Apparatus and methods for managing key material in cryptographic assets
Abstract
Apparatus and methods for managing key material in cryptographic assets are disclosed. The methods can include defining first key material to be delivered to a cryptographic asset, wherein the first key material has a cryptoperiod having an expiration. Second key material to be delivered to the cryptographic asset is also defined. An automatic delivery of the second key material is scheduled such that the second key material will be delivered automatically to the cryptographic asset at or before the expiration of the cryptoperiod of the first key material. The methods can include defining a set of equipment classes, and registering at least one cryptographic asset with each equipment class. Cryptographic assets selected from the registered cryptographic assets are grouped into secure communication services, thereby defining secure communication interfaces between the cryptographic assets. Key material for each communications interface is defined, and an automatic delivery of the key material to the selected cryptographic assets is scheduled. The apparatus and methods of the invention provide an integrated key management system suitable for managing key material in a plurality of heterogeneous cryptographic assets from a single system.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method for managing key material in cryptographic assets, the method comprising:
defining first key material to be delivered to a cryptographic asset, wherein the first key material has a cryptoperiod having an expiration; defining second key material to be delivered to the cryptographic asset; and scheduling an automatic delivery of the second key material to the cryptographic asset such that the second key material will be delivered automatically to the cryptographic asset at or before the expiration of the cryptoperiod of the first key material.
2 . The method of claim 1 , further comprising:
associating a distribution method with the cryptographic asset; determining, based on the distribution method, a minimum lead time required to deliver the key material to the cryptographic asset; and scheduling the automatic delivery of the second key material to the cryptographic asset based on the distribution method and on the minimum lead time.
3 . The method of claim 1 , further comprising:
determining whether the key material was successfully delivered to the cryptographic asset; and if the key material was not successfully delivered to the cryptographic asset, then redelivering the key material to the cryptographic asset.
4 . The method of claim 1 , further comprising:
defining a set of equipment classes; registering at least one cryptographic asset with each equipment class; grouping selected cryptographic assets selected from the registered cryptographic assets into secure communication services, thereby defining secure communication interfaces between the cryptographic assets.
5 . The method of claim 1 , wherein defining the first or second key material includes receiving the first or second key material from a remote key management system.
6 . The method of claim 1 , wherein defining the first or second key material includes defining a number of keys to be delivered to the cryptographic asset and, for each key to be delivered, defining a key type.
7 . The method of claim 1 , further comprising:
encrypting the first or second key material under a protection key; and storing the encrypted first or second key material.
8 . A method for managing key material in a plurality of cryptographic assets having a communications interface defined therebetween, the method comprising:
defining a key management interface between a cryptographic processor and the cryptographic assets; generating, via the cryptographic processor, key material to secure the communications interface; and distributing the key material from the cryptographic processor to the cryptographic assets.
9 . A method for managing key material for cryptographic assets, comprising:
generating, via a cryptographic processor, key material for each of a plurality of heterogeneous cryptographic assets; and distributing the key material to the heterogeneous cryptographic assets via a key management interface coupled to the cryptographic processor.
10 . A method for managing key material in cryptographic assets, comprising:
generating first key material having a cryptoperiod; distributing the first key material to a cryptographic asset; monitoring the cryptographic asset to determine, based on the cryptoperiod, whether the first key material has expired; generating second key material for the cryptographic asset; and if the first key material has expired, automatically distributing the second key material to the cryptographic asset.
11 . A method for securing a communications interface, comprising:
defining a set of equipment classes; registering at least one cryptographic asset with each equipment class; grouping selected cryptographic assets selected from the registered cryptographic assets into secure communication services thereby defining secure communication interfaces between the cryptographic assets; defining key material for each communications interface; and scheduling an automatic delivery of the key material to the selected cryptographic assets.
12 . Apparatus for managing key material for cryptographic assets, comprising:
a cryptographic processor that generates key material for each of a plurality of heterogeneous cryptographic assets; and a controller having a key management interface, that receives the key material from the cryptographic processor and distributes the key material to the heterogeneous cryptographic assets via the key management interface.
13 . Apparatus for managing key material for cryptographic assets, comprising:
a cryptographic processor that defines first and second key material to be delivered to a cryptographic asset, wherein the first key material has a cryptoperiod having an expiration; and a controller that schedules an automatic delivery of the second key material to the cryptographic asset such that the second key material will be delivered automatically to the cryptographic asset at or before the expiration of the cryptoperiod.
14 . Apparatus for managing key material for cryptographic assets, comprising a computer readable medium having stored thereon computer executable instructions for:
defining a set of equipment classes; registering at least one cryptographic asset with each equipment class; grouping selected cryptographic assets selected from the registered cryptographic assets into secure communication services thereby defining secure communication interfaces between the cryptographic assets; defining key material for each communications interface; and scheduling an automatic delivery of the key material to the selected cryptographic assets.Join the waitlist — get patent alerts
Track US2002126849A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.