发明名称 Handling key rotation problems
摘要 Example embodiments include centralized systems for managing cryptographic keys and trust relationships among systems. Embodiments may include a centralized key store and a centralized policy store. Key sets comprising public/private keys may be stored in or identified by key objects. Key objects within the key store may be organized into trust sets and policies may apply at any level within the key store. Policies may identify when to rotate key sets. When rotating key sets, a new public key and a new private key may be generated. The new public/private keys may be installed at locations where the old public/private keys reside. As the new public/private keys are installed, they may be tested. If problems with the new public/private keys occur, the new public/private keys may be rolled back to the old public/private keys for locations experiencing problems. Remedial action may then be taken to resolve the problems.
申请公布号 US9369279(B2) 申请公布日期 2016.06.14
申请号 US201314034091 申请日期 2013.09.23
申请人 Venafi, Inc. 发明人 Harjula Tero Petteri;McCartney Breon Malachy;Saura Asko Juha
分类号 H04L9/08 主分类号 H04L9/08
代理机构 Schwegman Lundberg & Woessner, P.A. 代理人 Schwegman Lundberg & Woessner, P.A.
主权项 1. A method comprising: generating, via a processor of a computing device, a new key pair having a new public key and a new private key; retaining a copy of an old key pair having an old public key and and an old private key so the old public key and the old private key are not lost when the new private key and new public key are installed; installing the new public key at all locations where the old public key resides; installing the new private key at all locations where the old private key resides; testing the new key pair to identify whether the keys function properly; and responsive to detecting the keys are not functioning properly, performing key rollback by reinstalling the old private key and discontinuing use of the new private key.
地址 Salt Lake City UT US