IP Library Granted Patent US 8,995,669
Granted Patent B1
US 8,995,669 · App. 14/148,542 · Granted Mar 31, 2015

Updating shared keys

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,995,669
App. No.
14/148,542
Granted
Mar 31, 2015
Kind
B1
Abstract

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for updating shared keys. In one aspect, a method includes generating, at a first server and using a first key associated with a current period of time on the first server, a first piece of information based on a first request received from a first client device; receiving, at a second server, a second request from the first client device, the second request including the generated first piece of information; and validating, at the second server and using the first key, the first piece of information, wherein the validating is performed during the current period of time on the second server and wherein to generate information the second server uses a second key different from the first key.

Claims (55)

1. A method performed by data processing apparatus, the method comprising:

obtaining, at a first server, a first set of three or more keys, each key in the first set of keys being associated with a different respective time period;

generating, at the first server and at a first local time read by local clock of the first server that is during a first time period associated with a first key in the first set of keys, a first piece of information based on a first request received from a first client device using the first key;

receiving, at the first server and at a second local time read by the local clock of the first server that is during the first time period associated with the first key in the first set of keys, a second request from a second client device, the second request including a second piece of information generated using a second key in the first set of keys, the second key being associated with a second time period subsequent to the first time period; and

validating, at the first server and at a third local time read by a local clock of the first server that is during the first time period associated with the first key, the second piece of information using the second key associated with the second time period subsequent to the first time period.

2. The method of claim 1 , further comprising:

determining, at the first server, that the second piece of information was generated using the second key.

3. The method of claim 2 , wherein the second piece of information includes an identifier corresponding to the second key.

4. The method of claim 1 , further comprising:

obtaining, at the first server, a third key; and

discarding an oldest key of the first set of keys associated with a respective oldest period of time.

5. The method of claim 1 , wherein validating the second piece of information comprises:

decrypting the second piece of information using the second key.

6. The method of claim 1 , wherein validating the second piece of information comprises:

generating a new piece of information using the second key; and

comparing the new piece of information to the second piece of information.

7. The method of claim 1 , further comprising:

obtaining, at a second server, a second set of three or more keys, each key in the third set of keys being associated with a different respective period of time, the second set of three or more keys including the second key;

receiving a third request from the second client device; and

generating, using the second key, the second piece of information associated with the second request for transmission to the second client device.

8. The method of claim 7 , wherein the receiving is performed at a fourth local time during the second time period, wherein the generating is performed at a fifth local time during the second time period, and wherein the fourth and fifth local times are times read by a local clock of the second server.

9. A system comprising one or more data processing apparatus and one or more storage devices that when executed by the one or more data processing apparatus cause the one or more data processing apparatus to perform operations comprising:

obtaining, at a first server, a first set of three or more keys, each key in the first set of keys being associated with a different respective time period;

generating, at the first server and at a first local time read by a local clock of the first server that is during a first time period associated with a first key in the first set of keys, a first piece of information based on a first request received from a first client device using the first key;

receiving, at the first server and at a second local time read by the local clock of the first server that is during the first time period associated with the first key in the first set of keys, a second request from a second client device, the second request including a second piece of information generated using a second key in the first set of keys, the second key being associated with a second time period subsequent to the first time period; and

validating, at the first server and at a third local time read by a local clock of the first server that is during the first time period associated with the first key, the second piece of information using the second key associated with the second time period subsequent to the first time period.

10. The system of claim 9 , the operations further comprising:

determining, at the first server, that the second piece of information was generated using the second key.

11. The system of claim 10 , wherein the second piece of information includes an identifier corresponding to the second key.

12. The system of claim 9 , the operations further comprising:

obtaining, at the first server, a third key; and

discarding an oldest key of the first set of keys associated with a respective oldest period of time.

13. The system of claim 9 , wherein validating the second piece of information comprises:

decrypting the second piece of information using the second key.

14. The system of claim 9 , wherein validating the second piece of information comprises:

generating a new piece of information using the second key; and

comparing the new piece of information to the second piece of information.

15. The system of claim 9 , the operations further comprising:

obtaining, at a second server, a second set of three or more keys, each key in the third set of keys being associated with a different respective period of time, the second set of three or more keys including the second key;

receiving a third request from the second client device; and

generating, using the second key, the second piece of information associated with the second request for transmission to the second client device.

16. The system of claim 15 , wherein the receiving is performed at a fourth local time during the second time period, wherein the generating is performed at a fifth local time during the second time period, and wherein the fourth and fifth local times are times read by a local clock of the second server.

17. A non-transitory computer storage medium encoded with a computer program, the computer program comprising instructions that when executed by one or more data processing apparatus cause the one or more data processing apparatus to perform operations comprising:

obtaining, at a first server, a first set of three or more keys, each key in the first set of keys being associated with a different respective time period;

generating, at the first server and at a first local time read by a local clock of the first server that is during a first time period associated with a first key in the first set of keys, a first piece of information based on a first request received from a first client device using the first key;

receiving, at the first server and at a second local time read by the local clock of the first server that is during the first time period associated with the first key in the first set of keys, a second request from a second client device, the second request including a second piece of information generated using a second key in the first set of keys, the second key being associated with a second time period subsequent to the first time period; and

validating, at the first server and at a third local time read by a local clock of the first server that is during the first time period associated with the first key, the second piece of information using the second key associated with the second time period subsequent to the first time period.

18. The computer storage medium of claim 17 , the operations further comprising:

obtaining, at the first server, a third key; and

discarding an oldest key of the first set of keys associated with a respective oldest period of time.

19. The computer storage medium of claim 17 , the operations further comprising:

obtaining, at a second server, a second set of three or more keys, each key in the third set of keys being associated with a different respective period of time, the second set of three or more keys including the second key;

receiving a third request from the second client device; and

generating, using the second key, the second piece of information associated with the second request for transmission to the second client device.

20. The computer storage medium of claim 18 , wherein the receiving is performed at a fourth local time during the second time period, wherein the generating is performed at a fifth local time during the second time period, and wherein the fourth and fifth local times are times read by a local clock of the second server.

Assignments (2)
CHANGE OF NAME Recorded Oct 2, 2017
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 044334/0466 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2014
From: RADHAKRISHNAN, SIVASANKAR; CHENG, YUCHUNG
To: GOOGLE INC.
Reel/Frame 032985/0864 →