IP Library › Granted Patent US 10,715,318
Granted Patent B2
US 10,715,318 · App. 15/877,789 · Granted Jul 14, 2020

Lightweight cryptographic service for simplified key life-cycle management

Inventors: Graham C. Charters (Hampshire, GB); Bret W. Dixon (South Perth, AU); Benjamin T. Horwood (North Perth, AU); Alexander H. Poga (Wembley, AU); Mark A. Shewell (Perth, AU)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L9/083G06F21/31H04L9/0825H04L9/0894H04L9/3247G06F21/602H04L63/0442
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,715,318
App. No.
15/877,789
Granted
Jul 14, 2020
Kind
B2
Abstract

A method for a cryptographic service facilitating asymmetric encryption is provided. The cryptographic service is implemented on one or more computer systems. The method includes receiving, by the cryptographic service, one or more unique identifiers. The method also includes determining, by the cryptographic service, whether each of the one or more unique identifiers is valid. The method includes generating, by the cryptographic service, a key pair per unique identifier of the one or more unique identifiers based on whether the corresponding unique identifier is valid. The method includes sending, by the cryptographic service, a success reply including a public key for each key pair generation.

Claims (36)

1. A method for a cryptographic service facilitating asymmetric encryption, the cryptographic service implemented on one or more computer systems, the method comprising:

receiving, by the cryptographic service, one or more unique identifiers;

determining, by the cryptographic service, whether each of the one or more unique identifiers is valid;

generating, by the cryptographic service, a key pair per unique identifier of the one or more unique identifiers based on whether the corresponding unique identifier is valid; and

sending, by the cryptographic service, a success reply including a private key for each key pair generation,

wherein the key pair enables the cryptographic service to avoid digital certificates or associated key life-cycle management for the encryption of data between a requester and one or more remote system,

wherein in the key pair comprises the private key and a public key, the private key being distributed once to a requester and the public key being provided on demand,

wherein the method of the cryptographic service provides a success reply including a public key to a remote system upon receiving the unique identifier from the remote system and validating the unique identifier received from the remote system with respect to a get request from the remote system.

2. The method of claim 1 , wherein the method of the cryptographic service sends a failure reply based on whether the corresponding unique identifier is invalid.

3. The method of claim 1 , wherein the method of the cryptographic service deletes an association of the key pair and the unique identifier of the one or more unique identifiers upon validating the unique identifier and an input signature with respect to a delete request from a requester.

4. The method of claim 3 , wherein the method of the cryptographic service sends a failure reply based on whether the unique identifier of the one or more unique identifiers or the input signature is invalid.

5. A computer program product for a cryptographic service facilitating asymmetric encryption, the cryptographic service implemented on one or more computer systems, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by at least one of processor of the one or more computer systems to cause:

receiving, by the cryptographic service, one or more unique identifiers;

determining, by the cryptographic service, whether each of the one or more unique identifiers is valid;

generating, by the cryptographic service, a key pair per unique identifier of the one or more unique identifiers based on whether the corresponding unique identifier is valid; and

sending, by the cryptographic service, a success reply including a private key for each key pair generation,

wherein the key pair enables the cryptographic service to avoid digital certificates or associated key life-cycle management for the encryption of data between a requester and one or more remote system,

wherein in the key pair comprises the private key and a public key, the private key being distributed once to a requester and the public key being provided on demand,

wherein the method of the cryptographic service provides a success reply including a public key to a remote system upon receiving the unique identifier from the remote system and validating the unique identifier received from the remote system with respect to a get request from the remote system,

wherein the key pair enables the cryptographic service to avoid digital certificates or associated key life-cycle management for the encryption of data between a requester and one or more remote system,

wherein in the key pair comprises the private key and a public key, the private key being distributed once to a requester and the public key being provided on demand,

wherein the method of the cryptographic service provides a success reply including a public key to a remote system upon receiving the unique identifier from the remote system and validating the unique identifier received from the remote system with respect to a get request from the remote system.

6. The computer program product of claim 5 , wherein the program instructions are further executable by the processor to cause the cryptographic service to send a failure reply based on whether the corresponding unique identifier is invalid.

7. The computer program product of claim 5 , wherein the program instructions are further executable by the processor to cause the cryptographic service to delete an association of the key pair and the unique identifier of the one or more unique identifiers upon validating the unique identifier and an input signature with respect to a delete request from a requester.

8. The computer program product of claim 5 , wherein the program instructions are further executable by the processor to cause the cryptographic service to send a failure reply based on whether the unique identifier of the one or more unique identifiers or the input signature is invalid.

9. A cryptographic service system comprising a processor and a memory storing program instructions for a cryptographic service facilitating asymmetric encryption thereon, the program instructions executable by the processor to cause:

receiving, by the cryptographic service system, one or more unique identifiers;

determining, by the cryptographic service system, whether each of the one or more unique identifiers is valid;

generating, by the cryptographic service system, a key pair per unique identifier of the one or more unique identifiers based on whether the corresponding unique identifier is valid; and

sending, by the cryptographic service system, a success reply including a private key for each key pair generation,

wherein the key pair enables the cryptographic service to avoid digital certificates or associated key life-cycle management for the encryption of data between a requester and one or more remote system,

wherein in the key pair comprises the private key and a public key, the private key being distributed once to a requester and the public key being provided on demand,

wherein the method of the cryptographic service provides a success reply including a public key to a remote system upon receiving the unique identifier from the remote system and validating the unique identifier received from the remote system with respect to a get request from the remote system.

10. The cryptographic service system of claim 9 , wherein the program instructions are further executable by the processor to cause the cryptographic service system to send a failure reply based on whether the corresponding unique identifier is invalid.

11. The cryptographic service system of claim 9 , wherein the program instructions are further executable by the processor to cause the cryptographic service system to delete an association of the key pair and the unique identifier of the one or more unique identifiers upon validating the unique identifier and an input signature with respect to a delete request from a requester.

12. The cryptographic service system of claim 9 , wherein the program instructions are further executable by the processor to cause the cryptographic service to send a failure reply based on whether the unique identifier of the one or more unique identifiers or the input signature is invalid.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2018
From: CHARTERS, GRAHAM C.; DIXON, BRET W.; HORWOOD, BENJAMIN T.; POGA, ALEXANDER H.; SHEWELL, MARK A.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 044702/0431 →
Continuity (1)
Related Publication 20190229896A1 · Jul 25, 2019
Cited By (1)
US 12,238,090