US2007189541A1PendingUtilityA1
Method and system for initialzing a key management system
Est. expiryDec 21, 2021(expired)· nominal 20-yr term from priority
H04L 9/083H04L 9/0894G06Q 20/382G06Q 20/367H04L 2209/60H04L 9/0822H04L 63/0428H04L 63/06
45
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A network system for key management including a server, a key management system providing process logic for key management system initialization located on the server, a key management system storage providing a secure data storage for the key management system, and an interface providing a means for inputting data into the key management system.
Claims
exact text as granted — not AI-modified1 - 35 . (canceled)
36 . A method for securing data in a key management system (KMS), comprising:
receiving the data in the KMS, wherein the data comprises a key name, a key value, and a key type; receiving a key encryption key (KEK) in the KMS; encrypting the data using the KEK to generate a secret token; hashing the KEK to generate a hashed KEK; generating a data structure comprising the secret token and the hashed KEK; and storing the data structure in a KMS storage.
37 . The method of claim 36 , further comprising:
storing the data in a data structure prior to encrypting the data.
38 . The method of claim 37 , further comprising:
encoding the key name to obtain an encoded key name after storing the key name in the data structure.
39 . The method of claim 38 , wherein the data structure comprises an encoded key list and wherein the encoded key list comprises the encoded key name.
40 . The method of claim 36 , further comprising:
associating the secret token with an application.
41 . The method of claim 40 , wherein the data structure comprises an application name tag corresponding to the application.
42 . The method of claim 36 , wherein storing the data structure comprises:
serializing the data structure to generate a serialized file; and storing the serialized file in the KMS storage.
43 . The method of claim 36 , wherein encrypting the data comprises using one selected from a group consisting of a symmetric algorithm and an asymmetric algorithm.
44 . The method of claim 36 , wherein the data is received from a client over a network.
45 . The method of claim 36 , wherein the KEK is received from a client using a security device interfacing over the network with the KMS and wherein the security device stores the KEK.
46 . The method of claim 36 , wherein the data is encrypted by the KMS.
47 . A system for securing data, comprising:
a key management system (KMS) configured to receive data and a key encryption key (KEK), comprising:
an encryption module configured to encrypt the data using the KEK to generate a secret token;
a hashing module configured to hash the KEK to generate a hashed KEK;
a serialization module configured to generate a data structure comprising the secret token and the hashed KEK; and
a KMS storage configured to store the data structure, wherein the data comprises a key name, a key value, and a key type.
48 . The system of claim 47 , further comprising:
a graphical user interface configured to receive the data.
49 . The system of claim 48 , wherein the graphical user interface is integrated into a web browser.
50 . The system of claim 47 , wherein the data is received from a client over a network.
51 . The system of claim 47 , wherein the KEK is received from a client using a security device interfacing over the network with the KMS, and wherein the security device stores the KEK.
52 . The system of claim 47 , wherein the data structure is stored in the KMS storage as a serialized file.
53 . The system of claim 47 , wherein the KMS is further configured to store the data in a data structure prior to encrypting the data.
54 . The system of claim 53 , wherein the encoding module is further configured to encode the key name to obtain an encoded key name after the key name is stored in the data structure.
55 . The system of claim 54 , wherein the data structure comprises an encoded key list comprising the encoded key name.
56 . The system of claim 47 , wherein the KMS is further configured to:
tag the secret token to associate the secret token with an application, wherein the data structure further comprises the tag.
57 . A computer readable medium storing instructions for execution on a processor, wherein the instructions comprise functionality to:
receive the data in the KMS, wherein the data comprises a key name, a key value, and a key type; receive a key encryption key (KEK) in the KMS; encrypt the data using the KEK to generate a secret token; hash the KEK to generate a hashed KEK; generate a data structure comprising the secret token and the hashed KEK; and store the data structure in a KMS storage.Join the waitlist — get patent alerts
Track US2007189541A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.