IP Library › Granted Patent US 12,554,869
Granted Patent B2
US 12,554,869 · App. 18/040,968 · Granted Feb 17, 2026

Device and a method for performing a cryptographic algorithm

Inventor: Richard John Kettlewell (Cambridge, GB)
Assignee: NCIPHER SECURITY LIMITED
G06F21/604G06F21/602G06F21/6209
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,554,869
App. No.
18/040,968
Granted
Feb 17, 2026
Kind
B2
Abstract

A computer implemented method comprising: obtaining first data, comprising a representation of computer program code that embodies a cryptographic algorithm; obtaining second data; receiving a request for a first mechanism to be performed, the request comprising information identifying the first mechanism, and information identifying the first data as corresponding to a program and the second data as corresponding to an input; performing the first mechanism, wherein performing the first mechanism comprises: performing a first determination, the first determination comprising: determining whether a first policy associated with the second data permits the second data to be used with the program represented in the first data, and determining whether a third policy associated with the computer program code permits the computer program code to be used with the second data; and if the first determination is successful, executing the program represented in the first data taking the second data as input.

Claims (92)

1 . A computer implemented method comprising:

obtaining first data, comprising a representation of computer program code that embodies a cryptographic algorithm;

obtaining second data;

receiving a request for a first mechanism to be performed, the request comprising information identifying the first mechanism, and information identifying the first data as corresponding to a program and the second data as corresponding to an input;

performing the first mechanism, wherein performing the first mechanism comprises:

performing a first determination, the first determination comprising:

determining whether a first policy associated with the second data permits the second data to be used with the program represented in the first data, and

determining whether a further policy associated with the computer program code permits the computer program code to be used with the second data; and

if the first determination is successful, executing the program represented in the first data taking the second data as input;

wherein the further policy is a third policy, and the computer implemented method further comprises obtaining third data, comprising a representation of output policy information;

wherein the request further comprises information identifying the third data as corresponding to a second policy; and

wherein performing the first mechanism further comprises associating the second policy with output data from the program.

2 . The computer implemented method according to claim 1 , wherein the first determination further comprises determining whether the first policy permits the second data to be used in the first mechanism.

3 . The computer implemented method according to claim 1 , wherein the first policy is a first access control list comprising a list of permissions relating to use of the second data.

4 . The computer implemented method according to claim 1 , wherein the third policy is a third access control list comprising a list of permissions relating to use of the program.

5 . The computer implemented method according to claim 1 , wherein the first determination further comprises determining whether the first policy permits the second data to be used with the output policy in the third data.

6 . The computer implemented method according to claim 1 , wherein the first determination further comprises determining whether a fourth policy associated with the output policy permits the output policy to be used with the program represented in the first data.

7 . The computer implemented method according to claim 1 , wherein the second data is a cryptographic key.

8 . The computer implemented method according to claim 1 , wherein the computer program code comprises one or more functions from a pre-determined set of functions.

9 . The computer implemented method according to claim 1 , further comprising:

generating the representation of computer program code that embodies the cryptographic algorithm at a first device;

sending the first data from the first device to a second device; and

performing the first mechanism at the second device.

10 . The computer implemented method according to claim 1 , further comprising:

obtaining fourth data;

wherein the request further comprises information identifying the fourth data as corresponding to input data, and wherein the request further defines a role of the second data and the fourth data;

wherein performing the first determination further comprises determining whether a fifth policy associated with the fourth data permits the fourth data to be used with the program represented in the first data.

11 . The computer implemented method according to claim 10 , wherein the first determination further comprises determining whether the fifth policy permits the fourth data to be used with the second data and/or determining whether the first policy permits the second data to be used with the fourth data.

12 . A device, comprising:

an interface configured to receive a request for a first mechanism to be performed, the request comprising information identifying the first mechanism, and information identifying first data as corresponding to a program and second data as corresponding to an input; and

a processor configured to:

obtain the first data, comprising a representation of computer program code that embodies one or more cryptographic operations, and obtain the second data;

perform the first mechanism, wherein performing the first mechanism comprises:

performing a first determination, the first determination comprising:

determining whether a first policy associated with the second data permits the second data to be used with the program represented in the first data, and

determining whether a further policy associated with the computer program code permits the computer program code to be used with the second data; and

if the first determination is successful, executing the program represented in the first data taking the second data as input;

wherein the further policy is a third policy, and the processor is further configured to obtain third data, comprising a representation of output policy information;

wherein the request further comprises information identifying the third data as corresponding to a second policy; and

wherein performing the first mechanism further comprises associating the second policy with output data from the program.

13 . A non-transitory computer readable storage medium comprising computer readable code configured to cause a computer to perform the following:

obtaining first data, comprising a representation of computer program code that embodies a cryptographic algorithm;

obtaining second data;

receiving a request for a first mechanism to be performed, the request comprising information identifying the first mechanism, and information identifying the first data as corresponding to a program and the second data as corresponding to an input;

performing the first mechanism, wherein performing the first mechanism comprises:

performing a first determination, the first determination comprising:

determining whether a first policy associated with the second data permits the second data to be used with the program represented in the first data, and

determining whether a further policy associated with the computer program code permits the computer program code to be used with the second data; and

if the first determination is successful, executing the program represented in the first data taking the second data as input;

wherein the further policy is a third policy, and the non-transitory computer readable storage medium further comprises computer readable code configured to cause a computer to obtain third data, comprising a representation of output policy information;

wherein the request further comprises information identifying the third data as corresponding to a second policy; and

wherein performing the first mechanism further comprises associating the second policy with output data from the program.

