IP Library Granted Patent US 7,925,890
Granted Patent B2
US 7,925,890 · App. 11/551,746 · Granted Apr 12, 2011

Network centered recovery process for cryptographic processing modules

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,925,890
App. No.
11/551,746
Granted
Apr 12, 2011
Kind
B2
Abstract

A method is provided for re-initializing a cryptographic processing module ( 102 ) at a location designated as an unclassified environment. The method includes storing in a database ( 122 ) a module unique recovery vector ( 310, 510 ) assigned to a cryptographic processing module. The method also includes indexing the module unique recovery vector in the database using a unique module identifying code (for example, a serial number) assigned to the cryptographic processing module. The method further includes subsequently communicating the module unique recovery vector from the database, over a computer network ( 120 ), to a remote computing environment ( 400 ) that is unclassified. The module unique recovery vector is used to re-initialize the cryptographic processing module.

Claims (42)

1. A method for re-initializing a cryptographic processing module, comprising:

generating recovery information, at said cryptographic processing module located in a classified environment, that includes a module unique recovery vector and module unique data;

communicating said module unique recovery vector from said classified environment, over a computer network, to an unclassified network database;

storing in said unclassified network database said module unique recovery vector defining first re-initialization data that is required for re-activating previously deactivated information security functions of said cryptographic processing module at a future time and is functional only with one said cryptographic processing module for which it was uniquely generated;

indexing said module unique recovery vector in said unclassified network database using a unique module identifying code that identifies said cryptographic processing module;

relocating said cryptographic processing module from said classified environment to an unclassified environment;

subsequent to said relocation, communicating said module unique recovery vector from said unclassified network database, over said computer network, to said unclassified environment; and

using said module unique data and said module unique recovery vector provided from said unclassified network database to re-initialize said cryptographic processing module in said unclassified environment;

wherein said module unique data defines second re-initialization data that is required for re-activating said previously deactivated information security functions of said cryptographic processing module and is unique to said cryptographic processing module.

2. The method according to claim 1 , further comprising generating a new module unique recovery vector in said unclassified environment.

3. The method according to claim 1 , further comprising generating said module unique recovery vector in a cryptographic initialization process exclusively responsive to receipt of at least one initialization vector.

4. The method according to claim 1 , further comprising storing said module unique data in a storage device of said cryptographic processing module.

5. The method according to claim 1 , further comprising encrypting said module unique recovery vector prior to said communicating step.

6. The method according to claim 1 , further comprising querying said cryptographic processing module in said unclassified environment to obtain said unique module identifying code.

7. The method according to claim 1 , further comprising communicating said unique module identifying code from said unclassified environment to a server associated with said unclassified network database.

8. The method according to claim 7 , further comprising encrypting said unique module identifying code prior to communicating said unique module identifying code.

9. A method for re-initializing a cryptographic processing module, comprising:

generating recovery information, at said cryptographic processing module located in a classified environment, that includes a module unique recovery vector and module unique data;

communicating said module unique recovery vector from said classified environment, over a computer network, to an unclassified network database;

storing in said unclassified network database said module unique recovery vector defining first re-initialization data that is required for re-activating previously deactivated information security functions of said cryptographic processing module at a future time and is functional only with one said cryptographic processing module for which it was uniquely generated;

querying said cryptographic processing module to obtain a unique module identifying code that is assigned only to said cryptographic processing module;

communicating said unique module identifying code to said unclassified network database;

indexing said module unique recovery vector in said unclassified network database using said unique module identifying code;

relocating said cryptographic processing module from said classified environment to an unclassified environment;

subsequent to said relocation, communicating said module unique recovery vector from said unclassified network database, over a computer network, to said unclassified environment; and

using module unique data and said module unique recovery vector provided from said unclassified network database to re-initialize said cryptographic processing module in said unclassified environment;

wherein said module unique data defines second re-initialization data that is required for re-activating said previously deactivated information security functions of said cryptographic processing module and is unique to said cryptographic processing module.

10. The method according to claim 9 , further comprising generating a new module unique recovery vector in said unclassified environment.

11. The method according to claim 9 , further comprising generating said module unique recovery vector in a cryptographic re-initialization process exclusively responsive to receipt of at least one initialization vector.

12. A method for re-initializing a cryptographic processing module, comprising:

generating recovery information, at said cryptographic processing module located in a classified environment, that includes a module unique recovery vector and module unique data;

communicating said module unique recovery vector from said classified environment, over a computer network, to an unclassified network database;

storing in said unclassified network database said module unique recovery vector defining first re-initialization data that is required for re-activating previously deactivated information security functions of said cryptographic processing module at a future time and is functional only with one said cryptographic processing module for which it was uniquely generated;

querying said cryptographic processing module to obtain a unique module identifying code that is assigned only to said cryptographic processing module;

encrypting said unique module identifying code;

communicating said unique module identifying code from said cryptographic processing module, over a computer network, to said unclassified network database;

indexing said module unique recovery vector in said unclassified network database using said unique module identifying code;

encrypting said module unique recovery vector;

relocating said cryptographic processing module from said classified environment to an unclassified environment;

subsequent to said relocation, communicating said module unique recovery vector from said unclassified network database, over a computer network, to said unclassified environment; and

using said module unique data and said module unique recovery vector provided from said unclassified network database to re-initialize said cryptographic processing module in said unclassified environment;

wherein said module unique data defines second re-initialization data that is required for re-activating said previously deactivated information security functions of said cryptographic processing module and is unique to said cryptographic processing module.

Assignments (3)
CHANGE OF NAME Recorded Nov 19, 2018
From: HARRIS SOLUTIONS NY, INC.
To: HARRIS GLOBAL COMMUNICATIONS, INC.
Reel/Frame 047598/0361 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2018
From: HARRIS CORPORATION
To: HARRIS SOLUTIONS NY, INC.
Reel/Frame 047600/0598 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2006
From: DEVER, DONALD J.; MANN, IAN D.
To: HARRIS CORPORATION
Reel/Frame 018421/0351 →