Cryptographic services engine
A cryptographic services management engine may provide a single point of interaction for both users and administrators to manage and consume cryptographic services. Such an engine may allow centralized control over cryptography parameters, ensuring enterprise security standards are maintained while abstracting the complexity and potential for error away from users. Automating cryptographic maintenance tasks may avoid outages caused by expired or incorrect certificates, and improve reliability and predictability of critical infrastructure services.
1. A cryptographic services system, that includes:
a computer processor;
at least one interface, the at least one interface including at least one network interface, the at least one interface configured to translate a plurality of cryptographic services requests from at least one user of the system and at least one administrator of the system into a plurality of service instructions for the processor; and
at least one memory, comprising cryptographic data and processor executable code to perform at least one cryptographic service, wherein the cryptographic data comprises a certificate and the at least one cryptographic service comprises revoking the certificate when the certificate does not meet a requirement,
wherein the computer processor is configured, in response to the plurality of service instructions, to cause the executable code in the at least one memory to be executed to perform the at least one cryptographic service using the cryptographic data so as to provide the at least one cryptographic service to the at least one user of the system and to the at least one administrator of the system.
2. The system of claim 1 , wherein the at least one cryptographic service further comprises performing a health check on cryptographic infrastructure that generates a report comprising data on device and interface availability and performance.
3. The system of claim 1 , wherein the at least one cryptographic service further comprises scanning a certificate configuration of the cryptographic data to ensure the cryptographic data meets the requirement.
4. The system of claim 1 , wherein the at least one cryptographic service further comprises generating a report that includes certificate expiration data associated with the cryptographic data.
5. The system of claim 1 , wherein the at least one cryptographic service further comprises logging all user or administrator activity pertaining to the cryptographic data.
6. The system of claim 1 , wherein the at least one cryptographic service comprises notifying at least one of the at least one user of an impending expiration of the certificate.
7. A non-transitory, tangible computer-readable medium, storing machine readable instructions that when executed by a processor cause the processor to:
receive a plurality of cryptographic service instructions from at least one interface in response to a plurality of cryptographic services requests from at least one user of a cryptographic services system and at least one administrator of the cryptographic services system, the at least one interface including at least one network interface;
retrieve processor executable code and cryptographic data from at least one memory, wherein the cryptographic data comprises a certificate; and
execute the processor executable code to perform at least one cryptographic service, corresponding to the plurality of cryptographic service instructions, on the cryptographic data so as to provide the at least one cryptographic service to the at least one user of the cryptographic services system and to the at least one administrator of the cryptographic services system, wherein the at least one cryptographic service comprises revoking the certificate when the certificate does not meet a requirement.
8. The medium of claim 7 , wherein the at least one cryptographic service further comprises performing a health check on cryptographic infrastructure that generates a report comprising data on device and interface availability and performance.
9. The medium of claim 7 , wherein the at least one cryptographic service further comprises scanning a certificate configuration of the cryptographic data to ensure the cryptographic data meets the requirement.
10. The medium of claim 7 , wherein the at least one cryptographic service further comprises generating a report that includes certificate expiration data associated with the cryptographic data.
11. The medium of claim 7 , wherein the at least one cryptographic service further comprises logging all user or administrator activity pertaining to the cryptographic data.
12. The medium of claim 7 , wherein the at least one cryptographic service comprises notifying at least one of the at least one user of an impending expiration of the certificate.
13. A computer implemented method, executed with a computer processor, to perform at least one cryptographic service, comprising:
receiving, with the computer processor, a plurality of cryptographic service instructions from at least one interface in response to a plurality of cryptographic services requests from at least one user of a cryptographic services system and at least one administrator of the cryptographic services system, the at least one interface including at least one network interface;
retrieving, with the computer processor, processor executable code and cryptographic data from at least one memory, the cryptographic data comprising a certificate; and
executing, in the computer processor, the processor executable code to perform the at least one cryptographic service, corresponding to the plurality of cryptographic service instructions, on the cryptographic data so as to provide the at least one cryptographic service to the at least one user of the cryptographic services system and to the at least one administrator of the cryptographic services system, the at least one cryptographic service comprising revoking the certificate when the certificate does not meet a requirement.
14. The method of claim 13 , wherein the at least one cryptographic service further comprises performing a health check on cryptographic infrastructure that generates a report comprising data on device and interface availability and performance.
15. The method of claim 13 , wherein the at least one cryptographic service further comprises scanning a certificate configuration of the cryptographic data to ensure the cryptographic data meets the requirement.
16. The method of claim 13 , wherein the at least one cryptographic service further comprises generating a report that includes certificate expiration data associated with the cryptographic data.
17. The method of claim 13 , wherein the at least one cryptographic service further comprises logging all user or administrator activity pertaining to the cryptographic data.