IP Library Granted Patent US 10,742,689
Granted Patent B2
US 10,742,689 · App. 16/374,522 · Granted Aug 11, 2020

System and method for encryption key management, federation and distribution

Inventors: Charles White (Charles Town, WV); Joseph Brand (Charles Town, WV); Stephen Edwards (Shepherdstown, WV)
Assignee: Fornetix LLC
H04L63/20G06F16/245H04L63/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,742,689
App. No.
16/374,522
Granted
Aug 11, 2020
Kind
B2
Abstract

Systems and methods are described for orchestrating a security object, including, for example, defining and storing a plurality of policies in a database coupled to a policy engine and receiving, by the policy engine, the security object and at least one object attribute associated with the security object. In addition, the policy engine determines the acceptability of the security object based, at least in part, on the at least one object attribute and at least one of the plurality of policies corresponding to the at least one object attribute. The security object to at least one communication device associated with the policy engine is distributed when the security object is determined to be acceptable. The at least one communication device establishes communication based, at least in part, on the security object.

Claims (37)

1. A method for orchestrating a security object, the method comprising:

defining and storing a plurality of policies in a database coupled to a policy engine;

receiving, by the policy engine, the security object for distributing at least one communication device and at least one object attribute associated with the security object;

determining, with the policy engine, acceptability of the security object based, at least in part, on the at least one object attribute and at least one of the plurality of policies corresponding to the at least one object attribute;

transmitting a rejection indicator to a key source in response to determining that the security object is unacceptable, wherein the security object is received from the key source; and

transmitting a hint to the key source informing inadequacies of the security object.

2. The method of claim 1 , wherein the security object is an encryption key.

3. The method of claim 1 , wherein the at least one object attribute comprises at least one of a security object size, time when the security object is generated, geo-location where the security object is generated, classification of the security object, role associated with the key source, role associated with a source device, and role associated with a target device.

4. The method of claim 3 , wherein the plurality of policies comprises accepting the security object when the security object size is within a predetermined size range.

5. The method of claim 3 , wherein the plurality of policies comprises accepting the security object when the security object is generated within a predetermined time interval.

6. The method of claim 3 , wherein the plurality of policies comprises accepting the security object when the geo-location where the security object is generated is within a predetermined area.

7. The method of claim 3 , wherein the plurality of policies comprises accepting the security object when the classification of the security object is associated with a predetermined security object classification group.

8. The method of claim 3 , wherein the plurality of policies comprises accepting the security object when the role associated with the key source, the source device, or the target device is associated with a predetermined group of roles.

9. The method of claim 1 , wherein the key source generates a different security object based on the hint.

10. A non-transitory computer-readable medium comprising computer-readable instructions that, when executed, cause a processor to:

define a plurality of policies in a database;

receive the security object for distributing to at least one communication device and at least one object attribute associated with the security object;

determine acceptability of the security object based, at least in part, on the at least one object attribute and at least one of the plurality of policies corresponding to the at least one object attribute;

transmit a rejection indicator to a key source in response to determining that the security object is unacceptable, wherein the security object is received from the key source; and

transmit a hint to the key source informing inadequacies of the security object.

11. The non-transitory computer-readable medium of claim 10 , wherein the plurality of policies comprises accepting the security object when at least one of the security object size is within a predetermined size range, the time when the security object is generated is within a predetermined time interval, the geo-location where the security object is generated is within a predetermined area, the classification of the security object is included in a predetermined security object classification group, and the role associated with the key source, a source device, or a target device is associated with a predetermined group of roles.

12. The non-transitory computer-readable medium of claim 11 , wherein the plurality of policies comprises accepting the security object when the security object size is within a predetermined size range.

13. The non-transitory computer-readable medium of claim 11 , wherein the plurality of policies comprises accepting the security object when the security object is generated within a predetermined time interval.

14. The non-transitory computer-readable medium of claim 11 , wherein the plurality of policies comprises accepting the security object when the geo-location where the security object is generated is within a predetermined area.

15. The non-transitory computer-readable medium of claim 11 , wherein the plurality of policies comprises accepting the security object when the classification of the security object is associated with a predetermined security object classification group.

16. The non-transitory computer-readable medium of claim 10 , wherein the key source generates a different security object based on the hint.

17. A key orchestration device for orchestrating a security object, the device comprising:

a processor; and

memory having computer-readable instructions stored thereon that, when executed, cause the processor to:

define a plurality of policies in a database;

receive the security object for distributing to at least one communication device and at least one object attribute associated with the security object;

determine acceptability of the security object based, at least in part, on the at least one object attribute and at least one of the plurality of policies corresponding to the at least one object attribute;

transmit a rejection indicator to a key source in response to determining that the security object is unacceptable, wherein the security object is received from the key source; and

transmit a hint to the key source informing inadequacies of the security object.

18. The device of claim 17 , wherein the key source generates a different security object based on the hint.

19. The method of claim 1 , wherein the hint indicates one of the at least one object attribute caused the security object being rejected.

20. The method of claim 1 , wherein the received encryption object and one or both of the rejection indicator or the hint are returned to the key source.

Assignments (2)
SECURITY INTEREST Recorded Jul 15, 2021
From: FORNETIX, LLC
To: DELL MARKETING L.P.
Reel/Frame 056866/0945 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2019
From: WHITE, CHARLES; BRAND, JOSEPH; EDWARDS, STEPHEN
To: FORNETIX LLC
Reel/Frame 048786/0406 →
Continuity (5)
Continuation 15662185 · Jul 27, 2017
Continuation 14506346 · Oct 3, 2014
Provisional Application 61887662 · Oct 7, 2013
Provisional Application 61950362 · Mar 10, 2014
Related Publication 20190230131A1 · Jul 25, 2019
Cited By (1)
US 12,432,049