryptographically bound to the attribute credential such that the auxiliary credential can only be validly used with the corresponding attribute credential.

13. A computer system comprising:

a memory having computer program code; and

at least one processor, wherein the at least one processor, in response to retrieval and execution of the computer program code, causes the computer system to perform operations comprising:

storing an attribute credential certifying a set of attributes, the set of attributes being a plurality of attributes;

communicating with a revocation authority computer to obtain an auxiliary credential, cryptographically bound to said attribute credential, certifying a validity status for each attribute in the attribute credential, wherein said auxiliary credential certifies, for each attribute of the plurality of attributes, validity status data indicating whether that attribute is valid or invalid, and wherein, through use of the auxiliary credential, attributes in the attribute credential can be revoked individually, leaving others still valid, without requiring re-issue of the attribute credential as a whole;

communicating with a verifier computer to prove possession of said attribute credential and said auxiliary credential such that the verifier computer is configured to determine whether at least one attribute in the attribute credential, certified as valid by the auxiliary credential, satisfies an access condition for the resource; and

accessing the resource in response to the verifier computer permitting access to the resource.

14. An apparatus as claimed in claim 13 wherein the communicating with the verifier computer includes:

receiving from the verifier computer an access policy message indicating said access condition; and

proving to the verifier computer that at least one attribute in the attribute credential is certified as valid by the auxiliary credential and satisfies said access condition.

15. An apparatus as claimed in claim 14 wherein the at least one processor, in response to retrieval and execution of the computer program code, causes the computer system to perform operations comprising:

generating a cryptographic proof demonstrating that at least one attribute in the attribute credential is certified as valid by the auxiliary credential and satisfies said access condition; and

sending the cryptographic proof to the verifier computer.

16. An apparatus as claimed in claim 13 wherein the at least one processor, in response to retrieval and execution of the computer program code, causes the computer system to perform operations comprising: periodically communicating with the revocation authority computer to obtain said auxiliary credential.

17. An apparatus as claimed in claim 13 wherein the at least one processor, in response to retrieval and execution of the computer program code, causes the computer system to perform operations comprising: proving possession of said attribute credential to the verifier computer in response to at least one attribute in the attribute credential being certified as invalid by the auxiliary credential.

18. An apparatus as claimed in claim 13 wherein the auxiliary credential is cryptographically bound to the attribute credential such that the auxiliary credential can only be validly used with the corresponding attribute credential.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067801/0892 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067556/0783 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: GREEN MARKET SQUARE LIMITED
Reel/Frame 055078/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 9, 2016
From: CAMENISCH, JAN; KOVACS, DANIEL; SAMELIN, KAI; SOMMER, DIETER M.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 038852/0835 →
Continuity (1)
Related Publication 20170359184A1 · Dec 14, 2017