发明名称 Separating authorization identity from policy enforcement identity
摘要 The present invention extends to methods, systems, and computer program products for separating authorization identity from policy enforcement identity. Embodiments of the invention extend the consumption phase for protected information. Two identities, an authorization identity and a policy enforcement identity, are used for acquiring, issuing and enforcing usage license instead of one identity certificate. The authorization identity is used to evaluate against usage policy. The authorization identity is similar to identification information in an identity certificate. The policy enforcement identity is used to ensure the confidentiality of granted permissions and content key. The policy enforcement identity enforces a usage license on an authorization principal's (e.g., recipient's) machine. The policy enforcement identity's enforcement of a usage license is similar use of a cryptographic key in an identity certificate.
申请公布号 US8448228(B2) 申请公布日期 2013.05.21
申请号 US20100893763 申请日期 2010.09.29
申请人 ZHONG YUHUI;KOSTAL GREGORY;PATEL TEJAS D.;COTTRILLE SCOTT C.;YARMOLENKO VLADIMIR;KAMAT PANKAJ MOHAN;SAMUEL SUNITHA;BYRUM FRANK D.;MEHTA MAYANK;JAIN CHANDRESH KUMAR;BANTI EDWARD;MICROSOFT CORPORATION 发明人 ZHONG YUHUI;KOSTAL GREGORY;PATEL TEJAS D.;COTTRILLE SCOTT C.;YARMOLENKO VLADIMIR;KAMAT PANKAJ MOHAN;SAMUEL SUNITHA;BYRUM FRANK D.;MEHTA MAYANK;JAIN CHANDRESH KUMAR;BANTI EDWARD
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址