IP Library Granted Patent US 8,731,200
Granted Patent B2
US 8,731,200 · App. 12/770,928 · Granted May 20, 2014

Key distribution

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,731,200
App. No.
12/770,928
Granted
May 20, 2014
Kind
B2
Abstract

Methods and systems are provided for trusted key distribution. A key distribution or an identity service acts as an intermediary between participants to a secure network. The service provisions and manages the distribution of keys. The keys are used for encrypting communications occurring within the secure network.

Claims (29)

1. A machine-implemented method to execute on a router, comprising:

servicing, by the router, network transactions for a participant in a homogeneous network, the network transactions are encrypted with a first key;

detecting, by the router, a transition of the participant to a neighboring network serviced by a neighboring service provider, the neighboring network is a heterogeneous network;

contacting, by the router, the neighboring service provider on behalf of the participant to acquire a second key for use with other network transactions serviced through the neighboring service provider, the other network transactions are encrypted with the second key;

distributing, by the router, the second key to the participant for transitioning to the participant to the neighboring service provider, the second key acquired by the participant in advance of communication being lost by the participant with the homogeneous network and communicating, by the router, changed communication keys made by the participant to each of other participants associated with the homogenous or heterogeneous networks; and

managing, by the router, key policies for both the homogeneous and the heterogeneous networks to ensure key entropy has not degraded beyond a predefined threshold, the key entropy referring to a length of time that the key is considered safe for usage based on: the length of the key, a total amount of network traffic that the key is used for encryption, and a repetitive nature of encrypted traffic using the key.

2. The method of claim 1 , wherein detecting further includes noticing a degradation in signal strength from the participant indicating the transition is approaching.

3. The method of claim 1 , wherein contacting further includes authenticating to the neighboring service provider.

4. The method of claim 1 , wherein contacting further includes authenticating to an identity service for acquiring an authentication mechanism which is processed to authenticate to the neighboring service provider.

5. The method of claim 1 , wherein contacting further includes acquiring the second key from an identity service.

6. The method of claim 1 further comprising, determining, by the router, an identity for the neighboring service provider via interactions with an identity service.

7. The method of claim 1 further comprising, determining, by the router, an identity for the neighboring service provider from a list of available neighboring service providers based at least in part on a direction from which signals are being received from the participant.

8. A machine-implemented method to execute on a router, comprising:

moving, by the router, a connection of a processing device from a local homogeneous secure network to a heterogeneous secure network when the processing device is determined to be in process of transitioning out of the homogeneous secure network service area;

acquiring, by the router, a second key from a neighboring service provider before the processing device transitions out of the homogeneous secure network service area and before communication is lost with the homogeneous secure network;

configuring, by the router, the processing device to use encrypted communications that utilize the second key when the processing device transitions to the heterogeneous secure network of the neighboring service provider and managing a change in an Internet Protocol (IP) address for the processing device that changes when the processing device transitions from the homogeneous secure network to the heterogeneous secure network, and communication, by the router, changed keys used for communication, the changed keys provided by the processing device of the participant that provides the changed keys and the changed keys communicated to other participants of the homogeneous secure network and the heterogeneous secure network when it is no longer considered safe to use original keys based on key lengths, a total amount of network traffic that the keys have been used for encryption, and a repetitive nature of encrypted traffic.

9. The method of claim 8 , wherein acquiring further includes using, by the router, a key distribution service or an identity service of the neighboring service provider to acquire the second key.

10. The method of claim 9 , wherein using further includes, authenticating, by the router, to the key distribution service or the identity service before acquiring the second key.

11. The method of claim 9 , wherein acquiring further includes, enlisting, by the router, a third-party service to provide an identity and authentication mechanism for interacting with the neighboring service provider.

12. The method of claim 9 , wherein acquiring further includes, accessing, by the router service, a predefined list of available neighboring service providers to identify and interact with the neighboring service provider.

13. The method of claim 9 , wherein acquiring further includes monitoring, by the router, signal degradation to acquire the second key when the signal degradation falls below a threshold established via a policy managed by the router.

14. The method of claim 9 further comprising, migrating an Internet Protocol (IP) address of the processing device from a first IP address to a second and new IP address when the processing device is migrated to the neighboring service provider.

15. A machine-implemented system, comprising:

a router configured to interact with key distribution service and the key distribution service configured to authenticate the router and to provide the router with a new encryption key for an edge device that is transitioning from a first secure network to a second secure network, the first secure network is a homogeneous network and the second secure network is a heterogeneous network and communication with the edge device is transitioned from the homogeneous network to the heterogeneous network before communication with the edge device is lost with the homogeneous network, and an IP address from the edge device is managed and changed when the edge device migrates to the heterogeneous network, and the router further configured to communicate other encryption keys provided by the edge device including other encryption keys replacing specific keys that are no longer considered safe for use based on key lengths, a total amount of network traffic that the specific keys have been used for encryption, and a repetitive nature of encrypted traffic, the edge device a laptop, a personal digital assistant, or a phone, and the other encryption keys supplied by a participant and communicated to other participants of the first secure network and the second secure network.

16. The system of claim 15 , wherein the key distribution service is enabled to interact with the participants in both the first and second secure networks.

17. The system of claim 15 , wherein the router is configured to forward unrecognized traffic in the first secure network to the key distribution service within the second secure network.

18. The system of claim 15 , wherein the key distribution service is enabled to manage key entropy policies for both the first and second secure networks.

19. The system of claim 15 , wherein the router is preconfigured to identify and interact with the key distribution service.

20. The system of claim 15 , wherein the router is configured to dynamically identify and dynamically interact with the key distribution service.

Assignments (15)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →