IP Library Granted Patent US 8,938,622
Granted Patent B2
US 8,938,622 · App. 13/624,069 · Granted Jan 20, 2015

Encryption in the cloud with customer controlled keys

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,938,622
App. No.
13/624,069
Granted
Jan 20, 2015
Kind
B2
Abstract

A system and method for encryption in a cloud computing platform with customer controlled keys is disclosed. A cloud-based encryption key is uploaded from a customer computing platform to a key store of the cloud computing platform, based on a customer-based encryption key. The cloud-based encryption key and customer-based encryption key is able to encrypt or decrypt customer data used by an application server running on the cloud computing platform. Next, the cloud-based encryption key is unlocked from the key store, and then stored in a secure store of a main memory associated with the customer computing platform. Then, according to encryption or decryption mechanism, the unlocked cloud-based encryption key is accessed to encrypt or decrypt customer data stored on a database of the main memory and used by the application server.

Claims (32)

1. A method for encryption in a cloud computing platform with customer controlled keys, the method comprising:

uploading, from a customer computing platform to a key store of the cloud computing platform, a cloud-based encryption key based on a customer-based encryption key, the cloud-based encryption key and customer-based encryption key being able to encrypt or decrypt customer data used by an application server running on the cloud computing platform;

retrieving the customer-based encryption key stored on the customer computing platform;

unlocking, by one or more processors executing a key unlocking mechanism using the customer-based encryption key, the cloud-based encryption key from the key store;

storing, by one or more processors, the unlocked cloud-based encryption key in a secure store of a main memory associated with the customer computing platform; and

accessing, by one or more processors executing an encryption or decryption mechanism, the unlocked cloud-based encryption key to encrypt or decrypt customer data stored on a database of the main memory and used by the application server.

2. The method in accordance with claim 1 , wherein the unlocking the cloud-based encryption key further includes:

unlocking the cloud-based encryption key from the key store using the customer-based encryption key.

3. The method in accordance with claim 1 , wherein the accessing the unlocked cloud-based encryption key to encrypt or decrypt customer data further includes:

determining a relationship of the customer data with the cloud-based encryption key.

4. The method in accordance with claim 3 , wherein the accessing the unlocked cloud-based encryption key to encrypt or decrypt customer data further includes:

accessing the unlocked cloud-based encryption key according to the relationship.

5. A computer program product comprising a non-transitory machine-readable medium storing instructions that, when executed by at least one programmable processor, cause the at least one programmable processor to perform operations comprising:

uploading, from a customer computing platform to a key store of the cloud computing platform, a cloud-based encryption key based on a customer-based encryption key, the cloud-based encryption key and customer-based encryption key being able to encrypt or decrypt customer data used by an application server running on the cloud computing platform;

retrieving the customer-based encryption key stored on the customer computer platform;

unlocking, according to a key unlocking mechanism using the customer-based encryption key, the cloud-based encryption key from the key store;

storing the unlocked cloud-based encryption key in a secure store of a main memory associated with the customer computing platform; and

accessing, according to an encryption or decryption mechanism, the unlocked cloud-based encryption key to encrypt or decrypt customer data stored on a database of the main memory and used by the application server.

6. A system comprising:

at least one programmable processor; and

a machine-readable medium storing instructions that, when executed by the at least one processor, cause the at least one programmable processor to perform operations comprising:

uploading, from a customer computing platform to a key store of the cloud computing platform, a cloud-based encryption key based on a customer-based encryption key, the cloud-based encryption key and customer-based encryption key being able to encrypt or decrypt customer data used by an application server running on the cloud computing platform;

retrieving the customer-based encryption key stored on the customer computing platform;

unlocking, according to a key unlocking mechanism using the customer-based encryption key, the cloud-based encryption key from the key store;

storing the unlocked cloud-based encryption key in a secure store of a main memory associated with the customer computing platform; and

accessing, according to an encryption or decryption mechanism, the unlocked cloud-based encryption key to encrypt or decrypt customer data stored on a database of the main memory and used by the application server.

7. The system in accordance with claim 6 , wherein the unlocking the cloud-based encryption key further includes:

unlocking the cloud-based encryption key from the key store using the customer-based encryption key.

8. The system in accordance with claim 6 , wherein the accessing the unlocked cloud-based encryption key to encrypt or decrypt customer data further includes:

determining a relationship of the customer data with the cloud-based encryption key.

9. The system in accordance with claim 8 , wherein the accessing the unlocked cloud-based encryption key to encrypt or decrypt customer data further includes:

accessing the unlocked cloud-based encryption key according to the relationship.

Assignments (2)
CHANGE OF NAME Recorded Aug 26, 2014
From: SAP AG
To: SAP SE
Reel/Frame 033625/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2013
From: BUEHL, MATTHIAS
To: SAP AG, A GERMAN CORPORATION
Reel/Frame 029994/0893 →