Defined key structure for key distribution and use

A secure key structure with metadata and encryption enhances key management systems, addressing key misuse and unauthorized access, ensuring secure key distribution and mobility.

WO2026082287A1PCT designated stage Publication Date: 2026-04-23ASSA ABLOY AB +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
ASSA ABLOY AB
Filing Date
2024-10-17
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

Existing key management systems lack sufficient features to enforce security requirements, leading to risks of key misuse and loss of control over expired or compromised keys, introducing security gaps and risks.

Method used

A secure key structure is introduced, incorporating metadata such as key attributes, access control lists, lifecycle data, and protection schemes, ensuring secure key management through encryption, integrity checks, and authenticated key exchange protocols.

Benefits of technology

The secure key structure enhances key management by preventing misuse and unauthorized access, ensuring secure key distribution and mobility, and providing greater visibility and control over cryptographic keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024079345_23042026_PF_FP_ABST
    Figure EP2024079345_23042026_PF_FP_ABST
Patent Text Reader

Abstract

Various implementations of a defined key structure for the management and distribution of a cryptographic key and related metadata are described. An example method for establishing a secure key structure in a key management system includes: preparing (e.g., generating or obtaining) a cryptographic key; preparing (e.g., generating or updating) a key data structure to include the cryptographic key and properties associated with the cryptographic key, with the key data structure including key information and a signature of the key information, and with the key information including: (i) attributes associated with the cryptographic key, (ii) a secured key value that encrypts the cryptographic key, (iii) an access control list associated with access of the cryptographic key; (iv) date and time information associated with the cryptographic key, and (v) protection information associated with the cryptographic key; and outputting the key data structure from the key management system.
Need to check novelty before this filing date? Find Prior Art

Description

DEFINED KEY STRUCTURE FOR KEY DISTRIBUTION AND USETECHNICAL FIELD

[0001] Embodiments described herein generally relate to cryptography and computer security, and particularly to key management systems and the implementation of related approaches for managing keys and related credentials.BACKGROUND

[0002] Various key management systems are used in connection with the use of symmetric or asymmetric cryptographic keys, to store and track credentials for associated credential uses in a system or controlled environment. However, many key management systems do not include sufficient features to enforce current security requirements and best practices, such as features to control the occurrence of key misuse and unwanted key extraction. As a result, the risk of use of unwanted key material, and the loss of control over expired or compromised keys, may introduce a number of security gaps and risks.BRIEF SUMMARY

[0003] The following presents a simplified summary of one or more embodiments of the present disclosure in order to provide a basic understanding of such embodiments. This summary is not an extensive overview of all contemplated embodiments, and is intended to neither identify key or critical elements of all embodiments, nor delineate the scope of any or all embodiments.

[0004] The present disclosure, in one or more embodiments, relates to a method for establishing a secure key structure in a key management system, used for maintaining a cryptographic key. An example of the method includes operations for: obtaining the cryptographic key; generating a key data structure to include the cryptographic key and properties associated with the cryptographic key, where the key data structure includes key information and a signature of the key information, and where the key information includes: (i) attributes associated with the cryptographic key; (ii) a secured key value that encrypts the cryptographic key; (iii) an access control list associated with access of the cryptographic key; (iv date and time information associated with the cryptographic key; and (v) protection information associated with the cryptographic key; and outputting the key data structure from the key management system.15483.693WO1

[0005] The present disclosure, in one or more embodiments, additionally relates to a method for using a secure key structure for a cryptographic key managed by a key management system. An example of the method includes operations for: receiving a key data structure from a key management system; extracting key information from a key data structure, the key data structure including key information and a signature of the key information, where the key information comprises: (i) attributes associated with the cryptographic key; (ii) a secured key value that encrypts the cryptographic key; (iii) an access control list associated with access of the cryptographic key; (iv) date and time information associated with the cryptographic key; and (v) protection information associated with the cryptographic key; and performing an action based on the cryptographic key, based on one or more properties associated with the cryptographic key provided in the key information.

[0006] The present disclosure, in one or more embodiments, additionally relates to a non- transitory computer readable medium comprising executable program code, that when executed by one or more processors of a computing device, causes the one or more processors to perform the methods of establishing or using the secure key structure, as described herein.

[0007] The present disclosure, in one or more embodiments, additionally relates to an apparatus (e.g., a computing device, an embedded device, controller, electronic component or subsystem, etc.) comprising memory configured or adapted to store a secure key structure, and circuitry configured or adapted to perform the methods of establishing or using the secure key structure, as described herein.

[0008] While multiple embodiments are disclosed, still other embodiments of the present disclosure will become apparent to those skilled in the art from the following detailed description, which shows and describes illustrative embodiments of the invention. As will be realized, the various embodiments of the present disclosure are capable of modifications in various obvious aspects, all without departing from the scope of the present disclosure. Accordingly, the drawings and detailed description are to be regarded as illustrative in nature and not restrictive.BRIEF DESCRIPTION OF THE DRAWINGS

[0009] In the drawings, which are not necessarily drawn to scale, like numerals may describe similar components in different views. Like numerals having different letter suffixes may represent different instances of similar components. Some embodiments are25483.693WO1illustrated by way of example, and not limitation, in the figures of the accompanying drawings in which:

[0010] FIG. 1 illustrates an environment for use and distribution of cryptographic keys, according to an example;

[0011] FIGS. 2 A and 2B illustrate uses of a secure key structure via a key management system, according to an example;

[0012] FIG. 3 illustrates a schematic of a secure key structure, according to an example;

[0013] FIG. 4 illustrates a flowchart of a method of utilizing a secure key structure in a key management system, according to an example;

[0014] FIG. 5 illustrates a block diagram schematic of various components of an example electronic device configured to use a defined key structure, according to an example; and

[0015] FIG. 6 illustrates a block diagram schematic of various components of an example computing machine configured to establish a secure key structure, according to an example.DETAILED DESCRIPTION

[0016] The present disclosure generally relates to key management systems, key management operations, and related credential distribution and communication approaches. Key management systems are subject to a variety of operational and security risks and issues. For example, many types of existing key management systems are unable to fully manage or track the use of keys, and such key management systems often lack crucial key metadata and key attributes, Access Control Lists (ACLs), and lifecycle management information. This information may become essential for key management and policy enforcement, to provide and enforce secure parameter lifecycle policies. Further, many existing key management systems are non-extensible and lack the flexibility to support the distribution of both symmetric and asymmetric keys.

