发明申请
- 专利标题: SYSTEM AND METHOD FOR PROTECTING DATA IN A SECURE SYSTEM
- 专利标题(中): 用于保护安全系统中的数据的系统和方法
-
申请号: US12133658申请日: 2008-06-05
-
公开(公告)号: US20090323970A1公开(公告)日: 2009-12-31
- 发明人: Julian A. Cerruti , Sigfredo I. Nin , Dulce B. Ponceleon , Vladimir Zbarsky
- 申请人: Julian A. Cerruti , Sigfredo I. Nin , Dulce B. Ponceleon , Vladimir Zbarsky
- 申请人地址: US NY Armonk
- 专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人地址: US NY Armonk
- 主分类号: H04L9/08
- IPC分类号: H04L9/08 ; H04L9/14 ; G06F11/07
摘要:
A system for protecting data in a security system generates and encodes a backup key for encoding long-lived secrets. The system generates a distribution plan for distributing cryptographic splits of the encoded backup key to selected persons based on geographic and organizational diversity. The distribution plan specifies a number M of the cryptographic splits to be generated and a number N of the cryptographic splits required to recover the backup key. The system processes utilize an init file comprising system parameters and state files each comprising parameters reflecting a state of the secure system after a transaction. Any of the state files may be used for any of the system processes. The state files and the init file are encoded by the backup key, thus protecting the long-lived secrets.
公开/授权文献
- US08280043B2 System and method for protecting data in a secure system 公开/授权日:2012-10-02
信息查询