US2002126849A1PendingUtilityA1

Apparatus and methods for managing key material in cryptographic assets

Assignee: L 3 COMM CORPPriority: Oct 23, 1998Filed: Jan 31, 2001Published: Sep 12, 2002
Est. expiryOct 23, 2018(expired)· nominal 20-yr term from priority
H04L 9/50G07F 7/1016G07F 7/1008G06F 2221/2107G06Q 20/3552H04L 9/083G06Q 20/40975G06Q 20/341H04L 2209/56H04L 2209/12H04L 9/0891G06F 21/602G06Q 20/3829G06Q 20/02
41
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Apparatus and methods for managing key material in cryptographic assets are disclosed. The methods can include defining first key material to be delivered to a cryptographic asset, wherein the first key material has a cryptoperiod having an expiration. Second key material to be delivered to the cryptographic asset is also defined. An automatic delivery of the second key material is scheduled such that the second key material will be delivered automatically to the cryptographic asset at or before the expiration of the cryptoperiod of the first key material. The methods can include defining a set of equipment classes, and registering at least one cryptographic asset with each equipment class. Cryptographic assets selected from the registered cryptographic assets are grouped into secure communication services, thereby defining secure communication interfaces between the cryptographic assets. Key material for each communications interface is defined, and an automatic delivery of the key material to the selected cryptographic assets is scheduled. The apparatus and methods of the invention provide an integrated key management system suitable for managing key material in a plurality of heterogeneous cryptographic assets from a single system.

Claims

exact text as granted — not AI-modified
We claim:  
     
         1 . A method for managing key material in cryptographic assets, the method comprising: 
 defining first key material to be delivered to a cryptographic asset, wherein the first key material has a cryptoperiod having an expiration;    defining second key material to be delivered to the cryptographic asset; and    scheduling an automatic delivery of the second key material to the cryptographic asset such that the second key material will be delivered automatically to the cryptographic asset at or before the expiration of the cryptoperiod of the first key material.    
     
     
         2 . The method of  claim 1 , further comprising: 
 associating a distribution method with the cryptographic asset;    determining, based on the distribution method, a minimum lead time required to deliver the key material to the cryptographic asset; and    scheduling the automatic delivery of the second key material to the cryptographic asset based on the distribution method and on the minimum lead time.    
     
     
         3 . The method of  claim 1 , further comprising: 
 determining whether the key material was successfully delivered to the cryptographic asset; and    if the key material was not successfully delivered to the cryptographic asset, then redelivering the key material to the cryptographic asset.    
     
     
         4 . The method of  claim 1 , further comprising: 
 defining a set of equipment classes;    registering at least one cryptographic asset with each equipment class;    grouping selected cryptographic assets selected from the registered cryptographic assets into secure communication services, thereby defining secure communication interfaces between the cryptographic assets.    
     
     
         5 . The method of  claim 1 , wherein defining the first or second key material includes receiving the first or second key material from a remote key management system.  
     
     
         6 . The method of  claim 1 , wherein defining the first or second key material includes defining a number of keys to be delivered to the cryptographic asset and, for each key to be delivered, defining a key type.  
     
     
         7 . The method of  claim 1 , further comprising: 
 encrypting the first or second key material under a protection key; and    storing the encrypted first or second key material.    
     
     
         8 . A method for managing key material in a plurality of cryptographic assets having a communications interface defined therebetween, the method comprising: 
 defining a key management interface between a cryptographic processor and the cryptographic assets;    generating, via the cryptographic processor, key material to secure the communications interface; and    distributing the key material from the cryptographic processor to the cryptographic assets.    
     
     
         9 . A method for managing key material for cryptographic assets, comprising: 
 generating, via a cryptographic processor, key material for each of a plurality of heterogeneous cryptographic assets; and    distributing the key material to the heterogeneous cryptographic assets via a key management interface coupled to the cryptographic processor.    
     
     
         10 . A method for managing key material in cryptographic assets, comprising: 
 generating first key material having a cryptoperiod;    distributing the first key material to a cryptographic asset;    monitoring the cryptographic asset to determine, based on the cryptoperiod, whether the first key material has expired;    generating second key material for the cryptographic asset; and    if the first key material has expired, automatically distributing the second key material to the cryptographic asset.    
     
     
         11 . A method for securing a communications interface, comprising: 
 defining a set of equipment classes;    registering at least one cryptographic asset with each equipment class;    grouping selected cryptographic assets selected from the registered cryptographic assets into secure communication services thereby defining secure communication interfaces between the cryptographic assets;    defining key material for each communications interface; and    scheduling an automatic delivery of the key material to the selected cryptographic assets.    
     
     
         12 . Apparatus for managing key material for cryptographic assets, comprising: 
 a cryptographic processor that generates key material for each of a plurality of heterogeneous cryptographic assets; and    a controller having a key management interface, that receives the key material from the cryptographic processor and distributes the key material to the heterogeneous cryptographic assets via the key management interface.    
     
     
         13 . Apparatus for managing key material for cryptographic assets, comprising: 
 a cryptographic processor that defines first and second key material to be delivered to a cryptographic asset, wherein the first key material has a cryptoperiod having an expiration; and    a controller that schedules an automatic delivery of the second key material to the cryptographic asset such that the second key material will be delivered automatically to the cryptographic asset at or before the expiration of the cryptoperiod.    
     
     
         14 . Apparatus for managing key material for cryptographic assets, comprising a computer readable medium having stored thereon computer executable instructions for: 
 defining a set of equipment classes;    registering at least one cryptographic asset with each equipment class;    grouping selected cryptographic assets selected from the registered cryptographic assets into secure communication services thereby defining secure communication interfaces between the cryptographic assets;    defining key material for each communications interface; and    scheduling an automatic delivery of the key material to the selected cryptographic assets.

Join the waitlist — get patent alerts

Track US2002126849A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.