[0017] The following introduces a new key structure that incorporates metadata associated with a variety of key properties. Such key metadata may be based, at least in part, on the National Institute of Standards and Technology (NIST) recommendations for improving security procedures and auditing. Key metadata can contain important information such as key attributes, ACLs, key lifecycle data, date / time data, and protection scheme information. This information can be managed by a Key Management System (KMS) by binding the metadata to the key value in a key data structure, to ensure that the appropriate key information is always retrieved along with the key.35483.693WO1

[0018] Various security approaches can be applied to the presently disclosed key structure, particularly when the key structure is included in messaging and communications. To ensure the confidentiality of the secret value of the key, the secret value of the key can be protected with a wrapping key, and the entire key structure (or a message including the key structure) can undergo integrity checks to verify a signature of the key structure. Additionally, an authenticated key exchange protocol can be utilized to safeguard communications of the key structure via various secure communication protocols (e.g., TLS 1.2 / 1.3). Secure key access can be guaranteed through mutual Transport Layer Security (mTLS) authentication and Attribute-Based Access Control (ABAC). By implementing these measures in a new or modified KMS, many security gaps can be addressed to enhance an overall security posture and key management.

[0019] Accordingly, the presently disclosed key structure provides a number of security, computational, and operational benefits, including for sharing or using symmetric and asymmetric cryptographic keys in a variety of use cases and scenarios. The presently disclosed key structure helps a KMS manage relevant metadata and properties associated with a cryptographic key, such as an access control list (ACL), applicable time / date period information, lifecycle state of key information, key usage information, key source information, the security level of key, and the like. The metadata and properties of this key structure can be used to assist a client or a key management system to securely validate these properties for a key, and to validate the security of associated cryptography operations. This can help protect the integrity of a key management system and a customer's sensitive data — especially when used in connection with access control systems and other real-world access use cases.

[0020] Moreover, the presently disclosed key structure can be used with many key types in both symmetric and asymmetric cryptography. This enables efficient key distribution and mobility, and providing greater visibility and control of keys from a key management system for effective cryptographic key management. The presently disclosed key structure can also help prevent key misuse and unwanted key extraction by enforcing cryptography operations based on tracked key information. In contrast, if key information and access control lists (ACLs) are not provided and tracked, the risk of using unwanted keys (such as expired or compromised keys) increases. Thus, the presently disclosed key structure is designed to protect keys and their access level for a given user and use cases, improving security measures for a variety of entities.45483.693WO1

[0021] FIG. 1 illustrates an example system 100 which demonstrates an example environment for using cryptographic keys. System 100 can generally include one or more computing devices 102, one or more cloud computing systems 114, and one or more electronic devices 106. The computing devices 102 may be connected via a communication network 110 to a cloud service 104 implemented with the one or more cloud computing systems 114; likewise, the electronic devices 106 may be connected via a communication network 112 to the cloud service 104. The communication network 110, 112 may be any suitable wired or wireless network, such as but not limited to a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), a mobile telephone or data networks (e.g., 3GPP 4G / 5G cellular networks), a Plain Old Telephone (POTS) network, a wireless data network (e.g., the IEEE 802.11 family of standards known as Wi-Fi, the LoRaWAN® family of standards defined by the LoRa Alliance®, or low-earth-orbit satellite communication networks), any network based on the IEEE 802.15.4 family of standards, and a peer-to-peer (P2P) network, or any suitable combination of wired and / or wireless networks.

[0022] Examples of the computing devices 102 may include any suitable computing machine, such as but not limited to a mobile telephone (e.g., smartphone), personal computer (PC), a tablet PC, a personal digital assistant (PDA), etc. The computing devices 102 may operate as a device that uses the secure key structure to perform some credential presentation or verification operation (such as access control, rights verification, etc.). Additional features of the computing devices 102 are discussed with reference to an example machine 600 in FIG. 6.

[0023] Examples of the electronic devices 106 may include a credential device. A credential device may generally include any device that carries (provides or obtains) evidence of authority, status, rights, and / or entitlement to privileges for a holder of the credential device, including with the use of cryptographic keys and an associated secure key structure as discussed herein. A credential device may be provided in any suitable form factor. Example credential devices include, but are not limited to, RFID smartcards or other proximity -based cards, access control cards, electronic keys, key fobs, suitable near field communications (NFC)-enabled devices, tags, personal electronic devices, such as mobile phones, tablet PCs, wearable electronic devices, or PDAs, or any device configurable to emulate a credential. A credential device may generally include memory, storing, for example, one or more user credentials or credential data and any program instructions, and a reader interface (e.g., an antenna and Integrated Circuit (IC) chip), which permits the credential device to process instructions and / or exchange data with another device. Other examples of the electronic55483.693WO1devices include a reader device, such as a wireless reader device that can communicate with credential or key devices via wireless technologies, such as RFID or PAN technologies, such as the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, UWB, etc. Such a reader device may include a PIN pad, touch screen, fingerprint reader, magnetic stripe reader, chip reader, or other nonwireless input means for receiving credential or other information, such as a PIN or other secret code, biometric information such as a fingerprint, or information from a magnetic stripe card or chip card, for example. Additional features of the electronic devices 106 are discussed with reference to an example machine 600 in FIG. 6.

[0024] Cloud service 104 may be any suitable combination of hardware and / or software components providing services consistent with the examples herein, including a key management system 115 or other data processing services that establishes, manages, or controls cryptographic keys and properties of such keys. In some examples, cloud service 104 may utilize one or more cloud computing systems 114 (e.g., networked servers or server clusters) and associated network router(s), switch(es), or bridge(s), for connecting, administrating, and / or managing the service.

