Patent · US Active

Hitless manual cryptographic key refresh in secure packet networks

US8082441B2 · kind B2 · utility

1Cited by
2References
14Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 10, 2009
Grant dateDec 20, 2011
Priority date
Expiry dateJun 10, 2029

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L9/3247
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

In a hitless manual cryptographic key refresh scheme, a state machine is independently maintained at each network node. The state machine includes a first state, a second state, and a third state. In the first state, which is the steady state, a current cryptographic key is used both for generating signatures for outgoing packets and for authenticating signatures of incoming packets. In the second state, which is entered when a new cryptographic key is provisioned, the old (i.e. formerly current) key is still used for generating signatures for outgoing packets, however one or, if necessary, both of the old key and the newly provisioned key is used for authenticating signatures of incoming packets. In the third state, the new key is used for generating signatures for outgoing packets and either one or both of the old key and new key are used for authenticating signatures of incoming packets.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.