EP1997263A2

Techniques for managing keys using a key server in a network segment

Abstract

This record has no abstract on file.

Term

0.5 yearsto projected expiry

Projected expiry 15 March 2027, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

43 claims: 6 independent, 37 dependent

  1. 1
    Claims of equivalent WO 2007109493 A2 Claims We claim:1. A method for determining a new key server in a network segment, wherein a first key server provides a first secure key to key receivers in the network segment, the method comprising: determining, at a first key receiver, if a new key server needs to be elected;if a new key server needs to be elected, determining device information previously received from one or more key receivers in the network segment;and automatically electing the new key server from a group of the first key receiver and the one or more key receivers based on the device information from the one or more key receivers, the election automatically performed separately at the first key receiver, wherein the elected new key server is configured to provide a second secure key to key receivers that are not elected the new key server in the group of the first key receiver and the one or more key receivers.
  2. 14
    A method for managing secure keys for a first device and a second device using a first key server in a network segment, the method comprising:receiving at the first key server, from the first device, a first request for a first secure key, the first secure key used in encrypting data communications sent in the network segment;sending, from the first key server, a response to the first device, the response including the first secure key;receiving at the first key server, from the second device, a second request for the first secure key;and sending, from the first key server, a second response to the second device, the second response including the first secure key, wherein the first device and the second device are configured to automatically elect a second key server to provide a second secure key when it is determined that the first key server has become unavailable, the election performed separately by each of the first device and the second device.
  3. 22
    A device configured to determine a new key server in a network segment, wherein a first key server provides a first secure key to key receivers in the network segment, the device comprising:logic configured to determine if a new key server needs to be elected;logic configured to determine key receiver information previously received from one or more key receivers in the network segment;and logic configured to automatically elect the new key server from a group of the device and the one or more key receivers based on the key receiver information from one or more key receivers, the election automatically performed separately at the device, wherein the elected key server is configured to provide a second secure key to key receivers that are not elected the new key server in the group of the device and the one or more key receivers.
  4. 34
    A first key server configured to manage secure keys for a first device and a second device in a network segment, the key receiver comprising:logic configured to receive, from the first device, a first request for a first secure key, the first secure key used in encrypting data communications sent to devices in the network segment;logic configured to send a response to the first device, the response including the first secure key;logic configured to receive, from the second device, a second request for the first secure key;and logic configured to send a second response to the second device, the second response including the first secure key, wherein the first device and the second device are configured to automatically elect a second key server to provide a second secure key when it is determined the first key server becomes unavailable, the election performed separately by each of the first device and the second device.
  5. 42
    A device configured to determine a new key server in a network segment, wherein a first key server provides a first secure key to key receivers in the network segment, the device comprising:means for determining if a new key server needs to be elected;means for determining key receiver information previously received from one or more key receivers in the network segment;and means for automatically electing the new key server from a group of the device and the one or more key receivers based on the key receiver information from one or more key receivers, the election automatically performed separately at the device, wherein the elected key server is configured to provide a second secure key to key receivers that are not elected the new key server in the group of the device and the one or more key receivers.
  6. 43
    A first key server configured to manage secure keys for a first device and a second device in a network segment, the key receiver comprising:means for receiving, from the first device, a first request for a first secure key, the first secure key used in encrypting data communications sent to devices in the network segment;means for sending a response to the first device, the response including the first secure key;means for receiving, from the second device, a second request for the first secure key;and means for sending a second response to the second device, the second response including the first secure key, wherein the first device and the second device are configured to automatically elect a second key server to provide a second secure key when it is determined the first key server becomes unavailable, the election performed separately by each of the first device and the second device.