[0025] As part of the operations performed in the system 100, a message 116 providing a defined key structure 118 may be generated, communicated, and used among the entities (e.g., electronic devices 106, cloud service 104, cloud computing systems 114, or computing devices 102). This message 116 may include a cryptographic key and associated information using the defined format discussed herein, referred to as a defined key structure 118 (also referred to herein as a “key data structure” or “secure key structure”). The defined key structure 118 is depicted as including key information 118A and a signature 118B of the key information. In this context, the key information 118A includes the actual cryptographic key (or some derivative / encrypted / secure value of the cryptographic key), depicted as secured key value 118C, and key management properties (e.g., metadata) associated with the cryptographic key. The characteristics of the defined key structure 118 are provided in more detail with reference to FIG. 3, discussed below.

[0026] Each of the entities (e.g., electronic devices 106, cloud service 104, cloud computing systems 114, or computing devices 102) may include functionality to receive, transmit, and / or use the defined key structure 118, including based on the communication of the message 116 among the entities. For example, the device that receives the message 116, such as the computing devices 102 or the electronic devices 106 (e.g., each being KMS clients), can perform basic operations to extract a cryptographic key from the key information65483.693WO1118 A, evaluate respective properties from the key information 118A, validate the signature 118B of the key information 118A to determine validity of the key information 118A, and perform some action (e.g., access control action, cryptography operation, etc.) using the cryptographic key after a successful evaluation / validation.

[0027] FIG. 2A illustrates an example use case 200A of the presently described key data structure, in connection with communication of the message 116 and the included defined key structure 118. A key management system 115 is used to generate and maintain information about cryptographic keys by providing the key information 118A in a secured and defined key data structure, to associate the cryptographic key with a variety of attributes and properties discussed with reference to FIG. 3, below. The key management system 115 may manage keys and perform cryptographic operations using one or more hardware security modules (HSMs) 230A or similar security components. The key management system 115 may also use other aspects of object identifier management (e.g., in a management information base) and a key vault (e.g., in a secure storage unit / protected database), not shown.

[0028] The example use case 200A also shows the communication of the message 116 and the included defined key structure 118 from the key management system 115 to a manufacturing or business system 210. This communication may occur via a secure channel 220, such as a TLS 1.3 encrypted communication channel (e.g., implemented as part of a key management system protocol). The manufacturing or business system 210 in turn use the defined key structure 118 based on cryptographic operations performed with an associated HSM 230B, or provide the defined key structure 118 to one or more other key management system clients (e.g., that include HSMs or similar security features). The various clients then can enforce key management policies using key metadata shared as part of the defined key structure.

[0029] FIG. 2B illustrates another example use case 200B of the presently described key data structure, in connection with communication of the message 116 and the included defined key structure 118 with endpoints 260. This scenario shows how the key management system 115 can also provide key information to endpoints 260, via a provisioning system 250, using a secure communication channel established as an endpoint protocol 240. For instance, the endpoint protocol 240 may communicate the message 116 and the defined key structure 118 to the provisioning system 250 using RESTful communications (secured with mTLS authentication), and between the provisioning system 250 and the endpoints 260 using some secure wired, contact, or contactless communication. Each of the endpoints 26075483.693WO1includes (or is communicatively coupled to) a secure element 230C that enables the performance of cryptographic operations. The provisioning system 250 may use the key information in the defined key structure 118 to ensure the validity and applicability of the cryptographic key before provisioning the cryptographic key to the endpoints 260. The endpoints 260 can also enforce key management policies using key metadata shared as part of the defined key structure.

[0030] FIG. 3 illustrates an example arrangement of the defined key structure 118 and the key information 118A and signature 118B stored therein, as a data structure. As discussed above, this defined key structure 118 may be communicated among various devices or systems discussed herein, such as the electronic devices 106, cloud service 104, cloud computing systems 114, or computing devices 102, with the use of messages. However, the defined key structure 118 may also provide information that enables a standalone evaluation of key information at each of these individual devices or systems. Further, the defined key structure 118 may provide information that enables a KMS to define properties or requirements that ensure clients will handle keys securely, preventing any potential security breaches.

[0031] In an example, key metadata is grouped using an ASN. l / JSON encoding format, or another other encoding format of the key structure, to facilitate a defined exchange of keys between the KMS and its clients. Additionally, an encryption scheme provided by encryption can be utilized to provide confidentiality and integrity to the underlying cryptographic key and the metadata. This can be used to safeguard sensitive information and prevent unauthorized access to the cryptographic key while in transit, ensuring the security of keys and data for both the KMS and its clients.

[0032] The key information 118A is depicted in FIG. 3 as including at least the following data fields, and may be composed in varying order:

[0033] Key Attributes 311 to provide the basic information for the maintenance and use of the cryptographic key. In an example, the Key Attributes 311 include one or more of: ID, Label, Type, Length, Algorithm, Scheme, Format, Parameter, Sensitivity, Owner, Version, and the like.

[0034] Secured Key Value 118C to provide the underlying cryptographic key. In an example, the Secured Key Value 118C includes an encrypted version of the cryptographic key in a specified format.

[0035] Access Control List (ACL) 313 to provide access control characteristics as defined by the KMS. In an example, the ACL 313 defines the access control characteristics to include85483.693WO1one or more of: an access control subject, allowed access control operation, and environment mapping to provide access for the cryptographic key.

[0036] Additional Attributes 314 to provide additional information for the maintenance and use of the cryptographic key. In an example, the Additional Attributes 314 include one or more of: Source, Lifecycle state, Lifecycle phase, Intended usage, Parent ID, Sensitivity, Parameters, ACL, Revocation reasons, and the like.

[0037] Date Time Information 315. In an example, the Date Time Information 315 includes properties such as a date and time that the key was: Created, Activated, Expired, Deactivated, Last Used, Revoked, Compromised, or Destroyed (Destruction properties), and the like.

[0038] Protection Scheme Information 316. In an example, the protection scheme includes confidentiality and Integrity Protection based on standards (e.g., NIST standards) and recommendations.

[0039] FIG. 3 also depicts a signature 118B, such as a hash generated from the key information 118A (including the Key Attributes 311, Secured Key Value 118C, ACL 313, Additional Attributes 314, Date Time Information 315, Protection Scheme Information 316, and any other data fields). The message 116 providing the defined key structure 118 may also be accompanied by a message authentication code (MAC). It will be understood that other data fields or attributes (additional, or substituted data fields or attributes) may be integrated into the defined key structure 118, and other signatures or verification methods may be used to determine the validity and authenticity of the key information 118A, the signature 118B, and the message 116.

