IP Library Granted Patent US 8,789,210
Granted Patent B2
US 8,789,210 · App. 13/100,693 · Granted Jul 22, 2014

Key usage policies for cryptographic keys

Inventors: Todd W. Arnold (Charlotte, NC); Elizabeth A. Dames (Concord, NC); Carsten D. Frehr (Farum, DE); Michael J. Kelly (Wappingers Falls, NY); Kenneth B. Kerr (New Paltz, NY); Richard V. Kisley (Charlotte, NC); Eric D. Rossman (Wappingers Falls, NY); Eric B. Smith (Concord, NC)
Assignee: International Business Machines Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,789,210
App. No.
13/100,693
Granted
Jul 22, 2014
Kind
B2
Abstract

A computer program product for secure key management is provided. The computer program product includes a tangible storage medium readable by a processing circuit and storing instructions for execution by the processing circuit for creating a token and populating the token with key material, and binding key control information to the key material. The key control information includes information relating to usage of the key material populating one or more key usage fields that define attributes that limit actions that may be performed with the key material.

Claims (24)

1. A computer program product for secure key management, the computer program product comprising:

a non-transient computer readable medium readable by a processing circuit and storing instructions for execution by the processing circuit for:

creating a token and populating the token with key material; and

cryptographically binding key control information to the key material such that the key material is accompanied with key binding material, which conforms to and is wrapped using a wrapping method indicated by token fields that are unchanged by a chosen wrapping method, the key control information including:

information relating to usage of the key material populating one or more key usage fields that define attributes that limit actions that may be performed with the key material,

wherein the key control information further comprises a key usage field count indicating a number of the key usage fields and each of the key usage fields comprises:

a high order byte containing flag bits as an indicator, the high order flag bits comprising a first position defining a rule for export using a symmetric key, a second position defining a rule for export using an unauthenticated asymmetric key, a third position defining a rule for export using an authenticated asymmetric key, a fourth position defining a rule for export to a TR-31 format and a fifth position defining a rule for export in RAW format; and

a low order byte containing flag bits as an indicator, the low order flag bits comprising a first position defining a rule for export using a DES key, a second position defining a rule for export using an AES key and a fifth position defining a rule of export using an RSA key,

each of the indicators being independent and indicative of one key exchange that is performable with the key material.

2. The method according to claim 1 , wherein the number of the key usage fields is 1 to n.

3. The method according to claim 1 , wherein a fixed set of indicators have indicators that are in use and indicators that are reserved, the reserved indicators being set to ‘Not allowed’.

4. A system for secure key management, comprising:

a computer processor; and

an application configured to execute on the computer processor, the application implementing:

creation of a token and population of the token with key material; and

a cryptographic binding of key control information to the key material such that the key material is accompanied with key binding material, which conforms to and is wrapped using a wrapping method indicated by token fields that are unchanged by a chosen wrapping method, the key control information including:

information relating to usage of the key material populating one or more key usage fields that that define attributes that limit actions that may be performed with the key material,

wherein each of the key usage fields comprises:

a high order byte containing flag bits as an indicator, the high order flag bits comprising a first position defining a rule for export using a symmetric key, a second position defining a rule for export using an unauthenticated asymmetric key, a third position defining a rule for export using an authenticated asymmetric key, a fourth position defining a rule for export to a TR-31 format and a fifth position defining a rule for export in RAW format; and

a low order byte containing flag bits as an indicator, the low order flag bits comprising a first position defining a rule for export using a DES key, a second position defining a rule for export using an AES key and a fifth position defining a rule of export using an RSA key,

each of the indicators being independent and indicative of one key exchange that is performable with the key material.

5. The method according to claim 4 , wherein the number of the key usage fields is 1 to n.

6. The method according to claim 4 , wherein the key control information further comprises a key usage field count indicating a number of the key usage fields.

7. The method according to claim 4 , wherein a fixed set of indicators have indicators that are in use and indicators that are reserved, the reserved indicators being set to ‘Not allowed’.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2011
From: ARNOLD, TODD W.; DAMES, ELIZABETH A.; FREHR, CARSTEN D.; KELLY, MICHAEL J.; KERR, KENNETH B.; KISLEY, RICHARD V.; ROSSMAN, ERIC D.; SMITH, ERIC B.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 026225/0456 →
Continuity (1)
Related Publication 20120281839A1 · Nov 8, 2012