×

SESSION NEGOTIATIONS

  • US 20180083929A1
  • Filed: 11/27/2017
  • Published: 03/22/2018
  • Est. Priority Date: 06/13/2013
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method, comprising:

  • under the control of one or more computer systems configured with executable instructions,at a first security module of a plurality of security modules;

    receiving, from an operator device, a first request for a session key;

    in response to the first request, using a domain key to encrypt one or more session keys and information usable to identify the operator device, the domain key accessible to each of the plurality of security modules;

    providing the one or more session keys and encrypted one or more session keys to the operator device; and

    at a second security module of the plurality of security modules;

    receiving, from the operator device, a second request to perform a cryptographic operation, the second request including an encrypted session key from the encrypted one or more session keys and a digital signature generated based at least in part on the session key;

    using the domain key to decrypt the encrypted session key and the information usable to identify the operator device;

    verifying that the operator device matches the information usable to identify the operator deviceusing the session key to verify the digital signature; and

    as a result of verifying the digital signature and verifying that the operator device matches the information usable to identify the operator device, performing the requested cryptographic operation;

    using the session key to encrypt a result of performing the requested cryptographic operation; and

    providing the encrypted result to the operator device.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×