IP Library › Granted Patent US 9,912,646
Granted Patent B2
US 9,912,646 · App. 15/062,444 · Granted Mar 6, 2018

Automatic security parameter management and renewal

Inventors: Ashish Kundu (Yorktown Heights, NY); Ruchi Mahindru (Yorktown Heights, NY); Ajay Mohindra (Yorktown Heights, NY); Valentina Salapura (Yorktown Heights, NY); Mahesh Viswanathan (Yorktown Heights, NY)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/06H04L63/083H04L63/0823H04L63/0846H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,912,646
App. No.
15/062,444
Filed
Mar 7, 2016
Granted
Mar 6, 2018
Kind
B2
Art Unit
2436
USPC
726/6
Abstract

A method of automatic security parameter renewal includes determining if a security parameter satisfies a renewal condition, and automatically updating the security parameter when the renewal condition is satisfied. The automatically updating the security parameter includes modifying a certificate in dependent components of an application of the security parameter, by a central certification server, upon receipt of a new certificate.

Claims (41)

1. A method of automatic security parameter renewal, said method comprising:

determining if said security parameter satisfies a renewal condition, said determining comprising automatically detecting a time when a security parameter is going to expire;

before said security parameter is expired, automatically updating said security parameter when said renewal condition is satisfied; and

automatically updating said security parameter in dependent components of an application of said security parameter,

wherein said automatically updating said security parameter in the dependent components comprises modifying a certificate in dependent components, by a central certification server, upon receipt of a new certificate.

2. The method according to claim 1 , wherein said automatically updating comprises one or more of resetting said security parameter and updating a security parameter expiration field.

3. The method according to claim 2 , wherein a value of said security parameter expiration field is set based on a security parameter expiration policy.

4. The method according to claim 1 , wherein said automatically updating comprises:

ascertaining whether a pro-approval has been obtained; and

receiving a manual approval when said pre-approval has not been obtained.

5. The method according to claim 1 , further comprising obtaining information related to a dependent application of said security parameter.

6. The method according to claim 5 , further comprising automatically updating a security parameter of said dependent application.

7. The method according to claim 1 , wherein said security parameter comprises one or more of a password, a license, a secure socket level (SSL) key, a certificate, and a cookie.

8. The method according to claim 1 , wherein said determining whether said security parameter satisfies said renewal condition comprises comparing a security parameter expiration amount to a threshold amount.

9. The method according to claim 8 , wherein said security parameter satisfies said renewal condition when said security parameter expiration amount is one of less than and equal to said threshold amount.

10. The method according to claim 1 , wherein said security parameter satisfies said renewal condition upon an occurrence of a compromise.

11. A system for automatic renewal and management of a security parameter, said system comprising:

an automatic distribution component for distributing information related to said security parameter;

an automatic renewal component for automatically updating said security parameter, before said security parameter is expired, when a renewal condition is satisfied by automatically updating said security parameter in dependent components of an application of said security parameter; and

a memory device storing information on a dependency of the security parameter,

wherein said automatic distribution component is configured to automatically detect a time when said security parameter is going to expire, and

wherein said automatically updating said security parameter in the dependent components comprises modifying a certificate in the dependent components, by a central certification server, upon receipt of a new certificate.

12. The system according to claim 11 , further comprising an automatic detection component for detection of the dependency of said security parameter.

13. The system according to claim 11 , wherein said automatic distribution component comprises:

a credential updater which provides said security parameter with an updated value; and

a parameter distributor which distributes said updated security parameter to at least one dependent application.

14. The system according to claim 11 , wherein said automatic renewal component comprises:

a search agent which determines an expiration status of said security parameter;

a renewal request generator which generates a renewal request based on said expiration status; and

a parameter generator which generates an updated security parameter.

15. The system according to claim 11 , further comprising a pre-approval list for determining whether a pre-approval has been obtained.

16. A security parameter management system, said system comprising:

a security parameter service for managing a plurality of security parameters within an integrated solution;

an automatic security parameter generator which communicates with said security parameter service; and

an automatic renewal component for updating at least one of the plurality of parameter services, before said at least one of the plurality of parameter services is expired, when a renewal condition is satisfied by automatically updating said one of the plurality of parameter services in dependent components of an application of said one of the plurality of parameter services,

wherein said automatically updating said one of the plurality of security parameter services in the dependent components comprises modifying a certificate in the dependent, by a central certification server, upon receipt of a new certificate, and

wherein said security parameter service automatically detects a time when said at least one of plurality of security parameters is going to expire.

17. The system according to claim 16 , wherein said security parameter service manages said security parameters based on one or more of an application ID, an Internet Protocol (IP) address, and a host expiration policy.

18. The system according to claim 16 , wherein said security parameter service updates said plurality of security parameters throughout an entirety of said integrated service.

19. The system according to claim 18 , wherein said security parameter updates said plurality of security parameters in response to a command, and

wherein said command comprises one or more of a user command and an application command.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2016
From: KUNDU, ASHISH; MAHINDRU, RUCHI; MOHINDRA, AJAY; SALAPURA, VALENTINA; VISWANATHAN, MAHESH
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 037942/0025 →
Continuity (2)
Continuation 14192204 · Feb 27, 2014
Related Publication 20160191477A1 · Jun 30, 2016