US2001026619A1PendingUtilityA1

Apparatus and methods for managing key material in cryptographic assets

Assignee: L 3 COMM CORPPriority: Oct 23, 1998Filed: May 30, 2001Published: Oct 4, 2001
Est. expiryOct 23, 2018(expired)· nominal 20-yr term from priority
H04L 9/50H04L 9/0891H04L 9/083H04L 2209/12G06Q 20/3829G07F 7/1008G07F 7/1016G06Q 20/40975G06F 21/602G06Q 20/02G06Q 20/3552G06F 2221/2107G06Q 20/341H04L 2209/56
41
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Apparatus and methods for managing key material in cryptographic assets are disclosed. The methods can include defining first key material to be delivered to a cryptographic asset, wherein the first key material has a cryptoperiod having an expiration. Second key material to be delivered to the cryptographic asset is also defined. An automatic delivery of the second key material is scheduled such that the second key material will be delivered automatically to the cryptographic asset at or before the expiration of the cryptoperiod of the first key material. The methods can include defining a set of equipment classes, and registering at least one cryptographic asset with each equipment class. Cryptographic assets selected from the registered cryptographic assets are grouped into secure communication services, thereby defining secure communication interfaces between the cryptographic assets. Key material for each communications interface is defined, and an automatic delivery of the key material to the selected cryptographic assets is scheduled. The apparatus and methods of the invention provide an integrated key management system suitable for managing key material in a plurality of cryptographic assets from a single system.

Claims

exact text as granted — not AI-modified
We claim:  
     
         1 . A method for managing key material in a plurality of cryptographic assets, the method comprising: 
 defining, for each of the cryptographic assets, respective first key material to be delivered to the cryptographic assets, wherein the respective first key material has a cryptoperiod having an expiration;    defining, for each of the cryptographic assets, respective second key material to be delivered to the cryptographic assets;    maintaining a schedule for automatic delivery of the respective second key material to the cryptographic assets such that, for each said cryptographic asset, the respective second key material will be delivered automatically to the cryptographic asset at or before the expiration of the cryptoperiod of the respective first key material; and    delivering the respective second key material to each of the cryptographic assets via an integrated key management system having a plurality of key management interfaces that couple the key management system to the plurality of cryptographic assets.    
     
     
         2 . The method of    claim 1   , further comprising: 
 associating a distribution method with each of the cryptographic assets;    determining, based on the associated distribution method, a minimum lead time required to deliver the second key material to the respective cryptographic asset; and    scheduling the automatic delivery of the second key material based on the associated distribution methods and minimum lead times.    
     
     
         3 . The method of    claim 1   , further comprising: 
 determining, for a selected cryptographic asset, whether the respective first or second key material was successfully delivered to the selected cryptographic asset; and    if the respective first or second key material was not successfully delivered to the selected cryptographic asset, then redelivering the respective first or second key material to the selected cryptographic asset.    
     
     
         4 . The method of    claim 1   , further comprising: 
 defining a set of equipment classes;    registering at least one cryptographic asset with each equipment class;    grouping selected cryptographic assets selected from the registered cryptographic assets into secure communication services, thereby defining secure communication interfaces between the cryptographic assets.    
     
     
         5 . The method of    claim 1   , wherein defining the first or second key material includes receiving the first or second key material from a remote key management system.  
     
     
         6 . The method of    claim 1   , wherein defining the respective first or second key material includes defining a number of keys to be delivered to the cryptographic asset and, for each key to be delivered, defining a key type.  
     
     
         7 . The method of    claim 1   , further comprising: 
 encrypting the first or second key material under a protection key; and    storing the encrypted first or second key material.    
     
     
         8 . A method for managing key material in a plurality of cryptographic assets, comprising: 
 generating, for each of the cryptographic assets, respective first key material having an associated cryptoperiod;    distributing the respective first key material to the cryptographic assets;    monitoring a selected cryptographic asset to determine, based on the associated cryptoperiod, whether the respective first key material has expired;    generating second key material for the selected cryptographic asset; and    if the respective first key material has expired, automatically delivering the second key material to the selected cryptographic asset via an integrated key management system having a plurality of key management interfaces that couple the key management system to the plurality of cryptographic assets.    
     
     
         9 . A method for securing a communications interface, comprising: 
 defining a set of equipment classes;    registering at least one cryptographic asset with each equipment class;    grouping selected cryptographic assets selected from the registered cryptographic assets into secure communication services thereby defining secure communication interfaces between the cryptographic assets;    defining key material for each communications interface;    maintaining a schedule for automatic delivery of the key material to the cryptographic assets; and    delivering the key material to the cryptographic assets via an integrated key management system having a plurality of key management interfaces that couple the key management system to each of the cryptographic assets.    
     
     
         10 . A method for managing key material in a plurality of cryptographic assets, the method comprising: 
 defining, for each of the cryptographic assets, respective first key material to be delivered to the cryptographic assets, wherein the respective first key material has a cryptoperiod having an expiration;    defining, for each of the cryptographic assets, respective second key material to be delivered to the cryptographic assets;    maintaining a schedule for automatic delivery of the respective second key material to the cryptographic assets such that for each said cryptographic asset the respective second key material will be delivered automatically to the cryptographic asset at or before the expiration of the cryptoperiod of the respective first key material; and    delivering the respective second key material to each of the cryptographic assets based on the schedule.

Join the waitlist — get patent alerts

Track US2001026619A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.