Security key distribution in a cluster
Abstract
Provided are techniques for the fast and reliable distribution of security keys within a cluster of computing devices, or computers. One embodiment provides a method for secure distribution of encryption keys, comprising generating a symmetric key for the encryption of communication among a plurality of nodes of a cluster of nodes; encrypting the symmetric key with a plurality of public keys, each public key corresponding to a particular node of the plurality of modes, to generate a plurality of encrypted symmetric keys; storing the plurality of encrypted symmetric keys in a central repository; and distributing the encrypted symmetric keys to the nodes such that each particular node receives an encrypted symmetric key corresponding to a corresponding public key of the particular node.
Claims
exact text as granted — not AI-modified1 . A method for secure distribution of encryption keys, comprising:
generating a symmetric key for the encryption of communication among a plurality of nodes of a cluster of nodes; encrypting the symmetric key with a plurality of public keys, each public key corresponding to a particular node of the plurality of modes, to generate a plurality of encrypted symmetric keys; storing the plurality of encrypted symmetric keys in a central repository; and distributing the encrypted symmetric keys to the nodes such that each particular node receives an encrypted symmetric key corresponding to a corresponding public key of the particular node.
2 . The method of claim 1 , the distributing comprising:
notifying a particular node of the plurality of nodes of the availability of the corresponding encrypted symmetric key in the central repository; retrieving by the particular node the corresponding encrypted symmetric key from the central repository; and decrypting the corresponding encrypted symmetric key with a corresponding private key.
3 . The method of claim 1 , the distributing comprising transmitting to each particular node, in conjunction with a notification of the generating, the corresponding encrypted symmetric key.
4 . The method of claim 1 , further comprising:
setting a timer corresponding to a period of time to wait between two successive generations of the symmetric key; detecting an expiration of the timer; and initiating the generating, encrypting, storing and distributing upon the detecting of the expiration of the timer.
5 . The method of claim 4 , further comprising reinitializing the timer upon notification of a generation of a symmetric key.
6 . The method of claim 5 , wherein the notification is initiated by a node of the plurality of nodes that is different than the node of the plurality of nodes that corresponds to the timer.
7 . The method of claim 4 , wherein the period of time corresponding to the timer is different than a period of time corresponding to a corresponding plurality of timers corresponding to other nodes of the plurality of nodes.
8 - 21 . (canceled)
22 . A method for secure reception of an encryption key, comprising:
receiving, by a node of a plurality of nodes of a cluster, notification of the generation of an encrypted symmetric key, encrypted with a public key corresponding to the node; retrieving the encrypted key from a central repository of the cluster; decrypting the encrypted symmetric key using a private key corresponding to the public key; and employing, by the node, the decrypted symmetric key for communication within the cluster.
23 . The method of claim 22 , further comprising:
setting a timer corresponding to a period of time to wait between the receiving and a previous receiving of the symmetric key; detecting an expiration of the timer; and, upon expiration of the timer, generating a new symmetric key for the encryption of communication among the plurality of nodes of a cluster of nodes; encrypting the symmetric key with a plurality of public keys, each public key corresponding to a particular node of the plurality of modes, to generate a plurality of encrypted symmetric keys; storing the plurality of encrypted symmetric keys in a central repository; and distributing the encrypted symmetric keys to each node of the plurality nodes such that each particular node receives an encrypted symmetric key corresponding to a corresponding public key of the particular node.
24 . The method of claim 23 , further comprising reinitializing the timer upon notification of the generation.
25 . The method of claim 24 , wherein the notification is initiated by a node of the plurality of nodes that is different than the node of the plurality of nodes that corresponds to the timer.Join the waitlist — get patent alerts
Track US2012272051A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.