[0040] In a specific example, the Key Attributes 311 used in the key information 118A may include one or more combinations of the following:95483.693WO1TABLE 1105483.693WO1

[0041] In a specific example, the Additional Attributes 314 may include one or more combinations of the following:115483.693WO1TABLE 2

[0042] The use of the presently described key structure supports many key types, including those provided via symmetric and asymmetric cryptography. This enables efficient key distribution and mobility, and provides greater visibility and control of keys for effective key management. Accordingly, the presently described key structure presents a variety of benefits for secure key sharing and usage in a variety of technology and business use cases. This key structure helps provide inbuilt metadata relating to many aspects such as access control, cryptographic validity period, lifecycle state of key, key usage, key source, the security level of key, etc. Each of these properties can be securely communicated and validated for key and cryptographic operations, particularly for sensitive data and restricted use cases. Moreover, by enforcing crypto operations based on key metadata, the structure helps prevent key misuse and unwanted key extraction. If key metadata and access control lists (ACLS) are not present, the risk of using unwanted key material such as expired or compromised keys increases. Therefore, the new key structure is designed to protect keys and their access level for the given user and use cases, ensuring optimal security measures under the control of a key management system.

[0043] FIG. 4 illustrates a flowchart 400 of an example method of establishing a secure key structure in a key management system. This method may be performed by any of the devices or systems discussed herein, in connection with any of the use cases for generating or providing a secure key data structure (e.g., from a key management system) as discussed herein.

[0044] Operation 410 includes generating or obtaining a key value for a cryptographic key. In one example, the cryptographic key is a symmetric key. In another example, the cryptographic key is an asymmetric key. A variety of specific key types and properties may be provided for the cryptographic key.

[0045] Operation 420 includes preparing a key data structure for encapsulating the key value and properties associated with the cryptographic key. This may include generating or updating the key data structure, such as based on the properties depicted in FIG. 3 and described with reference to TABLES 1 and 2. In some examples, the key data structure may arrange respective information fields of the key information using an ASN. l / JSON encoding format.125483.693WO1

[0046] A first operation 422 of preparing the key data structure can include generating or updating the key structure metadata, reflecting key information associated with the cryptographic key.

[0047] A second operation 424 of preparing the key data structure can include generating or updating a secured key value that encrypts the cryptographic key. In some examples, the cryptographic key is separately encrypted from the key information (metadata), or the cryptographic key and the key information (metadata) are jointly encrypted.

[0048] A third operation 426 of preparing the key data structure can include generating a signature of the key package (e.g., the key structure metadata and the secured key value) and / or a message including the key package and a signature. In an example, the signature of the key information is generated based on an entirety of the key information (e.g., both the key structure metadata and the secured key value).

[0049] Further to the examples of FIG. 3 and TABLES 1 and 2, the key information can specifically include a defined arrangement of attributes associated with the cryptographic key; a secured key value that encrypts the cryptographic key; an access control list associated with access of the cryptographic key; date and time information associated with the cryptographic key; and protection information associated with the cryptographic key.

[0050] Operation 430 includes outputting (e.g., communicating) the key structure to one or more entities. In an example, outputting of the key data structure from the key management system is based on an authenticated key exchange protocol, with the authenticated key exchange protocol including use of mutual Transport Layer Security (mTLS) authentication and attribute-based access control. For example, the key structure may be communicated in connection with the handshake and operations conducted according to the TLS 1.3 protocol, which encrypts data and establishes a secure channel to communicate the key structure.

[0051] Operation 440 includes performing a key management operation at a device (e.g., client, endpoint, etc.) based on the metadata provided in the key structure. For example, this may include verifying the validity of the cryptographic key, based on the key information; performing some additional or substitute security operation, based on the key information; proceeding with some action or validation, based on the key information; and the like.

[0052] FIG. 5 illustrates a block diagram schematic of various components of an example electronic device 500, such as implemented by the electronic devices 106 (e.g., a device that receives the presently described key data structure and uses the included cryptographic key). In general, electronic device 500 can include one or more of a memory 502, a processor 504, one or more antennas 506, communication circuitry 508, a network interface device 510, a135483.693WO1user interface 512, a power source 514 or like power supply, and a secure hardware element 522. The electronic device 500 may take a variety of form factors such as a mounted device, a free-standing device, or a portable device (such as but not limited to a mobile device). Moreover, in some examples, the electronic device 500 may be implemented as a component of a mobile device (e.g., smartphone) of the user, such as a device that performs cryptography operations such as in connection with credential presentation, verification, or use.

[0053] Memory 502 can be used in connection with the execution of application programming or instructions by processor 504, and for the temporary or long-term storage of program executable instructions 516 or instruction sets and / or credential or authorization data 518, such as credential data, credential authorization data, or access control data or instructions which include or are based on a cryptographic key or properties associated with a cryptographic key. For example, memory 502 can contain executable instructions 516 that are used by the processor 504 to run functions or perform determinations based on credential or authorization data 518, including based on the cryptographic key or properties associated with a cryptographic key provided by a defined key data structure as discussed herein. Memory 502 can comprise a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions for use by or in connection with the device 500. The computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or EEPROM), Dynamic RAM (DRAM), any solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. Computer readable media includes, but is not to be confused with, computer readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer readable media.

[0054] Processor 504 can correspond to one or more computer processing devices or resources. For instance, processor 504 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, processor 504 can be provided as a microprocessor, Central Processing Unit (CPU), or a plurality of microprocessors or CPUs that are configured to execute instruction sets 520145483.693WO1stored in an internal memory and / or memory 502. The instructions sets 520 executed by the processor 504 may include instructions for interfacing with the secure hardware element 522. For instance, the secure hardware element 522 may be used for processing and performing cryptographic operations with keys (including the secured key and key value discussed herein).

[0055] Antenna 506 can correspond to one or multiple antennas and can be configured to provide for wireless communications between, for example, device 500 and a credential or key device. Antenna(s) 506 can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, and the like. By way of example, antenna(s) 506 can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by a credential or key device having an RF transceiver.

