Back-up for key authority point for scaling and high availability for stateful failover
System and methods for simplified management of secured data and communications networks with a back-up for a key authority point for scalability and availability for stateful failover.
1 . A system for providing secure networks comprising:
a communication network having a network infrastructure; and
software operating on a server in connection to the network for providing security for the network; wherein the software provides:
a management and policy (MAP) server coupled to the network for communication with at least two key authority points (KAPs), including a primary KAP and a back-up KAP,
wherein the MAP includes at least one policy for providing secure association (SA) within the network;
wherein the primary KAP is operable to generate, distribute, and manage key(s) communicated to a multiplicity of policy enforcement points (PEPs) having nodes distributed throughout the network;
wherein the back-up KAP is operable to function as the primary KAP in any event that prevents the primary KAP from functioning,
and wherein the network automatically provides a network topography of secure communication based upon the policy and keys distributed to the PEPs for any encryption form at the nodes
thereby providing a secure, flexible network security solution.
2 . The system of claim 1 , wherein the back-up KAP is operable to force a re-key for all policies upon taking over functions for the primary KAP.
3 . The system of claim 2 , wherein the primary KAP is operable to use re-key to recover.
4 . The system of claim 2 , wherein the back-up KAP is operable to gain full knowledge of the network and store keys without transferring keys or interrupting traffic on the network.
5 . The system of claim 1 , wherein the KAP is operable to reconfigure secure PEP interactivity without requiring change to the network infrastructure.
6 . The system of claim 1 , wherein the KAP is operable to communicate key(s) and policy to peer KAP(s).
7 . The system of claim 1 , wherein the primary and back-up KAPs share a common name such that the PEPs consider them to be identical.
8 . A method for providing secure interactivity between points on a network comprising the steps of:
providing a communication network having a network infrastructure and a secure network topography between a multiplicity of policy enforcement points (PEPs) having nodes with any form of encryption associated therewith;
a user providing at least one policy definition to a management and policy (MAP) server in communication with at least two key authority points (KAPs), including a primary KAP and a back-up KAP;
the primary KAP generating and distributing at least one key to the PEPs consistent with the MAP policy;
the PEPs enforcing the policy at the nodes to provide secure communication across the network topography;
the primary KAP failing its normal operation;
the back-up KAP forcing a re-key and taking over original functions of the primary KAP.
9 . The method of claim 8 , further including the step of the back-up KAP gaining full knowledge of the network and storing current keys.
10 . The method of claim 9 , wherein the step of the back-up KAP gaining full knowledge of the network and storing current keys occurs without transferring keys or interrupting traffic on the network.
11 . The method of claim 8 , further including the step of the primary KAP recovering and using a re-key to regain its primary functionality.
12 . The method of claim 8 , wherein the primary and back-up KAP are using a common KAP name such that they appear to be identical to the PEPs.
13 . The method of claim 12 , wherein the PEPs only use the latest information provided by either KAP.
14 . A method for state functioning of a primary key authority point (KAP) and a back-up KAP within a system for providing secure network communication, the system including a communication network having a network infrastructure and software operating on a management and policy (MAP) server in connection with the network for providing security for the network through communication with at least two key authority points (KAPs), including a primary KAP and a back-up KAP, which are operable to provide keys and policies to a multiplicity of policy enforcement points (PEPs), the method including the steps of:
the primary KAP generating, distributing, and managing the keys communicated to the PEPs;
the primary KAP failing to function;
the back-up KAP activating to function as the primary KAP;
the back-up KAP re-keying for all policies;
thereby providing uninterrupted traffic across the network.
15 . The method of claim 14 , further including the step of the back-up KAP gaining knowledge of the network and storing current keys without transferring keys or interrupting network traffic.
16 . The method of claim 14 , wherein the primary KAP and back-up KAP use the same KAP name to appear identical to the PEPs.