IP Library Patent Application 12102853
Patent Application
App. No. 12/102,853

Method and System for Identifying and Managing Keys

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
12/102,853
Abstract

A system and method for managing encryption keys, wherein one of more of they keys incorporates a disabled state, and wherein the system further incorporates a namespace.

Claims (40)

1 . A method of controlling use of an encryption key, wherein the encryption key resides in one or more key management servers in a key management system, the method comprising:

disabling the encryption key, wherein the disabling comprises:

deleting the encryption key from all cryptographic units; and

isolating the encryption key within the key management servers in the key management system, wherein isolating the encryption key comprises barring all access to the disabled encryption key.

2 . The method of claim 1 , further comprising:

determining whether the encryption key can be returned to a usable state, wherein the determining is performed by a user with appropriate credentials; and

if the encryption key can be activated, activating the encryption key for use by the cryptographic units by restoring the key to a usable state.

3 . The method of claim 2 , wherein a user with appropriate credentials comprises a key administrator or manager.

4 . The method of claim 2 , wherein a usable state comprises any state higher than the disabled state.

5 . The method of claim 2 , wherein a user with appropriate credentials is authorized to determine whether a disabled key can be activated with respect to a security policy associated with the encryption key.

6 . The method of claim 1 , further comprising:

splitting the disabled key into two or more component shares, and

storing each component share, wherein rights to each component share are given to an administrator or manager, wherein no administrator or manager has rights to more than one component share.

7 . The method of claim 6 , further comprising:

determining whether the encryption key can be returned to a usable state, wherein the determining is performed by a user with appropriate credentials; and

restoring the encryption key to a usable state, wherein restoring the encryption key comprises restoring two or more of the component shares.

8 . A method of identifying an object within a key management system, the method comprising:

creating a GUID for the object, wherein the GUID is represented by a URI, the URI comprising a prefix, a realm element, an object element, and a path element;

mapping the URI to one or more key management servers in the key management system; and

storing the object on the one or more key management servers in the key management system.

9 . The method of claim 6 , wherein the prefix is “km” or “kms”.

10 . The method of claim 6 , wherein the realm element comprises a name of a zone of authority within the key management system.

11 . The method of claim 6 , wherein the object element comprises an object space including any key under the control of the key management system.

12 . The method of claim 11 , wherein the object space is named one of “key”, “policy”, “client”, “group”, “pool”, “set”, “log”, “session”, or “.domain”.

13 . The method of claim 6 , wherein the object element comprises an object space including one of any key management policy, client, group, pool, set, log, or session.

14 . The method of claim 6 , wherein the object element comprises an object space reserved for the DNS domain.

15 . The method of claim 6 , wherein the path element comprises a multi-element path.

16 . The method of claim 15 , wherein the multi-element path defines a common default access control for the object.

17 . The method of claim 6 , wherein mapping comprises using KMSS or KMCS.

18 . The method of claim 6 , further comprising:

storing the object on one or more cryptographic units in the key management system.

19 . The method of claim 6 , further comprising:

storing the object on one or more KM Clients in the key management system.

20 . The method of claim 6 , further comprising:

distributing the object to one or more KM Clients in the key management system.

21 . A method of retrieving an object within a key management system, the method comprising:

receiving a URI for the object;

mapping the URI to one or more key management servers in the key management system; and

retrieving the object from one of the one or more key management servers in the key management system.

22 . The method of claim 21 , wherein mapping comprises using KMSS or KMCS.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2008
From: LOCKHART, ROBERT ADRIAN
To: NCIPHER CORPORATION LTD.
Reel/Frame 022042/0219 →