[0056] Communication circuitry 508 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to the device 500. This may include communications with other control mechanisms or control systems, or other functional entities arranged in a system.

[0057] The network interface device 510 includes hardware to facilitate communications with other devices, such as with cloud service 104, over a communication network, such as network 112, utilizing any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone or data networks (e.g., 3GPP 4G / 5G cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., the IEEE 802.11 family of standards known as Wi-Fi, the LoRaWAN® family of standards defined by the LoRa Alliance®, or low-earth-orbit satellite communication networks), networks based on the IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device 510 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device 510 can include one or more antennas to wirelessly communicate using, for example, at least one of singleinput multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.155483.693WO1

[0058] User interface 512 can include one or more input devices and / or display devices. Examples of suitable user input devices that can be included in user interface 512 include, without limitation, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, a PIN pad, touch screen, fingerprint reader, magnetic stripe reader, chip reader, etc. Examples of suitable user output devices that can be included in user interface 512 include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, a speaker, etc. It should be appreciated that user interface 512 can also include a combined user input and user output device, such as a touch-sensitive display or the like.

[0059] Power source 514 can be any suitable internal power source, such as a battery, capacitive power source or similar type of charge-storage device, etc., and / or can include one or more power conversion circuits suitable to convert external power into suitable power (e.g., conversion of externally-supplied AC power into DC power) for components of the device 500. Power source 514 can also include some implementation of surge protection circuitry to protect the components of device 500 from power surges.

[0060] Device 500 can also include one or more interlinks, interconnects, or buses 524 operable to transmit communications between the various hardware components of the reader. A system bus 524 can be any of several types of commercially available bus structures or bus architectures.

[0061] As suggested above, the device 500 may be embodied by a credential device or a reader device, or related equipment such as a control panel or other specialized electronic device for security or credential operations (e.g., operating as an endpoint 260). Thus, the device 500 may include various programmed functionality for making access control determinations, including with the use of a cryptographic key or properties associated with the cryptographic key and key data structure as discussed herein. Based on the access control determinations, the device 500 or an associated control panel can instruct a reader or another device to operate or command a control mechanism, or may directly operate or command a control mechanism.

[0062] As further example of the credential use cases discussed above, as a user (which may or may not be the same as user / holder) having a credential or key device (illustrated, for example, as a smartcard or mobile device) approaches a reader, the credential device may communicate the user’s credential or credential data to the reader, for example, via a suitable RFID or PAN technology. In some examples, credential device can be a portable device having memory, storing one or more user credentials or credential data, and a reader interface165483.693WO1(i.e., an antenna and Integrated Circuit (IC) chip), which permits the credential to exchange data with a reader device, such as reader, via a credential interface of the reader device, such as an antenna. More generally, and as indicated above, credential device may include some, any, or all of the various components described above with respect to the block diagram schematic of FIG. 5. In some examples, a reader and credential device may be the same device, such as if the user is attempting to access a logical asset via the user’s own mobile device (e.g., mobile device 102B). A reader, control panel, and / or host server may be used to determine that the user’s credential or credential data provided by credential device is valid and / or authorized, followed by the reader, control panel, or host server to operate a control mechanism to allow access to a secure asset by the user having the credential device.

[0063] FIG. 6 illustrates a block diagram schematic of various example components of an example computing machine 600 that can be used as, for example, the one or more computing devices 102, one or more hardware devices of cloud service 104, the one or more cloud computing systems 114, the one or more electronic devices 106, and the like.Examples, as described herein, can generally include, or can operate by, logic or a number of components, modules, or mechanisms in machine 600. Such components may be hardware, software, or firmware communicatively coupled to one or more processors in order to carry out the operations described herein. Generally, circuitry (e.g., processing circuitry) of example machine 600 may include a collection of circuits implemented in tangible entities of the machine 600 that include hardware (e.g., simple circuits, gates, logic, etc.). Circuitry membership can be flexible over time. Circuitries include members that can, alone or in combination, perform specified operations when operating. In some examples, hardware of the circuitry can be immutably designed to carry out a specific operation (e.g., hardwired). In some examples, the hardware of the circuitry can include variably connected physical components (e.g., execution units, transistors, simple circuits, etc.) including a machine readable medium physically modified (e.g., magnetically, electrically, moveable placement of invariant massed particles, etc.) to encode instructions of the specific operation. In connecting the physical components, the underlying electrical properties of a hardware constituent are changed, for example, from an insulator to a conductor or vice versa. The instructions permit embedded hardware (e.g., the execution units or a loading mechanism) to create members of the circuitry in hardware via the variable connections to carry out portions of the specific operation when in operation. Accordingly, in some examples, the machine readable medium elements are part of the circuitry or are communicatively coupled to the other components of the circuitry when the device is operating. In some examples, any of the175483.693WO1physical components can be used in more than one member of more than one circuitry. For example, under operation, execution units can be used in a first circuit of a first circuitry at one point in time and reused by a second circuit in the first circuitry, or by a third circuit in a second circuitry at a different time. Additional and / or more specific examples of components with respect to machine 600 follow.

[0064] In some embodiments, machine 600 can operate as a standalone device or can be connected (e.g., networked) to other machines. In a networked deployment, machine 600 can operate in the capacity of a server machine, a client machine, or both in server-client network environments. In some examples, machine 600 can act as a peer machine in a peer-to-peer (P2P) (or other distributed) network environment. Machine 600 can be or include a PC, a tablet, a compute node, a mobile telephone, a web appliance, a network router, switch or bridge, an RFID smartcard or other proximity -based card, access control card, electronic key, key fob, or any machine capable of executing instructions (sequential or otherwise) that specify actions to be taken by that machine. Further, while only a single machine is illustrated, the term “machine” shall also be taken to include any collection of machines that individually or jointly execute a set (or multiple sets) of instructions to perform any one or more of the methodologies discussed herein, such as cloud computing, software as a service (SaaS), other computer cluster configurations.

