EP1997263B1

Techniques for managing keys using a key server in a network segment

Abstract

This record has no abstract on file.

EP1997263B1, drawing sheet 1
Sheet 1 of 7

Term

0.5 yearsleft in the term

Expires 15 March 2027.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

24 claims: 4 independent, 20 dependent

  1. 1
    A method for determining a new key server in a network segment, the method comprising:receiving, at a first key receiver (103), a first secure key (SAK, SAK2) from a first key server (102), the first secure key used by the first key receiver in encrypting data communications sent in the network segment;determining, at the first key receiver, that a new key server needs to be elected in response to the first key server becoming unavailable;if a new key server needs to be elected, determining device information previously received from one or more further key receivers in the network segment;and automatically electing the new key server (103) from a group of the first key receiver and the one or more further key receivers based on the device information from the one or more key receivers, the election automatically performed separately at the first key receiver, wherein the elected new key server is configured to provide a second secure key (SAK3) to key receivers that are not elected the new key server in the group of the first key receiver and the one or more further key receivers.
  2. 14
    A method for managing secure keys for a first device and a second device using first and second key servers in a network segment, the method comprising:receiving at the first key server (102), from the first device (103), a first request for a first secure key, the first secure key used in encrypting data communications sent in the network segment;sending, from the first key server, a response to the first device, the response including the first secure key;receiving at the first key server, from the second device (103), a second request for the first secure key;sending, from the first key server, a second response to the second device, the second response including the first secure key, electing, by the first and second devices, a second key server (103) to provide a second secure key when it is determined that the first key server has become unavailable, the election performed separately by each of the first device and the second device;and providing the second secure key to the first and second devices by the elected second key server.
  3. 23
    A device (103) configured to determine a new key server in a network segment, the device comprising:means for receiving a first secure key (SAK, SAK2) from a first key server (102);means for determining that a new key server needs to be elected in response to the first key server becoming unavailable;means for determining key receiver information previously received from one or more key receivers in the network segment;and means for automatically electing the new key server from a group of the device and the one or more key receivers based on the key receiver information from one or more key receivers, the election automatically performed separately at the device, wherein the elected key server is configured to provide a second secure key to key receivers that are not elected the new key server in the group of the device and the one or more key receivers.
  4. 24
    A system configured to manage secure keys for devices in a network segment, the system comprising:a first device and second device in the network segment;a key server having means for receiving, from the first and second devices, requests for a first secure key, the first secure key used in encrypting data communications sent to devices in the network segment, and means for sending responses to the first and second devices, the responses including the first secure key;wherein the first device and the second device are configured to automatically elect a second key server to provide a second secure key when it is determined the first key server becomes unavailable, the election performed separately by each of the first device and the second device.