Patent · US Expired

Cryptographic key management

US6782103B1 · kind B1 · utility

22Cited by
7References
8Claims
0Family size

Assignee

Inventors

Key dates

Filing dateOct 25, 2000
Grant dateAug 24, 2004
Priority date
Expiry dateApr 3, 2023

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L9/0891
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Business data flows from one computer system (1) to another (2) and its integrity can be protected by cryptographic means, such as digital signatures. In particular, a source system (1) may use a private key (DSPR) to sign outgoing data, and a destination system (2) may use a public key (DSPU) to verify incoming data. For security purposes all keys should be changed at scheduled times calculated using factors including key lifetime (from which is calculated the key expiry time) and key delivery time. If a key is compromised it needs to be changed at other than the scheduled time, and in general this will result in calculation of a new scheduled key change time. If a DSPR key is delivered to the source system (1) encrypted by a key encryption key (KEK), then change to the KEK key will in general also be needed upon compromise of the DSPR key. A new key changetime calculation can be avoided if another public key/private key pair is pre-generated and the public key part pre-supplied to the destination system (2), where it is stored as a spare. When the existing private key (DSPR) is compromised, the new private key corresponding to the spare is supplied to the source system (1) and ca…

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.