Invention Grant
- Patent Title: System and method for protecting data in a secure system
- Patent Title (中): 用于在安全系统中保护数据的系统和方法
-
Application No.: US12133658Application Date: 2008-06-05
-
Publication No.: US08280043B2Publication Date: 2012-10-02
- Inventor: Julian A. Cerruti , Sigfredo I Nin , Dulce B Ponceleon , Vladimir Zbarsky
- Applicant: Julian A. Cerruti , Sigfredo I Nin , Dulce B Ponceleon , Vladimir Zbarsky
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Shimokaji & Assoc., PC
- Main IPC: H04L9/00
- IPC: H04L9/00 ; H04N7/167

Abstract:
A system for protecting data in a security system generates and encodes a backup key for encoding long-lived secrets. The system generates a distribution plan for distributing cryptographic splits of the encoded backup key to selected persons based on geographic and organizational diversity. The distribution plan specifies a number M of the cryptographic splits to be generated and a number N of the cryptographic splits required to recover the backup key. The system processes utilize an init file comprising system parameters and state files each comprising parameters reflecting a state of the secure system after a transaction. Any of the state files may be used for any of the system processes. The state files and the init file are encoded by the backup key, thus protecting the long-lived secrets.
Public/Granted literature
- US20090323970A1 SYSTEM AND METHOD FOR PROTECTING DATA IN A SECURE SYSTEM Public/Granted day:2009-12-31
Information query