[go: up one dir, main page]

MX2019007185A - Suministro seguro de certificados unicos por tiempo limitado a instancias de aplicación virtual en sistemas dinamicos y elasticos. - Google Patents

Suministro seguro de certificados unicos por tiempo limitado a instancias de aplicación virtual en sistemas dinamicos y elasticos.

Info

Publication number
MX2019007185A
MX2019007185A MX2019007185A MX2019007185A MX2019007185A MX 2019007185 A MX2019007185 A MX 2019007185A MX 2019007185 A MX2019007185 A MX 2019007185A MX 2019007185 A MX2019007185 A MX 2019007185A MX 2019007185 A MX2019007185 A MX 2019007185A
Authority
MX
Mexico
Prior art keywords
dynamic
certificates
instances
limited time
virtual application
Prior art date
Application number
MX2019007185A
Other languages
English (en)
Inventor
Medvinsky Alexander
B Prickett David
Original Assignee
Arris Entpr Llc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Arris Entpr Llc filed Critical Arris Entpr Llc
Publication of MX2019007185A publication Critical patent/MX2019007185A/es

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • H04L9/3268Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements using certificate validation, registration, distribution or revocation, e.g. certificate revocation list [CRL]
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/10Protecting distributed programs or content, e.g. vending or licensing of copyrighted material ; Digital rights management [DRM]
    • G06F21/12Protecting executable software
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/51Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems at application loading time, e.g. accepting, rejecting, starting or inhibiting executable software based on integrity or source reliability
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/602Providing cryptographic facilities or services
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/06Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols the encryption apparatus using shift registers or memories for block-wise or stream coding, e.g. DES systems or RC4; Hash functions; Pseudorandom sequence generators
    • H04L9/0618Block ciphers, i.e. encrypting groups of characters of a plain text message using fixed encryption transformation
    • H04L9/0631Substitution permutation network [SPN], i.e. cipher composed of a number of stages or rounds each involving linear and nonlinear transformations, e.g. AES algorithms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0822Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using key encryption key

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Software Systems (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Multimedia (AREA)
  • Technology Law (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Storage Device Security (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

Se proporciona un método para suministrar automáticamente Certificados X.509 únicos y Claves privadas en Instancias de aplicación en ambiente de nube dinámica y elástica. El método proporciona un medio de creación de una identidad segura para utilizar en comunicaciones seguras y asignación de recursos. La seguridad del suministro se garantiza por el hecho de que un Orquestador ejecuta la instancia de aplicación y luego suministra directamente el certificado y la clave. Como una medida de seguridad adicional, los certificados tendrán un tiempo de validez limitado, con el fin de reducir el impacto de un certificado emitido de manera incorrecta.
MX2019007185A 2016-12-19 2017-12-05 Suministro seguro de certificados unicos por tiempo limitado a instancias de aplicación virtual en sistemas dinamicos y elasticos. MX2019007185A (es)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US15/384,256 US10432407B2 (en) 2016-12-19 2016-12-19 Secure provisioning of unique time-limited certificates to virtual application instances in dynamic and elastic systems
PCT/US2017/064727 WO2018118418A1 (en) 2016-12-19 2017-12-05 Secure provisioning of unique time-limited certificates to virtual application instances in dynamic and elastic systems

Publications (1)

Publication Number Publication Date
MX2019007185A true MX2019007185A (es) 2020-02-10

Family

ID=60782381

Family Applications (1)

Application Number Title Priority Date Filing Date
MX2019007185A MX2019007185A (es) 2016-12-19 2017-12-05 Suministro seguro de certificados unicos por tiempo limitado a instancias de aplicación virtual en sistemas dinamicos y elasticos.

Country Status (5)

Country Link
US (1) US10432407B2 (es)
EP (1) EP3555786B1 (es)
CA (1) CA3047551C (es)
MX (1) MX2019007185A (es)
WO (1) WO2018118418A1 (es)

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11151253B1 (en) * 2017-05-18 2021-10-19 Wells Fargo Bank, N.A. Credentialing cloud-based applications
US11316666B2 (en) * 2017-07-12 2022-04-26 Amazon Technologies, Inc. Generating ephemeral key pools for sending and receiving secure communications
US11082412B2 (en) 2017-07-12 2021-08-03 Wickr Inc. Sending secure communications using a local ephemeral key pool
US10931517B2 (en) * 2017-07-31 2021-02-23 Vmware, Inc. Methods and systems that synchronize configuration of a clustered application
US11496322B2 (en) * 2018-05-21 2022-11-08 Entrust, Inc. Identity management for software components using one-time use credential and dynamically created identity credential
US11122014B2 (en) * 2019-01-25 2021-09-14 V440 Spółka Akcyjna User device and method of providing notification in messaging application on user device
US11226845B2 (en) 2020-02-13 2022-01-18 International Business Machines Corporation Enhanced healing and scalability of cloud environment app instances through continuous instance regeneration
US12500778B2 (en) * 2020-05-26 2025-12-16 Verizon Patent And Licensing Inc. Systems and methods for managing public key infrastructure certificates for components of a network
US12314410B2 (en) * 2022-06-03 2025-05-27 International Business Machines Corporation Data cluster management
US12244736B2 (en) * 2023-02-01 2025-03-04 Musaruba Us Llc Methods and apparatus for secure configuration of a compute device
US20250337599A1 (en) * 2024-04-26 2025-10-30 Oracle International Corporation System And Method For Managing Secure Shell Protocol Access In Cloud Infrastructure Environments

