Cryptographic key management

US11101997B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11101997-B2
Application numberUS-201916458733-A
CountryUS
Kind codeB2
Filing dateJul 1, 2019
Priority dateJul 1, 2019
Publication dateAug 24, 2021
Grant dateAug 24, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Cryptographic key provisioning by determining future cryptographic key demand according to historic key demand and key access requirements, determining cryptographic key provisioning resources for the future cryptographic key demand, and providing cryptographic keys, prior to the determined future cryptographic key demand using the cryptographic key provisioning resources.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer implemented method for cryptographic key provisioning, the method comprising: determining future cryptographic key demand according to historic key demand and key access requirements; determining cryptographic key provisioning resources for the future cryptographic key demand; provisioning cryptographic keys having a defined life-cycle, according to a user location; and providing cryptographic keys prior to the future cryptographic key demand using the cryptographic key provisioning resources. 2. The computer implemented method according to claim 1 , further comprising: identifying non-compliant system activity associated with cryptographic key demand, wherein the non-compliant system activity is not associated with the future cryptographic key demand; and refusing to provide a cryptographic key in response to the non-compliant system activity. 3. The computer implemented method according to claim 1 , further comprising: provisioning cryptographic keys according to a ranking function. 4. The computer implemented method according to claim 3 , wherein the ranking function is selected from the group consisting of: active time of a requesting entity, number of requests by the entity, average key usage time, and compliance level of the entity. 5. The computer implemented method according to claim 1 , further comprising provisioning cryptographic keys according to a threshold limit. 6. The computer implemented method according to claim 5 , wherein the threshold limit is based at least in part on a factor selected from the group consisting of: an entity ranking, and a total number of entities. 7. A computer program product for cryptographic key provisioning, the computer program product comprising one or more computer readable storage devices and stored program instructions on the one or more computer readable storage devices, the stored program instructions comprising: program instructions for determining future cryptographic key demand according to historic key demand and key access requirements; program instructions for determining cryptographic key provisioning resources for the future cryptographic key demand; program instructions for provisioning cryptographic keys having a defined life-cycle, according to a user location and program instructions for providing cryptographic keys prior to the future cryptographic key demand using the cryptographic key provisioning resources. 8. The computer program product according to claim 7 , the stored program instructions further comprising: program instructions for identifying a non-compliant system activity associated with cryptographic key demand, wherein the non-compliant system activity is not associated with the future cryptographic key demand; and program instructions for refusing to provide a cryptographic key in response to the non-compliant system activity. 9. The computer program product according to claim 7 , the stored program instructions further comprising program instructions for provisioning cryptographic according to a ranking function. 10. The computer program product according to claim 9 , wherein the ranking function is selected from the group consisting of: active time of a requesting entity, number of requests by the entity, average key usage time, and compliance level of the entity. 11. The computer program product according to claim 7 , the stored program instructions further comprising program instructions for provisioning cryptographic keys according to a threshold limit. 12. The computer program product according to claim 11 , wherein the threshold limit is based at least in part upon a factor selected from the group consisting of: an entity ranking, and a total number of entities. 13. A computer system for cryptographic key provisioning, the computer system comprising: one or more computer processors; one or more computer readable storage devices; and program instructions stored on the one or more computer readable storage devices for execution by the one or more computer processors, the stored program instructions comprising: program instructions for determining future cryptographic key demand according to historic key demand and key access requirements; program instructions for determining cryptographic key provisioning resources for the future cryptographic key demand; program instructions for provisioning cryptographic keys having a defined life-cycle, according to a user location; and program instructions for providing cryptographic keys prior to the future cryptographic key demand using the cryptographic key provisioning resources. 14. The computer system according to claim 13 , the stored program instructions further comprising: program instructions for identifying a non-compliant system activity associated with cryptographic key demand, wherein the non-compliant system activity is not associated with the future cryptographic key demand; and program instructions for refusing to provide a cryptographic key in response to the non-complaint system activity. 15. The computer system according to claim 13 , the stored program instructions further comprising program instructions for provisioning cryptographic according to a ranking function. 16. The computer system according to claim 15 , wherein the ranking function is selected from the group consisting of: active time of a requesting entity, number of requests by the entity, average key usage time, and compliance level of the entity. 17. The computer system according to claim 13 , the stored program instructions further comprising program instructions for provisioning cryptographic keys according to a threshold limit.

Assignees

Inventors

Classifications

  • H04L9/0894Primary

    Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage · CPC title

  • using geo-location information, e.g. location data, time, relative position or proximity to other entities · CPC title

  • H04L9/0861Primary

    Generation of secret information including derivation or calculation of cryptographic keys or passwords · CPC title

  • for supporting key management in a packet data network (cryptographic mechanisms or cryptographic arrangements for key management H04L9/08) · CPC title

  • Usage controlling of secret information, e.g. techniques for restricting cryptographic keys to pre-authorized uses, different access levels, validity of crypto-period, different key- or password length, or different strong and weak cryptographic algorithms (network architectures or network communication protocols for using time-dependent keys in a packet data network H04L63/068) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11101997B2 cover?
Cryptographic key provisioning by determining future cryptographic key demand according to historic key demand and key access requirements, determining cryptographic key provisioning resources for the future cryptographic key demand, and providing cryptographic keys, prior to the determined future cryptographic key demand using the cryptographic key provisioning resources.
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L9/0894. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Aug 24 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).