IP Library Granted Patent US 7,853,793
Granted Patent B2
US 7,853,793 · App. 10/838,642 · Granted Dec 14, 2010

Trusted signature with key access permissions

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,853,793
App. No.
10/838,642
Granted
Dec 14, 2010
Kind
B2
Abstract

Devices, methods, and computer code products are disclosed in which access to private keys required to create digital signatures for delimited information is controlled by permissions in the device. The permissions can be used to check the identity of an application to determine if the application has access to a digital key and permission to generate a digital signature.

Claims (23)

1. A non-transitory computer-readable medium having computer-readable instructions stored thereon that, upon execution by a processor, cause the processor to:

determine a hash value corresponding to information;

determine, based on a permission policy, whether an application associated with the information has permission to access at least one private key of a plurality of private keys, wherein the plurality of private keys are stored in a hierarchical namespace structure, and further wherein a single permission class of the permission policy is used to control access to the plurality of private keys within different parts of the hierarchical namespace structure; and

if the application has permission to access the private key, generate a digital signature with the private key, wherein the digital signature is based at least in part on the hash value.

2. The non-transitory computer-readable medium of claim 1 , wherein the plurality of private keys are stored on a smart card.

3. The non-transitory computer-readable medium of claim 1 , wherein the application is configured to present the information to a user through a user interface for delimiting.

4. The non-transitory computer-readable medium of claim 1 , wherein the processor is further caused to receive an identity of the application and compare the identity to the permission policy to determine whether the application has permission to access the private key.

5. The non-transitory computer-readable medium of claim 1 , wherein a second private key is stored at a second location and further wherein a second permission policy is used to control access to the second private key.

6. The non-transitory computer-readable medium of claim 1 , wherein the permission policy includes an identity of the application.

7. The non-transitory computer-readable medium of claim 1 , wherein the permission policy is established by an owner of the private key.

8. The non-transitory computer-readable medium of claim 1 , wherein the permission policy comprises an instance of a class of permission policies.

9. A method for generating a digital signature, the method comprising:

calculating a hash value corresponding to information;

determining, based on a permission policy, whether an application associated with the information has permission to access a private key of a plurality of private keys, wherein the plurality of private keys are stored in a hierarchical namespace structure, and further wherein a single permission class of the permission policy is used to control access to the plurality of private keys within different parts of the hierarchical namespace structure; and

if the application has permission to access the private key, using the private key to generate a digital signature based at least in part on the hash value.

10. The method of claim 9 , wherein determining whether the application has access to the private key is based at least in part on an identity of the application.

11. The method of claim 9 , further comprising providing the digital signature to the application.

12. The method of claim 9 , wherein the digital signature is generated by a cryptographic algorithm.

13. The method of claim 9 , further comprising determining, based on a second permission policy, whether the application has access to a second private key.

14. The method of claim 9 , further comprising providing the hash value and a key identifier corresponding to the private key to a cryptographic algorithm, wherein the cryptographic algorithm is used to generate the digital signature.

15. The method of claim 9 , further comprising employing a dedicated device manager to administer the permission policy, wherein the dedicated device manager is independent of the application.

16. The method of claim 9 , further comprising employing a security model to administer the permission policy, wherein the security model uses an identity of the application to determine whether the application has access to the private key.

17. The method of claim 9 , wherein determining whether the application has permission to access the private key is performed remotely.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2023
From: MIND FUSION, LLC
To: THINKLOGIX, LLC
Reel/Frame 064357/0554 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2023
From: INTELLECTUAL VENTURES ASSETS 191 LLC
To: MIND FUSION, LLC
Reel/Frame 064270/0685 →
SECURITY INTEREST Recorded Mar 24, 2023
From: MIND FUSION, LLC
To: INTELLECTUAL VENTURES ASSETS 191 LLC; INTELLECTUAL VENTURES ASSETS 186 LLC
Reel/Frame 063295/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2023
From: INTELLECTUAL VENTURES I LLC
To: INTELLECTUAL VENTURES ASSETS 191 LLC
Reel/Frame 062705/0781 →
MERGER Recorded Jul 22, 2011
From: SPYDER NAVIGATIONS L.L.C.
To: INTELLECTUAL VENTURES I LLC
Reel/Frame 026637/0611 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2007
From: NOKIA CORPORATION
To: SPYDER NAVIGATIONS L.L.C.
Reel/Frame 019893/0966 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2004
From: COFTA, PIOTR; IMMONEN, OLLI
To: NOKIA CORPORATION
Reel/Frame 015895/0402 →