Enhanced key availability for data services
US11044079B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Apr 19, 2019 |
| Grant date | Jun 22, 2021 |
| Priority date | — |
| Expiry date | Jul 31, 2039 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F2221/2131
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
Systems, methods, and software technology for managing keys used to encrypt data at-rest and decrypt the data when serving requests for the data. In an implementation, a data service receives a request for data that has been encrypted at rest using a data key, wherein the data key has been encrypted using a policy key, and wherein the policy key has been encrypted using a root key. When the root key is unavailable, the data service requests a key service to decrypt the policy key using an alternative root key. When the data service receives the policy key in an unencrypted state from the key service, it decrypts the data key using the policy key and decrypts the data using the data key.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.