发明申请
US20130044882A1 Enhancing provisioning for keygroups using key management interoperability protocol (KMIP)
审中-公开
使用密钥管理互操作协议(KMIP)增强密钥组的配置
- 专利标题: Enhancing provisioning for keygroups using key management interoperability protocol (KMIP)
- 专利标题(中): 使用密钥管理互操作协议(KMIP)增强密钥组的配置
-
申请号: US13213191申请日: 2011-08-19
-
公开(公告)号: US20130044882A1公开(公告)日: 2013-02-21
- 发明人: Bruce Arland Rich , John Thomas Peck
- 申请人: Bruce Arland Rich , John Thomas Peck
- 申请人地址: US NY Armonk
- 专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人: INTERNATIONAL BUSINESS MACHINES CORPORATION
- 当前专利权人地址: US NY Armonk
- 主分类号: H04L9/08
- IPC分类号: H04L9/08
摘要:
A key management protocol (such as Key Management Interoperability Protocol (KMIP)) is extended via set of one or more custom attributes to provide a mechanism by which clients pass additional metadata to facilitate enhanced key provisioning operations by a key management server. The protocol comprises objects, operations, and attributes. Objects are the cryptographic material (e.g., symmetric keys, asymmetric keys, digital certificates and so on) upon which operations are performed. Operations are the actions taken with respect to the objects, such as getting an object from a key management server, modifying attributes of an object and the like. Attributes are the properties of the object, such as the kind of object it is, the unique identifier for the object, and the like. According to this disclosure, a first custom server attribute has a value that specifies a keygroup name that can be used by the key management server to locate (e.g., during a Locate operation) key material associated with a named keygroup. A second custom server attribute has a value that specifies a keygroup name into which key material should be registered (e.g., during a Register operation) by the server. A third custom server attribute has a value that specifies a default keygroup that the server should use for the device passing a request that include the attribute. Using these one or more custom server attributes, the client taps into and consumes/contributes to the key management server's provisioning machinery.
信息查询