IP Library Granted Patent US 10,764,064
Granted Patent B2
US 10,764,064 · App. 15/829,257 · Granted Sep 1, 2020

Non-networked device performing certificate authority functions in support of remote AAA

Inventors: Shawn D. Hennessy (Lisbon, ME); Nevenko Zunic (Hopewell Junction, NY); Todd P. Seager (Orem, UT)
Assignee: International Business Machines Corporation
H04L9/3263G06F13/385G06F13/4282G06F21/33G06F21/34H04L9/3231H04L9/3234H04L63/0892G06F2213/0042
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,764,064
App. No.
15/829,257
Granted
Sep 1, 2020
Kind
B2
Abstract

In an approach, a certificate authority management device comprises a computing device with an operating system that supports certificate authority software, a power port with shutter door, a first key slot for an administrative user to enable use of the certificate authority management device in response to an insertion of a first key, a second key slot for management of a plurality of hybrid security keys in response to an insertion of a second key, and a touchscreen with graphical user interface.

Claims (27)

1. A standalone secure non-networked device that performs certificate authority, the standalone secure non-networked device comprising:

a computing device with an operating system and with embedded certificate authority software;

a first key slot for an administrative user to activate the standalone secure non-networked device and enable the certificate authority software in response to an insertion of a first hybrid security key by extracting credentials from a smart chip of the first hybrid security key and comparing the extracted credentials to an access control list stored on the computing device to determine an authorization of the first hybrid security key; and

a second key slot to manage a plurality of hybrid security keys in response to an insertion of a respective hybrid security key of the plurality of hybrid security keys, wherein:

the second key slot is one of a plurality of swappable key slots that each have a different shaped key slot that allow use with respective ones of the plurality of hybrid security keys having at least one logical face and at least one physical face,

the at least one logical face comprises a smart chip, and

the at least one logical face and the at least one physical face are separate faces of each respective hybrid security key of the plurality of hybrid security keys.

2. The standalone secure non-networked device of claim 1 , further comprising a USB port with a shutter door.

3. The standalone secure non-networked device of claim 1 , further comprising a biometric input scanner.

4. The standalone secure non-networked device of claim 3 , wherein the biometric input scanner is selected from the group consisting of: a retinal scanner, fingerprint scanner, and facial scanner.

5. The standalone secure non-networked device of claim 1 , wherein a repository of the computing device contains an access control list of authorized users and associated authorizations of each authorized user.

6. The standalone secure non-networked device of claim 1 , wherein the first key slot comprises a first locking device with a first lock cylinder that matches with the first hybrid security key.

7. The standalone secure non-networked device of claim 1 , wherein the second key slot comprises a second locking device with a second lock cylinder that allows use with a rectangular-shaped hybrid security key with one physical face and one logical face.

8. The standalone secure non-networked device of claim 1 , wherein the second key slot can be swapped for a third key slot comprising a third locking device with a third lock cylinder that allows use with a triangular-shaped hybrid security key with at least one physical face and at least one logical face.

9. The standalone secure non-networked device of claim 1 , wherein the second key slot can be swapped for a fourth key slot comprising a fourth locking device with a fourth lock cylinder that allows use with a square-shaped hybrid security key with two physical faces and two logical faces.

10. The standalone secure non-networked device of claim 1 , further comprising a power port with shutter door.

11. The standalone secure non-networked device of claim 1 , further comprising a touchscreen with a graphical user interface.

12. The standalone secure non-networked device of claim 1 , wherein each component of the standalone secure non-networked device is assigned a permanent unique identification at a time of manufacture, and wherein the permanent unique identification for each component of the standalone secure non-networked device is stored in a table in a repository of the computing device.

13. The standalone secure non-networked device of claim 12 , wherein the computing device is electronically coupled to each component of the standalone secure non-networked device through each respective permanent unique identification.

14. The standalone secure non-networked device of claim 1 , wherein the operating system of the computing device is digitally signed with a private certificate authority key of a certificate authority key pair.

15. The standalone secure non-networked device of claim 1 , wherein the first key slot can be turned using the first hybrid security key to one of a plurality of detent positions, wherein each of the plurality of detent positions enables a respective set of functions of the certificate authority software.

16. The standalone secure non-networked device of claim 1 , wherein the first hybrid security key comprises:

at least one physical face on a first side of the first hybrid security key comprising a key groove cut and a barcode coupled to a top surface of the physical face; and

at least one logical face on a second side of the first hybrid security key comprising a surface insert overlaying a conductive film, wherein the conductive film includes at least one contact point, at least one conductive trace, and a smart chip.

17. The standalone secure non-networked device of claim 1 , wherein the second hybrid security key comprises:

at least one physical face on a first side of the second hybrid security key comprising a key groove cut and a barcode coupled to a top surface of the physical face; and

at least one logical face on a second side of the second hybrid security key comprising a surface insert overlaying a conductive film, wherein the conductive film includes at least one contact point, at least one conductive trace, and a smart chip.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2017
From: HENNESSY, SHAWN D.; ZUNIC, NEVENKO; SEAGER, TODD P.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 044276/0474 →
Continuity (1)
Related Publication 20190173679A1 · Jun 6, 2019
Cited By (1)
US 12,355,757