Inventors:
Cyrus J. Durgin - Seattle WA, US
Pratik S. Dave - New York City NY, US
Eric J. Martin - Bainbridge Island WA, US
Assignee:
Amazon Technologies, Inc. - Reno NV
International Classification:
H04L 9/18, H04L 9/12
US Classification:
726 9, 726 20, 713185, 713172
Abstract:
Secure information is managed for each host or machine in an electronic environment using a series of key identifiers that each represent one or more secure keys, passwords, or other secure information. Applications and services needing access to the secure information can specify the key identifier, for example, and the secure information currently associated with that identifier can be determined without any change to the code or manual input or exposure of the secure information on the respective device. Functionality such as encryption key management and rotation are inaccessible and transparent to the user. In a networked or distributed environment, the key identifiers can be associated with host classes such that at startup any host in a class can obtain the necessary secure information. Updates and key rotation can be performed in a similar fashion by pushing updates to host classes transparent to a user, application, or service.