Invention Grant
- Patent Title: Method for secure management of secrets in a hierarchical multi-tenant environment
-
Application No.: US16470358Application Date: 2017-12-14
-
Publication No.: US11463251B2Publication Date: 2022-10-04
- Inventor: Dominique Lacouture , Patrick Lambert , Daniel Rocha Furtado
- Applicant: GEMALTO SA
- Applicant Address: FR Meudon
- Assignee: GEMALTO SA
- Current Assignee: GEMALTO SA
- Current Assignee Address: FR Meudon
- Agency: The Jansson Firm
- Agent Pehr B. Jansson
- Priority: EP16205091 20161219
- International Application: PCT/EP2017/082779 WO 20171214
- International Announcement: WO2018/114574 WO 20180628
- Main IPC: H04L9/08
- IPC: H04L9/08

Abstract:
The present invention relates to a method of securely using a first tenant secret key stored under an encrypted form in a first token (TKA) of a first tenant (A) identified by a first tenant identifier (UIDA) and having said first tenant secret key, wherein: each tenant identifier (UIDT) for a tenant (T) comprises a first value and, when said tenant (T) is allowed to use a secret key of a parent tenant (Tp) identified by a parent tenant identifier (UIDTP), said parent tenant identifier, appended before said first value, and said first token (TKA) has been generated from said first tenant identifier (UIDA) and a first tenant secret key encrypted with said first tenant identifier (UIDA) and with a first tenant customer master key (CMKA), said first tenant customer master key (CMKA) having been derived from said first tenant identifier (UIDA) and a secure domain master key (SDMK), said method comprising the following steps performed by a secure device storing said secure domain master key (SDMK), on request of a second tenant (B) identified by a second tenant identifier (UIDB): —getting a first tenant identifier (UIDA) of said first tenant (A) from said first token (TKA), —checking if the first tenant identifier (UIDA) is a prefix of or is equal to said second tenant identifier (UIDB), —when said first tenant identifier (UIDA) is a prefix of or is equal to said second tenant identifier (UIDB), recovering said first tenant secret key stored in said first token (TKA) and using it for the second tenant (B).
Public/Granted literature
- US20200092096A1 METHOD FOR SECURE MANAGEMENT OF SECRETS IN A HIERARCHICAL MULTI-TENANT ENVIRONMENT Public/Granted day:2020-03-19
Information query