US2016337326A1PendingUtilityA1
Systems and methods for managing cryptographic keys
Est. expirySep 14, 2027(~1.1 yrs left)· nominal 20-yr term from priority
H04L 63/18H04L 9/3213G06F 21/44H04L 9/0844G06F 21/45H04L 9/085H04L 9/083H04L 9/32H04L 63/0807H04L 63/0815G06F 21/606H04L 63/061
51
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A common interface for managing cryptographic keys is provided. A request to manage a cryptographic key may be received in a first interface format, translated to a common interface format, and then executed remotely from the first interface. Return arguments may then be translated from the common interface format to a format compatible with the first interface and communicated securely to the first interface. The cryptographic keys may be used in connection with a secure data parser that secures data by randomly distributing data within a data set into two or more shares.
Claims
exact text as granted — not AI-modified1 . (canceled)
2 . A method for managing cryptographic keys, the method comprising:
receiving, at a common interface using a hardware processor:
a first request from a first interface in a first interface format to manage at least one cryptographic key stored remotely from the first interface; and
a second request from a second interface in a second interface format to manage at least one cryptographic key stored remotely from the second interface;
translating each of the first request from the first interface format and the second request from the second interface format to a common interface format; authenticating the first and second requests by at least verifying that the requests originated from an authorized source; in response to verifying that the requests originated from an authorized source, storing a first authentication token for the first request and a second authentication token for the second request, wherein the first authentication token is usable to authenticate a subsequent request associated with the first request, and the second authentication token is usable to authenticate a subsequent request associated with the second request; and executing the first and second translated requests in the common interface format.
3 . The method of claim 2 , further comprising securing a data set using the at least one cryptographic key, wherein securing the data set comprises:
encrypting the data set using the at least one cryptographic key; generating a random or pseudo-random value; distributing, based, at least in part, on the random or pseudo-random value, encrypted data in the data set into two or more shares; and storing the two or more shares separately on at least one data depository.
4 . The method of claim 3 , wherein storing the two or more shares separately on at least one data depository comprises storing the two or more shares on at least two geographically separated data depositories.
5 . The method of claim 2 , further comprising:
translating at least one return argument of the executed requests from a common interface format to a first or second interface format; and sending the at least one return argument from the common interface to the first or second interface.
6 . The method of claim 5 , further comprising transmitting the at least one return argument to the first or second interface over a secure communications path.
7 . The method of claim 2 , wherein authenticating a respective one of the first request of or the second request comprises validating a corresponding one of the first authentication token or the second authentication token.
8 . The method of claim 7 , wherein validating a respective one of the first authentication token or the second authentication token comprises enforcing an expiration date or expiration time associated with a corresponding one of the first authentication token or the second authentication token.
9 . The method of claim 2 , further comprising determining whether an authentication token exists for each of the first request and the second request.
10 . The method of claim 9 , wherein in response to determining that an authentication token exists for each of the first request and the second request, the authenticating is bypassed.
11 . The method of claim 1 wherein the first interface format is different than the second interface format.
12 . A system for managing cryptographic keys, the system comprising:
a common interface having a hardware processor configured to:
receive a first request from a first interface in a first interface format to manage at least one cryptographic key stored remotely from the first interface;
receive a second request from a second interface in a second interface format to manage at least one cryptographic key stored remotely from the second interface;
translate each of the first request from the first interface format and the second request from the second interface format to a common interface format;
authenticate the first and second requests by at least verifying that the requests originated from an authorized source;
in response to verifying that the requests originated from an authorized source, store a first authentication token for the first request and a second authentication token for the second request, wherein the first authentication token is usable to authenticate a subsequent request associated with the first request and the second authentication token is useable to authenticate a subsequent request associated with the second request; and
execute the first and second translated requests in the common interface format.
13 . The system of claim 12 , the hardware processor is configured to secure a data set using the at least one cryptographic key by:
encrypting the data set using the at least one cryptographic key; generating a random or pseudo-random value; distributing, based, at least in part, on the random or pseudo-random value, encrypted data in the data set into two or more shares; and storing the two or more shares separately on at least one data depository.
14 . The system of claim 13 , wherein the hardware processor is configured to store the two or more shares separately on at least one data depository by storing the two or more shares on at least two geographically separated data depositories.
15 . The system of claim 12 , wherein the hardware processor is further configured to:
translate at least one return argument of the executed requests from a common interface format to a first or second interface format; and send the at least one return argument from the common interface to the first or second interface.
16 . The system of claim 15 , wherein the hardware processor is further configured to transmit the at least one return argument to the first or second interface over a secure communications path.
17 . The system of claim 12 , wherein the hardware processor is configured to authenticate a respective one of the first request or the second request by validating the corresponding first authentication token or the second authentication token.
18 . The system of claim 17 , wherein the hardware processor is further configured to enforce an expiration date or expiration time associated with the respective first authentication token or the second authentication token.
19 . The system of claim 12 , wherein the hardware processor is configured to determine whether an authentication token exists for each of the first request and the second request.
20 . The system of claim 19 , wherein in response to determining that an authentication token exists for each of the first request and the second request, the hardware processor is configured to bypass the authentication.
21 . The system of claim 12 , wherein the first interface format is different than the second interface format.Join the waitlist — get patent alerts
Track US2016337326A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.