US2007189541A1PendingUtilityA1

Method and system for initialzing a key management system

Assignee: SCHLUMBERGER OMNES INCPriority: Dec 21, 2001Filed: Mar 26, 2007Published: Aug 16, 2007
Est. expiryDec 21, 2021(expired)· nominal 20-yr term from priority
H04L 9/083H04L 9/0894G06Q 20/382G06Q 20/367H04L 2209/60H04L 9/0822H04L 63/0428H04L 63/06
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A network system for key management including a server, a key management system providing process logic for key management system initialization located on the server, a key management system storage providing a secure data storage for the key management system, and an interface providing a means for inputting data into the key management system.

Claims

exact text as granted — not AI-modified
1 - 35 . (canceled)  
     
     
         36 . A method for securing data in a key management system (KMS), comprising: 
 receiving the data in the KMS, wherein the data comprises a key name, a key value, and a key type;    receiving a key encryption key (KEK) in the KMS;    encrypting the data using the KEK to generate a secret token;    hashing the KEK to generate a hashed KEK;    generating a data structure comprising the secret token and the hashed KEK; and    storing the data structure in a KMS storage.    
     
     
         37 . The method of  claim 36 , further comprising: 
 storing the data in a data structure prior to encrypting the data.    
     
     
         38 . The method of  claim 37 , further comprising: 
 encoding the key name to obtain an encoded key name after storing the key name in the data structure.    
     
     
         39 . The method of  claim 38 , wherein the data structure comprises an encoded key list and wherein the encoded key list comprises the encoded key name.  
     
     
         40 . The method of  claim 36 , further comprising: 
 associating the secret token with an application.    
     
     
         41 . The method of  claim 40 , wherein the data structure comprises an application name tag corresponding to the application.  
     
     
         42 . The method of  claim 36 , wherein storing the data structure comprises: 
 serializing the data structure to generate a serialized file; and    storing the serialized file in the KMS storage.    
     
     
         43 . The method of  claim 36 , wherein encrypting the data comprises using one selected from a group consisting of a symmetric algorithm and an asymmetric algorithm.  
     
     
         44 . The method of  claim 36 , wherein the data is received from a client over a network.  
     
     
         45 . The method of  claim 36 , wherein the KEK is received from a client using a security device interfacing over the network with the KMS and wherein the security device stores the KEK.  
     
     
         46 . The method of  claim 36 , wherein the data is encrypted by the KMS.  
     
     
         47 . A system for securing data, comprising: 
 a key management system (KMS) configured to receive data and a key encryption key (KEK), comprising: 
 an encryption module configured to encrypt the data using the KEK to generate a secret token;  
 a hashing module configured to hash the KEK to generate a hashed KEK;  
 a serialization module configured to generate a data structure comprising the secret token and the hashed KEK; and  
   a KMS storage configured to store the data structure,    wherein the data comprises a key name, a key value, and a key type.    
     
     
         48 . The system of  claim 47 , further comprising: 
 a graphical user interface configured to receive the data.    
     
     
         49 . The system of  claim 48 , wherein the graphical user interface is integrated into a web browser.  
     
     
         50 . The system of  claim 47 , wherein the data is received from a client over a network.  
     
     
         51 . The system of  claim 47 , wherein the KEK is received from a client using a security device interfacing over the network with the KMS, and wherein the security device stores the KEK.  
     
     
         52 . The system of  claim 47 , wherein the data structure is stored in the KMS storage as a serialized file.  
     
     
         53 . The system of  claim 47 , wherein the KMS is further configured to store the data in a data structure prior to encrypting the data.  
     
     
         54 . The system of  claim 53 , wherein the encoding module is further configured to encode the key name to obtain an encoded key name after the key name is stored in the data structure.  
     
     
         55 . The system of  claim 54 , wherein the data structure comprises an encoded key list comprising the encoded key name.  
     
     
         56 . The system of  claim 47 , wherein the KMS is further configured to: 
 tag the secret token to associate the secret token with an application, wherein the data structure further comprises the tag.    
     
     
         57 . A computer readable medium storing instructions for execution on a processor, wherein the instructions comprise functionality to: 
 receive the data in the KMS, wherein the data comprises a key name, a key value, and a key type;    receive a key encryption key (KEK) in the KMS;    encrypt the data using the KEK to generate a secret token;    hash the KEK to generate a hashed KEK;    generate a data structure comprising the secret token and the hashed KEK; and    store the data structure in a KMS storage.

Join the waitlist — get patent alerts

Track US2007189541A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.