发明名称 Cryptographic material renewal
摘要 A method and apparatus for renewing cryptographic material are disclosed. In the method and apparatus a cryptographic material renewal entity of a computing resource service provider detects that cryptographic material stored by a secure module is to be renewed. Renewing the cryptographic material may include rekeying a private key associated with a certificate. Further, a digital certificate may be renewed, and the renewed certificate may be provided for use by the computing resource. The cryptographic material is used to fulfill requests made by a computing resource provisioned by the computing resource service provider for a customer. The renewed cryptographic material is provided to the secure module, whereby the renewed cryptographic material is used by the secure module to fulfill further requests made by the computing resource.
申请公布号 US9552485(B1) 申请公布日期 2017.01.24
申请号 US201414520168 申请日期 2014.10.21
申请人 Amazon Technologies, Inc. 发明人 Cignetti Todd Lawrence;Doane Andrew Jeffrey;Popoveniuc Stefan;Estes Matthew Allen;Schoof Alexander Edward;Fitzgerald Robert Eric;Bowen Peter Zachary
分类号 H04L29/06;G06F21/60;H04L9/32 主分类号 H04L29/06
代理机构 Davis Wright Tremaine LLP 代理人 Davis Wright Tremaine LLP
主权项 1. A computer-implemented method for renewing cryptographic material, comprising: under the control of one or more computer systems configured with executable instructions, receiving, from a customer of a plurality of customers of a computing resource service provider, a request to automatically renew cryptographic material made available for use by a virtual computer system provisioned for the customer by the computing resource service provider, the request being made as an application programming interface function call to the computing resource service provider;detecting, by a renewal agent of the computing resource service provider, that the cryptographic material made available for use by the virtual computer system is to be renewed, the detecting being based at least in part on the request to automatically renew the cryptographic material and the cryptographic material being stored by a secure module that includes a datastore and an associated cryptoprocessor configured to perform a set of cryptographic operations using the cryptographic material, the secure module logically attached to the virtual computer system;obtaining renewed cryptographic material; andproviding the renewed cryptographic material to the secure module in a manner enabling the virtual computer system to programmatically cause the secure module to use the renewed cryptographic material to perform cryptographic operations, providing the renewed cryptographic material being performed without updating a manner in which the virtual computer system programmatically interacts with the secure module.
地址 Seattle WA US