[0065] Machine (e.g., computer system) 600 can include a hardware processor 602 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), a hardware processor core, or any combination thereof) and a main memory 604, a static memory (e.g., memory or storage for firmware, microcode, a basic-input-output (BIOS), unified extensible firmware interface (UEFI), etc.) 606, and / or mass storage 608 (e.g., hard drives, tape drives, flash storage, or other block devices) some or all of which can communicate with each other via an interlink (e.g., bus) 636. Machine 600 can further include a display device 610, an input device 612, and / or a user interface (UI) navigation device 614. Examples of suitable display devices include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, etc. Example input devices and UI navigation devices include, without limitation, one or more buttons, a keyboard, a touch-sensitive surface, a stylus, a camera, a microphone, etc. In some examples, one or more of the display device 610, input device 612, and / or UI navigation device 614 can be a combined unit, such as a touch screen display. Machine 600 can additionally include a signal generation device 618 (e.g., a speaker), a network interface device 620, one or more antennas 630, a power source 632, a hardware security module 634, and one or more sensors 616, such as a global185483.693WO1positioning system (GPS) sensor, compass, accelerometer, or other sensor. Machine 600 can include an output controller 628, such as a serial (e.g., universal serial bus (USB)), parallel, or other wired or wireless (e.g., infrared (IR), NFC, etc.) connection to communicate with or control one or more peripheral devices (e.g., a printer, card reader, etc.).

[0066] Processor 602 can correspond to one or more computer processing devices or resources. For instance, processor 602 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like. As a more specific example, processor 602 can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instruction sets 622 stored in an internal memory and / or memory 604, 606 and mass storage 608. The instruction sets 622 may include instructions to perform cryptographic operations, including as coordinated with use of the hardware security module 634 that stores and maintains cryptographic data or performs cryptographic operations directly on the module 634. In some examples, the hardware security module 634 may be provided by an external system and accessible by a secure channel (e.g., a network trust link connection, e.g., accessible via network 110, 112).

[0067] Any of memory 604, 606 and mass storage 608 can be used in connection with the execution of application programming or instructions by processor 602 for performing any of the functionality or methods described herein, and for the temporary or long-term storage of program instructions 624 or instruction sets and / or other data for performing any of the functionality or methods described herein, such as for generating, obtaining, communicating, or using credentials based on the key data structure described herein. Any of memory 604, 606 and mass storage 608 can comprise a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions 624 for use by or in connection with machine 600. The computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or EEPROM), Dynamic RAM (DRAM), a solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device. As noted above, computer readable media includes, but is not to be195483.693WO1confused with, computer readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer readable media.

[0068] Network interface device 620 includes hardware to facilitate communications with other devices over a communication network, such as networks 110, 112, etc., utilizing any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.). Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone or data networks (e.g., 3GPP 4G / 5G cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., the IEEE 802.11 family of standards known as Wi-Fi, the LoRaWAN® family of standards defined by the LoRa Alliance®, or low-earth-orbit satellite communication networks), networks based on the IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others. In some examples, network interface device 620 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like. In some examples, network interface device 620 can include one or more antennas to wirelessly communicate using, for example, at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.

[0069] Antenna 630 can correspond to one or multiple antennas and can be configured to provide for wireless communications between machine 600 and another device. Antenna(s) 630 can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, and the like. By way of example, antenna(s) 630 can be RF antenna(s), and as such, may transmit / receive RF signals through free-space to be received / transferred by another device having an RF transceiver.

[0070] Power source 632 can be any suitable internal power source, such as a battery, capacitive power source or similar type of charge-storage device, etc., and / or can include one or more power conversion circuits suitable to convert external power into suitable power (e.g., conversion of externally-supplied AC power into DC power) for components of the machine 600. Power source 632 can also include some implementation of surge protection circuitry to protect the components of machine 600 from power surges.

[0071] As indicated above, machine 600 can include one or more interlinks or buses 636 operable to transmit communications between the various hardware components of the205483.693WO1machine. A system bus 636 can be any of several types of commercially available bus structures or bus architectures.

[0072] Additional examples of the present subject matter include the following list of examples. Other variations to the following examples will also be apparent based on the techniques discussed herein.

[0073] Example l is a method for establishing a secure key structure in a key management system, comprising: obtaining a cryptographic key; generating a key data structure to include the cryptographic key and properties associated with the cryptographic key, the key data structure including key information and a signature of the key information, wherein the key information comprises: attributes associated with the cryptographic key; a secured key value that encrypts the cryptographic key; an access control list associated with access of the cryptographic key; date and time information associated with the cryptographic key; and protection information associated with the cryptographic key; and outputting the key data structure from the key management system.

[0074] In Example 2, the subject matter of Example 1 optionally includes subject matter where the cryptographic key is a symmetric key.

[0075] In Example 3, the subject matter of any one or more of Examples 1-2 optionally include subject matter where the cryptographic key is an asymmetric key.

[0076] In Example 4, the subject matter of any one or more of Examples 1-3 optionally include subject matter where the attributes associated with the cryptographic key comprise at least one of: a unique identifier used in the key management system for the cryptographic key; a label of the cryptographic key to uniquely identify the cryptographic key in at least one format; a type of the cryptographic key; a length of the cryptographic key; an algorithm of the cryptographic key; an applicable scheme or mode of operation for performing a cryptographic function for using the cryptographic key; a format of the cryptographic key; a parameter of the cryptographic key; a sensitivity of the cryptographic key; an owner of the cryptographic key; or a version of the cryptographic key.

[0077] In Example 5, the subject matter of any one or more of Examples 1-4 optionally include subject matter where the key information further comprises additional attributes associated with the cryptographic key, and wherein the additional attributes comprise at least one of: a source of the cryptographic key; a lifecycle state of the cryptographic key; a lifecycle phase of the cryptographic key; an intended usage of the cryptographic key; a parent identifier of the cryptographic key; a sensitivity of the cryptographic key; parameters of the215483.693WO1cryptographic key; an access control list for access or use of the cryptographic key; or revocation reasons of the cryptographic key.

[0078] In Example 6, the subject matter of any one or more of Examples 1-5 optionally include subject matter where outputting of the key data structure from the key management system is based on an authenticated key exchange protocol, the authenticated key exchange protocol including use of mutual Transport Layer Security (mTLS) authentication and attribute-based access control.

[0079] In Example 7, the subject matter of any one or more of Examples 1-6 optionally include subject matter where the secured key value is generated using a private key maintained by the key management system.

