IP Library Granted Patent US 8,538,026
Granted Patent B2
US 8,538,026 · App. 12/771,109 · Granted Sep 17, 2013

Key distribution

Inventors: Stephen R. Carter (Spanish Fork, UT); Carolyn B. McClain (Springville, UT)
Assignee: Novell, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,538,026
App. No.
12/771,109
Filed
Apr 30, 2010
Granted
Sep 17, 2013
Kind
B2
Art Unit
2434
USPC
713/155
Abstract

Methods and systems are provided for trusted key distribution. A key distribution or an identity service acts as an intermediary between participants to a secure network. The service provisions and manages the distribution of keys. The keys are used for encrypting communications occurring within the secure network.

Claims (29)

1. A machine-implemented system, comprising:

an identity service interface implemented in a processing device and to execute on the processing device;

a service provider interface implemented in a router and to execute on the router; and

a participant interface implemented in an edge device and to execute on the edge device, wherein the identity service interface is configured to interact securely with an identity service to manage keys, the service provider interface and participant interface both configured for communications with one another via the keys, the identity service configured to facilitate secure communications engaged in by the multiple participants via the keys, the identity service also configured: to coordinate any keys from one or more of the participants, to revoke some keys, and to distribute, and wherein the keys are Wired Equivalent Privacy (WEP) encrypted the keys.

2. The network service system of claim 1 , further comprising a list of trusted service providers configured for communication through the service provider interface.

3. The network service system of claim 2 , wherein the list is configured to be dynamically modified or to be augmented through interactions with the identity service through the identity service interface.

4. The network service system of claim 1 , wherein the participant interface is configured to service network traffic received from participants, and wherein the identity service is configured to dynamically encrypt the network traffic with one of the keys.

5. The network service system of claim 1 , wherein the participant interface is configured to generate a new key for encrypted communications between the participant interface and the one or more participants, and wherein the identity service interface is configured to communicate the new key to the identity service.

6. The network service system of claim 1 , wherein the participant interface is configured to communicate wirelessly with the one or more participants.

7. The network service system of claim 1 , wherein the service provider interface is configured to acquire additional keys for interacting with one or more service providers, and wherein the participant interface is configured communicate the additional keys to the one or more participants when one or more of the participants are detected as reaching a diminished signal strength as measured by a predefined threshold, and wherein the additional keys are configured to transition the one or more participants to the one or more service providers.

8. A machine-implemented method to execute on a router, comprising:

authenticating, by the router, to an identity service to acquire an encryption key for a wireless network connection, the encryption key is encrypted via Wired Equivalent Privacy (WEP);

acquiring, by the router, an identity for a service provider using the encryption key; and

transitioning, by the router, a participant of a first secure network to a second secure network using the encryption key when the participant is detected as geographically moving into the second secure network, the second secure network using the encryption key for communications and an original Internet Protocol (IP) address for the participant associated with the first secure network changes when the participant transitions to the second secure network.

9. The method of claim 8 further comprising, monitoring, by the router, a signal strength for the first secure network as held by the participant and comparing against a threshold to determine if a transition of the participant to the second secure network is necessitated.

10. The method of claim 8 further comprising, using, by the router, the identity service to communicate with the participant when the router detects that the participant is using an unrecognized format to communicate within the first secure network.

11. The method of claim 8 , wherein acquiring further includes selecting, by the router, the identity from a list of available service providers supplied by the identity service in accordance with a policy.

12. The method of claim 8 , wherein transitioning further includes detecting a direction and signal strength of communications occurring with the participant within the first secure network with the router to determine when to transition to the second secure network.

13. The method of claim 12 , wherein detecting further includes selecting the identity in response to the direction and the signal strength.

14. The method of claim 8 further comprising, passing control, by the router, of communications sent from and received by the participant to another router associated with the second secure network.

15. A machine-implemented method to execute on a router, comprising:

identifying, by the router, a first secure network having first communications with a participant using a first encryption key;

determining, by the router, that participant is moving out of the service area of the first secure network;

locating, by the router, a second secure network using a second encryption key for second communications; and

configuring, by the router, the participant to use the second communications having the second encryption key of the second secure network and changing an original Internet Protocol (IP) address for the participant as used in the first secure network to a different IP address for the participant in the second secure network, the first encryption key and the second encryption key encrypted via Wired Equivalent Privacy (WEP).

