IP Library Patent Application 13527860
Patent Application
App. No. 13/527,860

KEY ROTATION AND SELECTIVE RE-ENCRYPTION FOR DATA SECURITY

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/527,860
Abstract

Systems and methods for maintaining data security through encryption key retirement and selective re-encryption are presented. A method of selectively re-encrypting a subset of encrypted values includes storing each encrypted value together with the key profile number for the encryption key that was used to generate that encrypted value. When a key is compromised, its associated key profile number allows the efficient identification of all the encrypted values that were created using the now-compromised key. Once identified, the encrypted values may be decrypted using the compromised key and re-encrypted using a new key, without changing other related data such as the token associated with the encrypted value.

Claims (28)

1 . A method of selectively re-encrypting a subset of encrypted data values, for use in a data processing operation for protecting sensitive data, said method comprising the computer-implemented steps of:

establishing a data store for storing a plurality of records, wherein each record comprises an encrypted value associated with original sensitive data, and a key profile number associated with an encryption key that was used to generate said encrypted value;

identifying a compromised key and a compromised key profile number associated therewith;

generating a new key and a new key profile number associated therewith;

identifying in said data store a subset of records, wherein said subset is characterized by a key profile number that matches said compromised key profile number, and for each record in said subset:

(a) de-encrypting said encrypted value using said compromised key to reveal said original sensitive data;

(b) re-encrypting said original sensitive data using said new key to generate a new encrypted data value;

(c) replacing said encrypted value with said new encrypted data value; and

(d) replacing said compromised key profile number with said new key profile number.

2 . The method of claim 1 , wherein each said record further comprises a token value associated with said original sensitive data, and wherein said method is executed without changing said token value.

3 . The method of claim 1 , wherein said step of generating said new key includes generating an activation date associated therewith, and wherein said step of identifying occurs after said activation date.

4 . A method for activating a new encryption key on a future date, for use in a data processing operation for protecting sensitive data, said method comprising the computer-implemented steps of:

establishing a data processing operation comprising a key manager for generating encryption keys, a token manager for encrypting sensitive data, and a data vault for storing encrypted data;

establishing a key management data store, in communication with said key manager, for storing a plurality of records, wherein each record comprises an encryption key, a key profile number, and an activation date;

generating a new record, comprising a new encryption key, a new key profile number, a new activation date; and

distributing said new record to said token manager for implementation of said new encryption key and said new key profile number upon reaching said activation date.

5 . A method of encryption key retirement for use in a data processing operation for protecting sensitive data, said method comprising the computer-implemented steps of:

establishing a data processing operation comprising a key manager for generating encryption keys, a token manager for encrypting sensitive data, and a data vault for storing encrypted data;

establishing a data store, in communication with said data vault, for storing a plurality of records, wherein each record comprises an encrypted value associated with original sensitive data, and a key profile number associated with an encryption key that was used to generate said encrypted value;

identifying a compromised key and a compromised key profile number associated therewith;

generating a new key and a new key profile number associated therewith;

identifying in said data store a subset of records, wherein said subset is characterized by a key profile number that matches said compromised key profile number, and for each record in said subset:

(a) de-encrypting said encrypted value using said compromised key to reveal said original sensitive data;

(b) re-encrypting said original sensitive data using said new key to generate a new encrypted data value;

(c) replacing said encrypted value with said new encrypted data value; and

(d) replacing said compromised key profile number with said new key profile number.

6 . The method of claim 5 , wherein each said record further comprises a token value associated with said original sensitive data, and wherein said method is executed without changing said token value.

7 . The method of claim 5 , wherein said step of generating said new key includes generating an activation date associated therewith, and wherein said step of identifying occurs after said activation date.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE LISTED PATENTS,NAMELY 5 NOS. LISTED AS PATENT NOS.(9590916,9344182,9650219,9588270,9294701),SHOULD BE LISTED AS APPLICATION NOS. PREVIOUSLY RECORDED ON REEL 047950 FRAME 0910. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Dec 10, 2019
From: LIAISON TECHNOLOGIES, INC.
To: SILICON VALLEY BANK
Reel/Frame 051255/0831 →
SECURITY INTEREST Recorded Jan 10, 2019
From: LIAISON TECHNOLOGIES, INC.
To: SILICON VALLEY BANK
Reel/Frame 047950/0892 →
SECURITY INTEREST Recorded Jan 10, 2019
From: LIAISON TECHNOLOGIES, INC.
To: SILICON VALLEY BANK
Reel/Frame 047950/0910 →
RELEASE OF SECURITY INTEREST Recorded Jan 10, 2019
From: SILICON VALLEY BANK
To: LIAISON TECHNOLOGIES, INC.
Reel/Frame 048043/0532 →
SECURITY INTEREST Recorded Mar 31, 2017
From: LIAISON TECHNOLOGIES, INC.
To: SILICON VALLEY BANK
Reel/Frame 041808/0027 →