[0080] In Example 8, the subject matter of any one or more of Examples 1-7 optionally include subject matter where the signature of the key information is generated based on an entirety of the key information.

[0081] In Example 9, the subject matter of any one or more of Examples 1-8 optionally include subject matter where the key data structure arranges respective information fields of the key information using an ASN. l / JSON encoding format.

[0082] In Example 10, the subject matter of any one or more of Examples 1-9 optionally include subject matter where outputting the key data structure includes transmitting a message, from the key management system to at least one key management system client, via a secure communication channel.

[0083] Example 11 is a non-transitory computer readable medium comprising executable program code, that when executed by one or more processors of a computing device, causes the one or more processors to perform any of the methods of Examples 1 to 10 for establishing a secure key structure.

[0084] Example 12 is an apparatus, comprising: memory configured to store a secure key structure; and circuitry configured to perform any of the methods of Examples 1 to 10 for establishing the secure key structure.

[0085] Example 13 is a method for using a secure key structure for a cryptographic key managed by a key management system, comprising: receiving a key data structure from a key management system; extracting key information from a key data structure, the key data structure including key information and a signature of the key information, wherein the key information comprises: attributes associated with the cryptographic key; a secured key value that encrypts the cryptographic key; an access control list associated with access of the cryptographic key; date and time information associated with the cryptographic key; and225483.693WO1protection information associated with the cryptographic key; and performing an action based on the cryptographic key, based on one or more properties associated with the cryptographic key provided in the key information.

[0086] In Example 14, the subject matter of Example 13 optionally includes subject matter where the cryptographic key is a symmetric key.

[0087] In Example 15, the subject matter of any one or more of Examples 13-14 optionally include subject matter where the cryptographic key is an asymmetric key.

[0088] In Example 16, the subject matter of any one or more of Examples 13-15 optionally include subject matter where the attributes associated with the cryptographic key comprise at least one of: a unique identifier used in the key management system for the cryptographic key; a label of the cryptographic key to uniquely identify the cryptographic key in at least one format; a type of the cryptographic key; a length of the cryptographic key; an algorithm of the cryptographic key; an applicable scheme or mode of operation for performing a cryptographic function for using the cryptographic key; a format of the cryptographic key; a parameter of the cryptographic key; a sensitivity of the cryptographic key; an owner of the cryptographic key; or a version of the cryptographic key.

[0089] In Example 17, the subject matter of any one or more of Examples 13-16 optionally include subject matter where the key information further comprises additional attributes associated with the cryptographic key, and wherein the additional attributes comprise at least one of: a source of the cryptographic key; a lifecycle state of the cryptographic key; a lifecycle phase of the cryptographic key; an intended usage of the cryptographic key; a parent identifier of the cryptographic key; a sensitivity of the cryptographic key; parameters of the cryptographic key; an access control list for access or use of the cryptographic key; or revocation reasons of the cryptographic key.

[0090] In Example 18, the subject matter of any one or more of Examples 13-17 optionally include subject matter where the receiving of the key data structure from the key management system is based on an authenticated key exchange protocol, the authenticated key exchange protocol including use of mutual Transport Layer Security (mTLS) authentication and attribute-based access control.

[0091] In Example 19, the subject matter of any one or more of Examples 13-18 optionally include subject matter where the secured key value is generated using a private key maintained by the key management system.235483.693WO1

[0092] In Example 20, the subject matter of any one or more of Examples 13-19 optionally include subject matter where the signature of the key information is generated based on an entirety of the key information.

[0093] In Example 21, the subject matter of any one or more of Examples 13-20 optionally include subject matter where the key data structure arranges respective information fields of the key information using an ASN. l / JSON encoding format.

[0094] In Example 22, the subject matter of any one or more of Examples 13-21 optionally include subject matter where the receiving of the key data structure is provided in a message, received from the key management system at a key management system client, via a secure communication channel.

[0095] Example 23 is a non-transitory computer readable medium comprising executable program code, that when executed by one or more processors of a computing device, causes the one or more processors to perform any of the methods of Examples 13 to 22 for using a secure key structure for a cryptographic key.

[0096] Example 24 is an apparatus, comprising: memory configured to store a secure key structure; and circuitry configured to perform any of the methods of Examples 13 to 22 for using the secure key structure for a cryptographic key.

[0097] The above detailed description includes references to the accompanying drawings, which form a part of the detailed description. The drawings show, by way of illustration, specific embodiments that can be practiced. These embodiments may also be referred to herein as “examples.” Such embodiments or examples can include elements in addition to those shown or described. However, the present inventors also contemplate examples in which only those elements shown or described are provided. Moreover, the present inventors also contemplate examples using any combination or permutation of those elements shown or described (or one or more aspects thereof), either with respect to a particular example (or one or more aspects thereof), or with respect to other examples (or one or more aspects thereof) shown or described herein. That is, the above-described embodiments or examples or one or more aspects, features, or elements thereof can be used in combination with each other.

[0098] As will be appreciated by one of skill in the art, the various embodiments of the present disclosure may be embodied as a method (including, for example, a computer- implemented process, a business process, and / or any other process), apparatus (including, for example, a system, machine, device, computer program product, and / or the like), or a combination of the foregoing. Accordingly, embodiments of the present disclosure or portions thereof may take the form of an entirely hardware embodiment, an entirely software245483.693WO1embodiment (including firmware, middleware, microcode, hardware description languages, etc.), or an embodiment combining software and hardware aspects. Furthermore, embodiments of the present disclosure may take the form of a computer program product on a computer-readable medium or computer-readable storage medium, having computerexecutable program code embodied in the medium, that define processes or methods described herein. A processor or processors may perform the necessary tasks defined by the computer-executable program code. In the context of this disclosure, a computer readable medium may be any medium that can contain, store, communicate, or transport the program for use by or in connection with the systems disclosed herein. As indicated above, the computer readable medium may be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device. More specific examples of suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a compact disc read-only memory (CD-ROM), or other optical, magnetic, or solid state storage device. As noted above, computer-readable media includes, but is not to be confused with, computer-readable storage medium, which is intended to cover all physical, non- transitory, or similar embodiments of computer-readable media.