16. The method of claim 15 , wherein determining further includes monitoring signal direction and signal strength to determine when the participant is moving out of the service area.

17. The method of claim 16 , wherein monitoring further includes comparing threshold values against values obtained for the signal direction and the signal strength to determine when the participant is moving out of the service area.

18. The method of claim 16 , wherein locating further includes contacting a third-party authentication service for an identity of the second secure network.

19. The method of claim 16 , wherein locating further includes accessing a predefined list to acquire an identity of the second secure network.

Assignments (15)
RELEASE OF SECURITY INTEREST REEL/FRAME 035656/0251 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.)
Reel/Frame 062623/0009 →
RELEASE OF SECURITY INTEREST REEL/FRAME 044183/0718 Recorded Feb 2, 2023
From: JPMORGAN CHASE BANK, N.A.
To: MICRO FOCUS LLC (F/K/A ENTIT SOFTWARE LLC); BORLAND SOFTWARE CORPORATION; MICRO FOCUS (US), INC.; SERENA SOFTWARE, INC; ATTACHMATE CORPORATION; MICRO FOCUS SOFTWARE INC. (F/K/A NOVELL, INC.); NETIQ CORPORATION
Reel/Frame 062746/0399 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT TYPO IN APPLICATION NUMBER 10708121 WHICH SHOULD BE 10708021 PREVIOUSLY RECORDED ON REEL 042388 FRAME 0386. ASSIGNOR(S) HEREBY CONFIRMS THE NOTICE OF SUCCESSION OF AGENCY. Recorded Jul 26, 2018
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 048793/0832 →
SECURITY INTEREST Recorded Oct 11, 2017
From: ATTACHMATE CORPORATION; BORLAND SOFTWARE CORPORATION; NETIQ CORPORATION; MICRO FOCUS (US), INC.; MICRO FOCUS SOFTWARE, INC.; ENTIT SOFTWARE LLC; ARCSIGHT, LLC; SERENA SOFTWARE, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 044183/0718 →
NOTICE OF SUCCESSION OF AGENCY Recorded May 2, 2017
From: BANK OF AMERICA, N.A., AS PRIOR AGENT
To: JPMORGAN CHASE BANK, N.A., AS SUCCESSOR AGENT
Reel/Frame 042388/0386 →
CHANGE OF NAME Recorded Sep 13, 2016
From: NOVELL, INC.
To: MICRO FOCUS SOFTWARE INC.
Reel/Frame 040020/0703 →
SECURITY INTEREST Recorded May 13, 2015
From: MICRO FOCUS (US), INC.; BORLAND SOFTWARE CORPORATION; ATTACHMATE CORPORATION; NETIQ CORPORATION; NOVELL, INC.
To: BANK OF AMERICA, N.A.
Reel/Frame 035656/0251 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0216 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034470/0680 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 028252/0316 Recorded Nov 24, 2014
From: CREDIT SUISSE AG
To: NOVELL, INC.
Reel/Frame 034469/0057 →
GRANT OF PATENT SECURITY INTEREST SECOND LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0316 →
GRANT OF PATENT SECURITY INTEREST FIRST LIEN Recorded May 23, 2012
From: NOVELL, INC.
To: CREDIT SUISSE AG, AS COLLATERAL AGENT
Reel/Frame 028252/0216 →
RELEASE OF SECURITY IN PATENTS SECOND LIEN (RELEASES RF 026275/0018 AND 027290/0983) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0154 →
RELEASE OF SECURITY INTEREST IN PATENTS FIRST LIEN (RELEASES RF 026270/0001 AND 027289/0727) Recorded May 22, 2012
From: CREDIT SUISSE AG, AS COLLATERAL AGENT
To: NOVELL, INC.
Reel/Frame 028252/0077 →
GRANT OF PATENT SECURITY INTEREST (SECOND LIEN) Recorded May 13, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026275/0018 →
GRANT OF PATENT SECURITY INTEREST Recorded May 12, 2011
From: NOVELL, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 026270/0001 →
Continuity (2)
Division 10999820 · Nov 30, 2004
Related Publication 20100223459A1 · Sep 2, 2010