US2012272051A1PendingUtilityA1

Security key distribution in a cluster

Assignee: CHITTIGALA JES KIRANPriority: Apr 22, 2011Filed: Apr 22, 2011Published: Oct 25, 2012
Est. expiryApr 22, 2031(~4.8 yrs left)· nominal 20-yr term from priority
H04L 9/0825H04L 63/045
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Provided are techniques for the fast and reliable distribution of security keys within a cluster of computing devices, or computers. One embodiment provides a method for secure distribution of encryption keys, comprising generating a symmetric key for the encryption of communication among a plurality of nodes of a cluster of nodes; encrypting the symmetric key with a plurality of public keys, each public key corresponding to a particular node of the plurality of modes, to generate a plurality of encrypted symmetric keys; storing the plurality of encrypted symmetric keys in a central repository; and distributing the encrypted symmetric keys to the nodes such that each particular node receives an encrypted symmetric key corresponding to a corresponding public key of the particular node.

Claims

exact text as granted — not AI-modified
1 . A method for secure distribution of encryption keys, comprising:
 generating a symmetric key for the encryption of communication among a plurality of nodes of a cluster of nodes;   encrypting the symmetric key with a plurality of public keys, each public key corresponding to a particular node of the plurality of modes, to generate a plurality of encrypted symmetric keys;   storing the plurality of encrypted symmetric keys in a central repository; and   distributing the encrypted symmetric keys to the nodes such that each particular node receives an encrypted symmetric key corresponding to a corresponding public key of the particular node.   
     
     
         2 . The method of  claim 1 , the distributing comprising:
 notifying a particular node of the plurality of nodes of the availability of the corresponding encrypted symmetric key in the central repository;   retrieving by the particular node the corresponding encrypted symmetric key from the central repository; and   decrypting the corresponding encrypted symmetric key with a corresponding private key.   
     
     
         3 . The method of  claim 1 , the distributing comprising transmitting to each particular node, in conjunction with a notification of the generating, the corresponding encrypted symmetric key. 
     
     
         4 . The method of  claim 1 , further comprising:
 setting a timer corresponding to a period of time to wait between two successive generations of the symmetric key;   detecting an expiration of the timer; and   initiating the generating, encrypting, storing and distributing upon the detecting of the expiration of the timer.   
     
     
         5 . The method of  claim 4 , further comprising reinitializing the timer upon notification of a generation of a symmetric key. 
     
     
         6 . The method of  claim 5 , wherein the notification is initiated by a node of the plurality of nodes that is different than the node of the plurality of nodes that corresponds to the timer. 
     
     
         7 . The method of  claim 4 , wherein the period of time corresponding to the timer is different than a period of time corresponding to a corresponding plurality of timers corresponding to other nodes of the plurality of nodes. 
     
     
         8 - 21 . (canceled) 
     
     
         22 . A method for secure reception of an encryption key, comprising:
 receiving, by a node of a plurality of nodes of a cluster, notification of the generation of an encrypted symmetric key, encrypted with a public key corresponding to the node;   retrieving the encrypted key from a central repository of the cluster;   decrypting the encrypted symmetric key using a private key corresponding to the public key; and   employing, by the node, the decrypted symmetric key for communication within the cluster.   
     
     
         23 . The method of  claim 22 , further comprising:
 setting a timer corresponding to a period of time to wait between the receiving and a previous receiving of the symmetric key;   detecting an expiration of the timer; and, upon expiration of the timer, generating a new symmetric key for the encryption of communication among the plurality of nodes of a cluster of nodes;   encrypting the symmetric key with a plurality of public keys, each public key corresponding to a particular node of the plurality of modes, to generate a plurality of encrypted symmetric keys;   storing the plurality of encrypted symmetric keys in a central repository; and   distributing the encrypted symmetric keys to each node of the plurality nodes such that each particular node receives an encrypted symmetric key corresponding to a corresponding public key of the particular node.   
     
     
         24 . The method of  claim 23 , further comprising reinitializing the timer upon notification of the generation. 
     
     
         25 . The method of  claim 24 , wherein the notification is initiated by a node of the plurality of nodes that is different than the node of the plurality of nodes that corresponds to the timer.

Join the waitlist — get patent alerts

Track US2012272051A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.