[0099] In the foregoing description various embodiments of the present disclosure have been presented for the purpose of illustration and description. They are not intended to be exhaustive or to limit the invention to the precise form disclosed. Obvious modifications or variations are possible in light of the above teachings. The various embodiments were chosen and described to provide the best illustration of the principles of the disclosure and their practical application and to enable one of ordinary skill in the art to utilize the various embodiments with various modifications as are suited to the particular use contemplated. All such modifications and variations are within the scope of the present disclosure as determined by the appended claims when interpreted in accordance with the breadth they are fairly, legally, and equitably entitled.255483.693WO1

Claims

CLAIMSWhat is claimed is:

1. A method for establishing a secure key structure in a key management system, comprising: obtaining a cryptographic key; generating a key data structure to include the cryptographic key and properties associated with the cryptographic key, the key data structure including key information and a signature of the key information, wherein the key information comprises: attributes associated with the cryptographic key; a secured key value that encrypts the cryptographic key; an access control list associated with access of the cryptographic key; date and time information associated with the cryptographic key; and protection information associated with the cryptographic key; and outputting the key data structure from the key management system.

2. The method of claim 1, wherein the cryptographic key is a symmetric key.

3. The method of claim 1, wherein the cryptographic key is an asymmetric key.

4. The method of claim 1, wherein the attributes associated with the cryptographic key comprise at least one of: a unique identifier used in the key management system for the cryptographic key; a label of the cryptographic key to uniquely identify the cryptographic key in at least one format; a type of the cryptographic key; a length of the cryptographic key; an algorithm of the cryptographic key; an applicable scheme or mode of operation for performing a cryptographic function for using the cryptographic key; a format of the cryptographic key; a parameter of the cryptographic key; a sensitivity of the cryptographic key; an owner of the cryptographic key; or265483.693WO1a version of the cryptographic key.

5. The method of claim 1, wherein the key information further comprises additional attributes associated with the cryptographic key, and wherein the additional attributes comprise at least one of: a source of the cryptographic key; a lifecycle state of the cryptographic key; a lifecycle phase of the cryptographic key; an intended usage of the cryptographic key; a parent identifier of the cryptographic key; a sensitivity of the cryptographic key; parameters of the cryptographic key; an access control list for access or use of the cryptographic key; or revocation reasons of the cryptographic key.

6. The method of claim 1, wherein outputting of the key data structure from the key management system is based on an authenticated key exchange protocol, the authenticated key exchange protocol including use of mutual Transport Layer Security (mTLS) authentication and attribute-based access control.

7. The method of claim 1, wherein the secured key value is generated using a private key maintained by the key management system.

8. The method of claim 1, wherein the signature of the key information is generated based on an entirety of the key information.

9. The method of claim 1, wherein the key data structure arranges respective information fields of the key information using an ASN. l / JSON encoding format.

10. The method of claim 1, wherein outputting the key data structure includes transmitting a message, from the key management system to at least one key management system client, via a secure communication channel.275483.693WO111. A non-transitory computer readable medium comprising executable program code, that when executed by one or more processors of a computing device, causes the one or more processors to perform any of the methods of claims 1 to 10 for establishing a secure key structure.

12. An apparatus, comprising: memory configured to store a secure key structure; and circuitry configured to perform any of the methods of claims 1 to 10 for establishing the secure key structure.

13. A method for using a secure key structure for a cryptographic key managed by a key management system, comprising: receiving a key data structure from a key management system; extracting key information from a key data structure, the key data structure including key information and a signature of the key information, wherein the key information comprises: attributes associated with the cryptographic key; a secured key value that encrypts the cryptographic key; an access control list associated with access of the cryptographic key; date and time information associated with the cryptographic key; and protection information associated with the cryptographic key; and performing an action based on the cryptographic key, based on one or more properties associated with the cryptographic key provided in the key information.

14. The method of claim 13, wherein the cryptographic key is a symmetric key.

15. The method of claim 13, wherein the cryptographic key is an asymmetric key.

16. The method of claim 13, wherein the attributes associated with the cryptographic key comprise at least one of: a unique identifier used in the key management system for the cryptographic key; a label of the cryptographic key to uniquely identify the cryptographic key in at least one format; a type of the cryptographic key;285483.693WO1a length of the cryptographic key; an algorithm of the cryptographic key; an applicable scheme or mode of operation for performing a cryptographic function for using the cryptographic key; a format of the cryptographic key; a parameter of the cryptographic key; a sensitivity of the cryptographic key; an owner of the cryptographic key; or a version of the cryptographic key.

17. The method of claim 13, wherein the key information further comprises additional attributes associated with the cryptographic key, and wherein the additional attributes comprise at least one of: a source of the cryptographic key; a lifecycle state of the cryptographic key; a lifecycle phase of the cryptographic key; an intended usage of the cryptographic key; a parent identifier of the cryptographic key; a sensitivity of the cryptographic key; parameters of the cryptographic key; an access control list for access or use of the cryptographic key; or revocation reasons of the cryptographic key.

18. The method of claim 13, wherein the receiving of the key data structure from the key management system is based on an authenticated key exchange protocol, the authenticated key exchange protocol including use of mutual Transport Layer Security (mTLS) authentication and attribute-based access control.

19. The method of claim 13, wherein the secured key value is generated using a private key maintained by the key management system.

20. The method of claim 13, wherein the signature of the key information is generated based on an entirety of the key information.295483.693WO121. The method of claim 13, wherein the key data structure arranges respective information fields of the key information using an ASN. l / JSON encoding format.

22. The method of claim 13, wherein the receiving of the key data structure is provided in a message, received from the key management system at a key management system client, via a secure communication channel.

23. A non-transitory computer readable medium comprising executable program code, that when executed by one or more processors of a computing device, causes the one or more processors to perform any of the methods of claims 13 to 22 for using a secure key structure for a cryptographic key.

24. An apparatus, comprising: memory configured to store a secure key structure; and circuitry configured to perform any of the methods of claims 13 to 22 for using the secure key structure for a cryptographic key.305483.693WO1

Citation Information

Patent Citations

  • Managing encrypted storage based on key-metadata

    US11677553B2

  • Distributed key management system with a key lookup service

    US11895227B1