-
1.
公开(公告)号:US10764261B2
公开(公告)日:2020-09-01
申请号:US14588042
申请日:2014-12-31
Applicant: Silver Spring Networks, Inc.
Inventor: Christopher Vigliaturo , Benjamin Damm , David Drinan , Aditi Hilbert
IPC: H04L29/06
Abstract: A method for enabling a scalable public-key infrastructure (PKI) comprises invoking a process of receiving a message for a device, identifying an association ID for the device, retrieving encrypted association keys stored on the server for communicating with the device, the encrypted association keys encrypted using a wrapping key stored on a Hardware Security Module (HSM). The method further comprises sending the message and the encrypted association keys to the HSM, unwrapping, by the HSM, the encrypted association keys to create unwrapped association keys, cryptographically processing the message to generate a processed message, deleting the unwrapped association keys, sending the processed message to the device, and invoking, concurrently and by a second application, the process.
-
公开(公告)号:US20150156180A1
公开(公告)日:2015-06-04
申请号:US14588042
申请日:2014-12-31
Applicant: Silver Spring Networks, Inc.
Inventor: Christopher Vigliaturo , Benjamin Damm , David Drinan , Aditi Hilbert
IPC: H04L29/06
CPC classification number: H04L63/0471 , H04B2203/5433 , H04L63/0281 , Y04S40/24
Abstract: A method for enabling a scalable public-key infrastructure (PKI) comprises invoking a process of receiving a message for a device, identifying an association ID for the device, retrieving encrypted association keys stored on the server for communicating with the device, the encrypted association keys encrypted using a wrapping key stored on a Hardware Security Module (HSM). The method further comprises sending the message and the encrypted association keys to the HSM, unwrapping, by the HSM, the encrypted association keys to create unwrapped association keys, cryptographically processing the message to generate a processed message, deleting the unwrapped association keys, sending the processed message to the device, and invoking, concurrently and by a second application, the process.
Abstract translation: 一种用于启用可扩展公钥基础结构(PKI)的方法包括:调用接收设备的消息的过程,识别该设备的关联ID,检索存储在该服务器上用于与该设备通信的加密关联密钥,该加密关联 使用存储在硬件安全模块(HSM)上的包装密钥加密的密钥。 该方法还包括将消息和加密的关联密钥发送到HSM,由HSM解包加密的关联密钥以创建未包裹的关联密钥,密码处理消息以生成经处理的消息,删除未包装关联密钥,发送 处理的消息到设备,并且同时和第二应用调用该过程。
-