Methods and systems for updatable encryption
Described herein are methods and systems for updating encryption keys. The updating may comprise application of an update token to a key to generate a second key. The updating may comprise application of a second update token to the key to generate a third key. The key may be the same key in both update operations.
1 . A computer-implemented method for updating an encryption key, wherein the encryption key is configured to be used to encrypt a plaintext into a ciphertext or to decrypt a ciphertext into a plaintext, the method comprising:
(a) processing a first update token together with said encryption key to update said encryption key, thereby generating a first updated encryption key; and
(b) subsequent to (a), processing a second update token together with said encryption key to update said encryption key, thereby generating a second updated encryption key, wherein said second update token is different than said first update token, and wherein said second updated encryption key is different than said first updated encryption key.
2 . The method of claim 1 , wherein said second updated encryption key is configured to be used to encrypt or decrypt a ciphertext.
3 . The method of claim 1 , wherein said encryption key is a public key, a private key, or both.
4 . The method of claim 1 , wherein said encryption key is an encryption key for a post-quantum encryption scheme.
5 . The method of claim 1 , wherein said updated encryption key or said second updated encryption key is configured to be used by an encryption algorithm to encrypt a ciphertext.
6 . The method of claim 1 , wherein said using said second update token comprises applying one or more operations from said update token to said encryption key.
7 . The method of claim 1 , wherein said encryption key is a decryption key.
8 . A system for updating an encryption key, wherein the encryption key is configured to be used to encrypt a plaintext into a ciphertext or to decrypt a ciphertext into a plaintext, the system comprising:
one or more computer processors operatively coupled to computer memory, wherein said one or more computer processors are individually or collectively configured to
(a) direct processing of a first update token together with said encryption key to update said encryption key, thereby generating a first updated encryption key; and
(b) subsequent to (a), direct processing of a second update token together with said encryption key to update said encryption key, thereby generating a second updated encryption key, wherein said second update token is different than said first update token, and wherein said second updated encryption key is different than said first updated encryption key.
9 . A non-transitory computer-readable medium comprising machine executable code that, upon execution by a processor, causes the processor to perform a method for updating an encryption key, wherein the encryption key is configured to be used to encrypt a plaintext into a ciphertext or to decrypt a ciphertext into a plaintext, the method comprising:
(a) processing a first update token together with said encryption key to update said encryption key, thereby generating a first updated encryption key; and
(b) subsequent to (a), processing a second update token together with said encryption key to update said encryption key, thereby generating a second updated encryption key, wherein said second update token is different than said first update token, and wherein said second updated encryption key is different than said first updated encryption key.