14 . A computer implemented method comprising:

obtaining first data, comprising a representation of computer program code that embodies a cryptographic algorithm;

obtaining second data;

receiving a request for a first mechanism to be performed, the request comprising information identifying the first mechanism, and information identifying the first data as corresponding to a program and the second data as corresponding to an input;

performing the first mechanism, wherein performing the first mechanism comprises:

performing a first determination, the first determination comprising:

determining whether a first policy associated with the second data permits the second data to be used with the program represented in the first data, and

determining whether a further policy associated with the computer program code permits the computer program code to be used with the second data; and

if the first determination is successful, executing the program represented in the first data taking the second data as input;

wherein the computer implemented method further comprises obtaining fourth data;

wherein the request further comprises information identifying the fourth data as corresponding to input data, and wherein the request further defines the role of the second data and the fourth data; and

wherein performing the first determination further comprises determining whether a fifth policy associated with the fourth data permits the fourth data to be used with the program represented in the first data.

15 . The computer implemented method according to claim 14 , wherein the first determination further comprises determining whether the fifth policy permits the fourth data to be used with the second data and/or determining whether the first policy permits the second data to be used with the fourth data.

16 . The computer implemented method according to claim 14 , wherein the first determination further comprises determining whether the first policy permits the second data to be used in the first mechanism.

17 . The computer implemented method according to claim 14 , wherein the first policy is a first access control list comprising a list of permissions relating to use of the second data.

18 . The computer implemented method according to claim 14 , wherein the further policy is a third policy, and the third policy is a third access control list comprising a list of permissions relating to use of the program.

19 . A device, comprising:

an interface configured to receive a request for a first mechanism to be performed, the request comprising information identifying the first mechanism, and information identifying first data as corresponding to a program and second data as corresponding to an input; and

a processor configured to:

obtain the first data, comprising a representation of computer program code that embodies one or more cryptographic operations, and obtain the second data;

perform the first mechanism, wherein performing the first mechanism comprises:

performing a first determination, the first determination comprising:

determining whether a first policy associated with the second data permits the second data to be used with the program represented in the first data, and

determining whether a further policy associated with the computer program code permits the computer program code to be used with the second data; and

if the first determination is successful, executing the program represented in the first data taking the second data as input;

wherein the processor is further configured to obtain fourth data;

wherein the request further comprises information identifying the fourth data as corresponding to input data, and wherein the request further defines the role of the second data and the fourth data; and

wherein performing the first determination further comprises determining whether a fifth policy associated with the fourth data permits the fourth data to be used with the program represented in the first data.

20 . A non-transitory computer readable storage medium comprising computer readable code configured to cause a computer to perform the following:

obtaining first data, comprising a representation of computer program code that embodies a cryptographic algorithm;

obtaining second data;

receiving a request for a first mechanism to be performed, the request comprising information identifying the first mechanism, and information identifying the first data as corresponding to a program and the second data as corresponding to an input;

performing the first mechanism, wherein performing the first mechanism comprises:

performing a first determination, the first determination comprising:

determining whether a first policy associated with the second data permits the second data to be used with the program represented in the first data, and

determining whether a further policy associated with the computer program code permits the computer program code to be used with the second data; and

if the first determination is successful, executing the program represented in the first data taking the second data as input;

wherein the non-transitory computer readable storage medium further comprises computer readable code configured to cause a computer to obtain fourth data;

wherein the request further comprises information identifying the fourth data as corresponding to input data, and wherein the request further defines the role of the second data and the fourth data; and

wherein performing the first determination further comprises determining whether a fifth policy associated with the fourth data permits the fourth data to be used with the program represented in the first data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 8, 2023
From: KETTLEWELL, RICHARD JOHN
To: NCIPHER SECURITY LIMITED
Reel/Frame 062621/0751 →
Priority Claims (1)
EP 20190045 · Aug 7, 2020 · regional
Continuity (1)
Related Publication 20230274008A1 · Aug 31, 2023
References Cited (8)
US 20060136332A1 · Ziegler · 2006 [cited by applicant]
US 20180367311A1 · Stahlberg · 2018 [cited by examiner]
US 20210406404A1 · Moran · 2021 [cited by examiner]
EP 2957063A1 · 2015 [cited by applicant]
WO 0042730A1 · 2000 [cited by applicant]
International Search Report and Written Opinion for PCT/GB2021/052035 (Oct. 29, 2021). [cited by applicant]
Search Report for European Patent Application No. 20190045.3 (Dec. 18, 2020). [cited by applicant]
International Preliminary Report on Patentability received for PCT Serial No. PCT/GB2021/052035 on Feb. 16, 2023, 10 pgs. [cited by applicant]