IP Library Granted Patent US 9,678,893
Granted Patent B2
US 9,678,893 · App. 13/464,338 · Granted Jun 13, 2017

Secure caching technique for shared distributed caches

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,678,893
App. No.
13/464,338
Granted
Jun 13, 2017
Kind
B2
Abstract

The present invention relates to a secure caching technique for shared distributed caches. A method in accordance with an embodiment of the present invention includes: encrypting a key K to provide a secure key, the key K corresponding to a value to be stored in a cache; and storing the value in the cache using the secure key.

Claims (44)

1. A method for secure caching in a shared distributed cache shared by a plurality of parties, comprising:

initiating a storage of a value in the shared distributed cache by a first party, the value being information to be stored and obtained by the plurality of parties;

associating a key with the value in a value/key pair;

generating a mask value and encrypting the mask value using a secret key to provide an encrypted mask value and storing the encrypted mask value in a shared distributed cache using a cache key, wherein the encrypted mask value can be retrieved from the cache using the cache key;

encrypting the key in the value/key pair by applying a masking algorithm using the generated mask value resulting in the creation of a secure key;

storing the value in the shared distributed cache using the secure key;

requesting the value from the shared distributed cache by a second party using the key;

computing, by the second party, the secure key by encrypting the key using the same mask value and masking algorithm; and

retrieving, by the second party, the value from the shared distributed cache using the secure key.

2. The method of claim 1 , wherein the mask value is obtained by:

retrieving the encrypted mask value from the shared distributed cache; and

decrypting the encrypted mask value using a secret key.

3. The method of claim 2 , further comprising:

securely distributing the secret key to the plurality of parties.

4. The method of claim 1 , further comprising:

periodically regenerating the mask value.

5. A system for secure caching in a shared distributed cache shared by a plurality of parties, comprising:

a first system configured for

initiating a storage of a value in the shared distributed cache by a first party, the value being information to be stored and obtained by the plurality of parties;

associating a key with the value in a value/key pair;

generating a mask value and encrypting the mask value using a secret key to provide an encrypted mask value and storing the encrypted mask value in a shared distributed cache using a cache key, wherein the encrypted mask value can be retrieved from the cache using the cache key;

encrypting the key in the value/key pair by applying a masking algorithm using the mask value resulting in the creation of a secure key; and

storing the value in the shared distributed cache using the secure key; and

a second system configured for

requesting the value from the shared distributed cache by a second party using the key;

computing the secure key by encrypting the key using the same mask value and masking algorithm; and

retrieving the value from the shared distributed cache using the secure key.

6. The system of claim 5 , wherein the second system is further configured for

retrieving the encrypted mask value from the shared distributed cache; and

decrypting the encrypted mask value using a secret key.

7. The system of claim 6 , wherein the secret key is securely distributed to the plurality of parties.

8. The system of claim 5 , wherein the mask value is periodically regenerated.

9. A computer program product for secure caching in a shared distributed cache shared by a plurality of parties, the computer program product comprising:

a computer usable storage medium having computer usable program code embodied therewith, the computer usable program code comprising:

computer usable program code for initiating a storage of a value in the shared distributed cache by a first party, the value being information to be stored and obtained by the plurality of parties;

computer usable program code for associating a key with the value in a value/key pair;

computer usable program code for generating a mask value and encrypting the mask value using a secret key to provide an encrypted mask value and storing the encrypted mask value in a shared distributed cache using a cache key, wherein the encrypted mask value can be retrieved from the cache using the cache key

computer usable program code for encrypting the key in the value/key pair by applying a masking algorithm using the mask value resulting in the creation of a secure key;

computer usable program code for storing the value in the shared distributed cache using the secure key;

computer usable program code for requesting the value from the shared distributed cache by a second party using the key;

computer usable program code for computing, by the second party, the secure key by encrypting the key using the same mask value and masking algorithm; and

computer usable program code for retrieving, by the second party, the value from the shared distributed cache using the secure key.

10. The computer program product of claim 9 , further comprising:

computer usable program code for periodically regenerating the mask value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 28, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: MAPLEBEAR INC.
Reel/Frame 055155/0943 →