×

MANAGING KEY ROTATIONS WITH MULTIPLE KEY MANAGERS

  • US 20170141916A1
  • Filed: 11/16/2015
  • Published: 05/18/2017
  • Est. Priority Date: 11/16/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • generating, by a network device, a request to obtain a resource object stored in a clustered network database that stores keys;

    transmitting, by the network device, the request to the clustered network database;

    receiving, by the network device, a response to the request;

    determining, by the network device, based on a value of the resource object carried in the response, whether permission to update the keys is permitted, wherein a first value of the resource object grants permission to update the keys and a second value of the resource object does not grant permission to update the keys, wherein the first value and the second value are different;

    determining, by the network device, whether any of the keys expired in response to determining that the value of the resource object corresponds to the first value indicating that permission is granted to update the keys, and wherein other network devices that are configured to update the keys are prevented from updating the keys stored in the clustered network database while the network device is granted permission to update the keys;

    generating, by the network device, a new key for each key of the keys that expired, in response to determining that one or more of the keys expired;

    storing, by the network device, the new key for each key of the one or more of the keys at the clustered network database; and

    releasing, by the network device, the resource object back to the clustered network database.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×