Family Cites Families (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6108788A (en) * 1997-12-08 2000-08-22 Entrust Technologies Limited Certificate management system and method for a communication security system
US7835520B2 (en) * 2003-02-20 2010-11-16 Zoran Corporation Unique identifier per chip for digital audio/video data encryption/decryption in personal video recorders
US8924469B2 (en) * 2008-12-18 2014-12-30 Headwater Partners I Llc Enterprise access control and accounting allocation for access networks
US20110138177A1 (en) * 2009-12-04 2011-06-09 General Instrument Corporation Online public key infrastructure (pki) system
US8997093B2 (en) * 2012-04-17 2015-03-31 Sap Se Application installation management by selectively reuse or terminate virtual machines based on a process status
US9313203B2 (en) * 2013-03-15 2016-04-12 Symantec Corporation Systems and methods for identifying a secure application when connecting to a network
US9515832B2 (en) * 2013-06-24 2016-12-06 Microsoft Technology Licensing, Llc Process authentication and resource permissions
US9485099B2 (en) * 2013-10-25 2016-11-01 Cliqr Technologies, Inc. Apparatus, systems and methods for agile enablement of secure communications for cloud based applications
GB2519826B (en) * 2013-10-30 2016-07-20 Barclays Bank Plc Transaction authentication
WO2015143651A1 (zh) 2014-03-26 2015-10-01 华为技术有限公司 基于网络功能虚拟化的证书配置方法、装置和系统
US10069914B1 (en) * 2014-04-21 2018-09-04 David Lane Smith Distributed storage system for long term data storage
US10454900B2 (en) * 2015-09-25 2019-10-22 Mcafee, Llc Remote authentication and passwordless password reset

Also Published As

Publication number Publication date
CA3047551C (en) 2024-07-02
EP3555786A1 (en) 2019-10-23
WO2018118418A1 (en) 2018-06-28
US10432407B2 (en) 2019-10-01
CA3047551A1 (en) 2018-06-28
US20180176023A1 (en) 2018-06-21
EP3555786B1 (en) 2022-11-09

Similar Documents

Publication Publication Date Title
MX2019007185A (es) Suministro seguro de certificados unicos por tiempo limitado a instancias de aplicación virtual en sistemas dinamicos y elasticos.
MX2019008945A (es) Certificado de origen basado en la emision de certificados en linea.
MX2021014176A (es) Metodo y sistema para una variante de cadena de bloques utilizando firmas digitales.
CL2018002362A1 (es) Almacenamiento y transferencia seguros resistentes a pérdida de múltiples partes de claves criptográficas para sistemas a base de cadena de bloques en conjunto con un sistema de administración de billetera.
BR112017020675A2 (pt) acordo de autenticação e chave com sigilo perfeito de emissão
PH12016501640A1 (en) Techniques to operate a service with machine generated authentication tokens
GB2525719A8 (en) Method and system for providing a vulnerability management and verification service
BR112017002747A2 (pt) método implementado por computador, e, sistema de computador.
MX390620B (es) Metodo y sistema para la provision y almacenamiento de claves criptograficas distribuidas mediante criptografia de curva eliptica.
BR112016028287A2 (pt) geração de assinatura digital semideterminística
BR112019001011A2 (pt) estabelecimento de canal seguro
BR112017017098A2 (pt) aparelhos, métodos e sistemas de agente de chave de criptografia de nuvem
BR112017020724A2 (pt) método, e, dispositivo de comunicação
TW201613416A (en) Node-to-multinode communication
MX352389B (es) Sistema y método para actualización de una clave de cifrado a través de una red.
EP3729258C0 (en) AMPLIFICATION, GENERATION OR CERTIFICATION OF RANDOMNESS
MX2016011306A (es) Mejoramiento de señales de referencia para una celula compartida.
MX2016011362A (es) Planificacion de comunicaciones de dispositivo a dispositivo.
BR112015019378A2 (pt) serviço de segurança de dados
AR105799A1 (es) Suministro de recursos
MX373229B (es) Aceleración de la verificación del estado de un certificado en línea con un servicio de sugerencias de internet.
GB201703301D0 (en) Password-based generation and management of secret cryptographic keys
GB2574545A (en) Security credentials
WO2015099635A3 (en) Resource classification using resource requests
BR112018009640A2 (pt) delegação de transações