Systems and methods for managing cryptographic keys

US9397827B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9397827-B2
Application numberUS-201213403142-A
CountryUS
Kind codeB2
Filing dateFeb 23, 2012
Priority dateSep 14, 2007
Publication dateJul 19, 2016
Grant dateJul 19, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A common interface for managing cryptographic keys is provided. A request to manage a cryptographic key may be received in a first interface format, translated to a common interface format, and then executed remotely from the first interface. Return arguments may then be translated from the common interface format to a format compatible with the first interface and communicated securely to the first interface. The cryptographic keys may be used in connection with a secure data parser that secures data by randomly distributing data within a data set into two or more shares.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for managing cryptographic keys, the method comprising: receiving at a common interface by using a hardware processor a first request from a first interface in a first interface format to manage at least one cryptographic key stored remote from the first interface, wherein the common interface is useable of recognizing a plurality of interface formats including the first interface format: translating the first request from the first interface format to a common interface format; in response to determining that a first authentication token associated with the first interface is not available, authenticating the first request by at least verifying that the first request originated from an authorized source and storing an authentication token for the first request, wherein the authentication token is usable to authenticate a subsequent request associated with the first interface; in response to determining that a first authentication token associated with the first interface is available, bypassing the authenticating step; accessing the at least one cryptographic key from a key store; executing the first translated. request in the common interface format; translating at least one return argument of the request from the common interface format to the first interface format; and sending the at least one return argument from the common interface to the first interface. 2. The method of claim 1 wherein executing the translated request comprises retrieving the at least one cryptographic key. 3. The method of claim 1 wherein executing the translated request comprises generating the at least one cryptographic key. 4. The method of claim 1 wherein executing the translated request comprises deleting the at least one cryptographic key. 5. The method of claim 1 wherein executing the translated request comprises storing the at least one cryptographic key in a key store. 6. The method of claim 1 wherein executing the translated request comprises storing the at least one cryptographic key on removable media. 7. The method of claim 1 further comprising securing a data set using the at least one cryptographic key, wherein securing the data set comprises: encrypting the data set using the at least one cryptographic key; generating a random or pseudo-random value; distributing, based, at least in part, on the random or pseudorandom value, encrypted data in the data set into two or more shares; and storing the two or more shares separately on at least one data depository. 8. The method of claim 7 wherein storing the two or more shares separately on at least one data depository comprises storing the two or more shares on at least two geographically separated data depositories. 9. The method of claim 1 wherein the at least one return argument of the executed request comprises at least one cryptographic key. 10. The method of claim 1 further comprising transmitting the at least one return argument to the first interface over a secure communications path. 11. The method of claim 1 wherein authenticating the request comprises implementing an authentication protocol or cryptographic handshake. 12. The method of claim 1 wherein authenticating the request comprises verifying a cryptographic signature associated with the request. 13. The method of claim 1 further comprising validating the authentication token. 14. The method of claim 13 wherein validating the authentication token comprises enforcing an expiration date or expiration time associated with the authentication token.

Assignees

Inventors

Classifications

  • H04L63/061Primary

    for key exchange, e.g. in peer-to-peer networks (cryptographic mechanisms or cryptographic arrangements for key agreement H04L9/0838) · CPC title

  • H04L9/083Primary

    involving central third party, e.g. key distribution center [KDC] or trusted third party [TTP] · CPC title

  • Structures or tools for the administration of authentication · CPC title

  • Secret sharing or secret splitting, e.g. threshold schemes · CPC title

  • with user authentication or key authentication, e.g. ElGamal, MTI, MQV-Menezes-Qu-Vanstone protocol or Diffie-Hellman protocols using implicitly-certified keys · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9397827B2 cover?
A common interface for managing cryptographic keys is provided. A request to manage a cryptographic key may be received in a first interface format, translated to a common interface format, and then executed remotely from the first interface. Return arguments may then be translated from the common interface format to a format compatible with the first interface and communicated securely to the …
Who is the assignee on this patent?
O'Hare Mark S, Orsini Rick L, Davenport Roger S, and 1 more
What technology area does this patent fall under?
Primary CPC classification H04L63/061. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 19 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).