Event-driven, asset-centric key management in a smart grid
First Claim
1. A method of key management in a delivery network comprising a plurality of nodes, each node supporting an entity, comprising:
- responsive to occurrence of an event, generating a set of event-asset associations by identifying one or more configuration records, and identifying one or more assets defined in the identified configuration records that may have generated the event, wherein the one or more assets are identified by examining a configuration of assets in an asset database associated with the delivery network to identify each event-asset association;
using the set of event-asset associations so generated, cross-referencing a first event-asset association that is associated with a first application software system, with a second event-asset association that is associated with a second application software system, the second application software system being distinct from the first application software system, to thereby generate cross-referenced event-asset associations for the first and second application software systems;
based at least on the cross-referenced event-asset associations, deriving a key handle;
using the key handle to initiate a key management operation; and
performing the key management operation for each of the first and second application software systems as a response to the event;
wherein the delivery network is a smart grid, and the nodes are one of;
a meter device, and a business application.
1 Assignment
0 Petitions
Accused Products
Abstract
A security management system comprises a key management sub-system, an asset/workload management sub-system, and an event management sub-system. The event management sub-system detects events. The asset/workload management sub-system correlates events (irrespective of type) with the assets that generate them, and the key management sub-system uses the event-asset associations determined by the asset/workload management sub-system to automatically orchestrate the necessary key management activities (e.g., key creation, revocation, refresh, etc.) across the impacted components in the information technology and operational realms to ensure data security. In one use case, a security event detected by the event management sub-system triggers one or more actions within the asset/workload management sub-system. Service configuration records are identified from this scan, and assets defined in those records are identified. An event-asset association is then supplied to the key management sub-system, which uses this information to determine a key management operation.
11 Citations
14 Claims
-
1. A method of key management in a delivery network comprising a plurality of nodes, each node supporting an entity, comprising:
-
responsive to occurrence of an event, generating a set of event-asset associations by identifying one or more configuration records, and identifying one or more assets defined in the identified configuration records that may have generated the event, wherein the one or more assets are identified by examining a configuration of assets in an asset database associated with the delivery network to identify each event-asset association; using the set of event-asset associations so generated, cross-referencing a first event-asset association that is associated with a first application software system, with a second event-asset association that is associated with a second application software system, the second application software system being distinct from the first application software system, to thereby generate cross-referenced event-asset associations for the first and second application software systems; based at least on the cross-referenced event-asset associations, deriving a key handle; using the key handle to initiate a key management operation; and performing the key management operation for each of the first and second application software systems as a response to the event; wherein the delivery network is a smart grid, and the nodes are one of;
a meter device, and a business application. - View Dependent Claims (2, 3, 4, 5)
-
-
6. Apparatus, comprising:
-
a processor; computer memory holding computer program instructions that when executed by the processor perform a method of key management in a delivery network comprising a plurality of nodes, each node supporting an entity, the method comprising; responsive to occurrence of an event, generating a set of event-asset associations by identifying one or more configuration records, and identifying one or more assets defined in the identified configuration records that may have generated the event, wherein the one or more assets are identified by examining a configuration of assets in an asset database associated with the delivery network to identify each event-asset association; using the set of event-asset associations so generated, cross-referencing a first event-asset association that is associated with a first application software system, with a second event-asset association that is associated with a second application software system, the second application software system being distinct from the first application software system, to thereby generate cross-referenced event-asset associations for the first and second application software systems; based at least on the cross-referenced event-asset associations, deriving a key handle; using the key handle to initiate a key management operation; and performing the key management operation for each of the first and second application software systems as a response to the event; wherein the delivery network is a smart grid, and the nodes are one of;
a meter device, and a business application. - View Dependent Claims (7, 8, 9, 10)
-
-
11. A computer program product in a non-transitory computer readable medium for use in a data processing system, the computer program product holding computer program instructions which, when executed by the data processing system, perform a method of key management in a delivery network comprising a plurality of nodes, each node supporting an entity, the method comprising:
-
responsive to occurrence of an event, generating a set of event-asset associations by identifying one or more configuration records, and identifying one or more assets defined in the identified configuration records that may have generated the event, wherein the one or more assets are identified by examining a configuration of assets in an asset database associated with the delivery network to identify each event-asset associations; using the set of event-asset associations so generated, cross-referencing a first event-asset association that is associated with a first application software system, with a second event-asset association that is associated with a second application software system, the second application software system being distinct from the first application software system, to thereby generate cross-referenced event-asset associations for the first and second application software systems; based at least on the cross-referenced event-asset associations, deriving a key handle; using the key handle to initiate a key management operation; and performing the key management operation for each of the first and second application software systems as a response to the event; wherein the delivery network is a smart grid, and the nodes are one of;
a meter device, and a business application. - View Dependent Claims (12, 13, 14)
-
Specification