Apparatus and methods for managing key material in cryptographic assets
Abstract
Apparatus and methods for managing key material in cryptographic assets are disclosed. The methods can include defining first key material to be delivered to a cryptographic asset, wherein the first key material has a cryptoperiod having an expiration. Second key material to be delivered to the cryptographic asset is also defined. An automatic delivery of the second key material is scheduled such that the second key material will be delivered automatically to the cryptographic asset at or before the expiration of the cryptoperiod of the first key material. The methods can include defining a set of equipment classes, and registering at least one cryptographic asset with each equipment class. Cryptographic assets selected from the registered cryptographic assets are grouped into secure communication services, thereby defining secure communication interfaces between the cryptographic assets. Key material for each communications interface is defined, and an automatic delivery of the key material to the selected cryptographic assets is scheduled. The apparatus and methods of the invention provide an integrated key management system suitable for managing key material in a plurality of cryptographic assets from a single system.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method for managing key material in a plurality of cryptographic assets, the method comprising:
defining, for each of the cryptographic assets, respective first key material to be delivered to the cryptographic assets, wherein the respective first key material has a cryptoperiod having an expiration; defining, for each of the cryptographic assets, respective second key material to be delivered to the cryptographic assets; maintaining a schedule for automatic delivery of the respective second key material to the cryptographic assets such that, for each said cryptographic asset, the respective second key material will be delivered automatically to the cryptographic asset at or before the expiration of the cryptoperiod of the respective first key material; and delivering the respective second key material to each of the cryptographic assets via an integrated key management system having a plurality of key management interfaces that couple the key management system to the plurality of cryptographic assets.
2 . The method of claim 1 , further comprising:
associating a distribution method with each of the cryptographic assets; determining, based on the associated distribution method, a minimum lead time required to deliver the second key material to the respective cryptographic asset; and scheduling the automatic delivery of the second key material based on the associated distribution methods and minimum lead times.
3 . The method of claim 1 , further comprising:
determining, for a selected cryptographic asset, whether the respective first or second key material was successfully delivered to the selected cryptographic asset; and if the respective first or second key material was not successfully delivered to the selected cryptographic asset, then redelivering the respective first or second key material to the selected cryptographic asset.
4 . The method of claim 1 , further comprising:
defining a set of equipment classes; registering at least one cryptographic asset with each equipment class; grouping selected cryptographic assets selected from the registered cryptographic assets into secure communication services, thereby defining secure communication interfaces between the cryptographic assets.
5 . The method of claim 1 , wherein defining the first or second key material includes receiving the first or second key material from a remote key management system.
6 . The method of claim 1 , wherein defining the respective first or second key material includes defining a number of keys to be delivered to the cryptographic asset and, for each key to be delivered, defining a key type.
7 . The method of claim 1 , further comprising:
encrypting the first or second key material under a protection key; and storing the encrypted first or second key material.
8 . A method for managing key material in a plurality of cryptographic assets, comprising:
generating, for each of the cryptographic assets, respective first key material having an associated cryptoperiod; distributing the respective first key material to the cryptographic assets; monitoring a selected cryptographic asset to determine, based on the associated cryptoperiod, whether the respective first key material has expired; generating second key material for the selected cryptographic asset; and if the respective first key material has expired, automatically delivering the second key material to the selected cryptographic asset via an integrated key management system having a plurality of key management interfaces that couple the key management system to the plurality of cryptographic assets.
9 . A method for securing a communications interface, comprising:
defining a set of equipment classes; registering at least one cryptographic asset with each equipment class; grouping selected cryptographic assets selected from the registered cryptographic assets into secure communication services thereby defining secure communication interfaces between the cryptographic assets; defining key material for each communications interface; maintaining a schedule for automatic delivery of the key material to the cryptographic assets; and delivering the key material to the cryptographic assets via an integrated key management system having a plurality of key management interfaces that couple the key management system to each of the cryptographic assets.
10 . A method for managing key material in a plurality of cryptographic assets, the method comprising:
defining, for each of the cryptographic assets, respective first key material to be delivered to the cryptographic assets, wherein the respective first key material has a cryptoperiod having an expiration; defining, for each of the cryptographic assets, respective second key material to be delivered to the cryptographic assets; maintaining a schedule for automatic delivery of the respective second key material to the cryptographic assets such that for each said cryptographic asset the respective second key material will be delivered automatically to the cryptographic asset at or before the expiration of the cryptoperiod of the respective first key material; and delivering the respective second key material to each of the cryptographic assets based on the schedule.Join the waitlist — get patent alerts
Track US2001026619A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.