IP Library Granted Patent US 9,756,022
Granted Patent B2
US 9,756,022 · App. 14/472,540 · Granted Sep 5, 2017

Enhanced remote key management for an enterprise in a cloud-based environment

Inventors: Kia Amiri (San Francisco, CA); Jeff Queisser (San Francisco, CA); Chris Byron (San Francisco, CA); Rand Wacker (San Francisco Bay, CA); Kevin Babcock (San Francisco, CA)
Assignee: Box, Inc.
H04L63/0428H04L9/0822H04L9/0897H04L63/06G06F21/60H04L2209/24H04L2209/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,756,022
App. No.
14/472,540
Granted
Sep 5, 2017
Kind
B2
Abstract

Systems and methods are disclosed for facilitating remote key management services in a collaborative cloud-based environment. In one embodiment, the remote key management architecture and techniques described herein provide for local key encryption and automatic generation of a reason code associated with content access. The reason code is logged by a hardware security module which is monitored by a remote client device (e.g., an enterprise client) to control a second (remote) layer of key encryption. The remote client device provides client-side control and configurability of the second layer of key encryption.

Claims (39)

1. A method for facilitating remote key management services in a collaborative cloud-based environment, the method comprising:

processing a data item indicated by a content request to determine that the data item is associated with remote key management functionality;

identifying audit log information associated with the content request, wherein the audit log information comprises a reason code enumerating a reason associated with the content request, wherein the reason comprises at least one of: accessing a data item request, fulfilling a maintenance request, performing a text extraction request, or fulfilling backend services;

initiating a secure key request by a HSM interface engine to a hardware security module (HSM), wherein the secure key request comprises the audit log information; and

determining whether to accept or reject the content request by processing the reason code from the secure key request based at least in part on one or more pre-configured rules by the HSM, wherein the HSM is located on a second client device that is remote from the HSM interface engine located on a first client device, the secure key request sent across a network from the first client device to the second client device for determining whether to accept or reject the content request based at least in part on the reason code.

2. The method of claim 1 , wherein the secure key request directs the HSM to store the audit log information.

3. The method of claim 2 , wherein the secure key request further directs the HSM to sign the audit log information with a secure key.

4. The method of claim 1 , wherein the audit log information is included in a free form block of the secure key request to the HSM.

5. The method of claim 1 , wherein the HSM is hosted by the collaborative cloud-based environment but the audit log information is inaccessible via the collaborative cloud-based environment.

6. The method of claim 1 , wherein the HSM is hosted by a second collaborative cloud-based environment distinct from the collaborative cloud-based environment.

7. The method of claim 1 , wherein the HSM is hosted by a managed services provider.

8. The method of claim 1 , wherein the HSM provides access to the collaborative cloud-based environment and the collaborative cloud-based environment is distinct from a client enterprise that owns the HSM.

9. The method of claim 1 , wherein the content request comprises an upload request and wherein the secure key request includes a request to encrypt an encrypted encryption key.

10. The method of claim 1 , wherein the content request comprises an access request and wherein the secure key request includes a request to decrypt a twice encrypted encryption key.

11. A system for facilitating remote key management services in a collaborative cloud-based environment, the system comprising: one or more processors;

a memory unit having instructions stored thereon which, when executed by the one or more processors, causes the system to:

process a data item indicated by a content request to determine that the data item is associated with remote key management functionality;

identify audit log information associated with the content request, wherein the audit log information comprises a reason code enumerating a reason associated with the content request, wherein the reason comprises at least one of: accessing a data item request, fulfilling a maintenance request, performing a text extraction request, or fulfilling backend services;

initiate a secure key request by a HSM interface engine to a hardware security module (HSM), wherein the secure key request comprises the audit log information; and

determine whether to accept or reject the content request by processing the reason code from the secure key request based at least in part on one or more pre-configured rules by the HSM, wherein the HSM is located on a second client device that is remote from the HSM interface engine located on a first client device, the secure key request sent across a network from the first client device to the second client device for determining whether to accept or reject the content request based at least in part on the reason code.

12. The system of claim 11 , wherein the secure key request directs the HSM to store the audit log information.

13. The system of claim 12 , wherein the secure key request further directs the HSM to sign the audit log information with a secure key.

14. The system of claim 11 , wherein the instructions, when executed by the one or more processors, further causes the system to:

format the audit log information for a free form block of the secure key request to the HSM, wherein the audit log information is included in the free form block of the secure key request to the HSM.

15. The system of claim 11 , wherein the HSM is hosted by the collaborative cloud-based environment but the audit log information is inaccessible via the collaborative cloud-based environment.

16. The system of claim 11 , wherein the HSM is hosted by a second collaborative cloud-based environment distinct from the collaborative cloud-based environment.

17. The system of claim 11 , wherein the HSM is hosted by a managed services provider.

18. The system of claim 11 , wherein the HSM provides access to the collaborative cloud-based environment and the collaborative cloud-based environment is distinct from a client enterprise that owns the HSM.

19. The system of claim 11 , wherein the content request comprises an upload request and wherein the secure key request includes a request to encrypt an encrypted encryption key.

20. The system of claim 11 , wherein the content request comprises an access request and wherein the secure key request includes a request to decrypt a twice encrypted encryption key.

21. A system for facilitating remote key management services in a collaborative cloud-based environment, the system comprising:

a processor;

a key service proxy device configured to initiate a secure key request responsive to a determination that a data item indicated by a content request is associated with remote key management functionality, wherein the secure key request comprises a reason code enumerating a reason associated with the content request, wherein the reason comprises at least one of: accessing a data item request, fulfilling a maintenance request, performing a text extraction request, or fulfilling backend services;

a reason engine configured to determine a reason code associated with the content request, wherein determining the reason code comprises directing the processor to identify a reason associated with the content request and responsively generate the reason code associated with the content request;

a hardware security interface engine configured to format the secure key request according to a particular hardware security module (HSM); and

the HSM configured to determine whether to accept or reject the content request by processing the reason code from the secure key request based at least in part on one or more pre-configured rules by the HSM, wherein the HSM is located on a second client device that is remote from the key service proxy device located on a first client device, the secure key request sent across a network from the first client device to the second client device for determining whether to accept or reject the content request based at least in part on the reason code.

22. The system of claim 21 , wherein the reason code is included in a free form block of the secure key request.

23. The system of claim 21 , wherein the secure key request directs the HSM to log the reason code.

24. The system of claim 23 , wherein an enterprise client is provided an interface for monitoring the log.

Assignments (5)
SECURITY INTEREST Recorded Jul 26, 2023
From: BOX, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 064389/0686 →
RELEASE OF SECURITY INTEREST Recorded Dec 8, 2015
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: BOX, INC.
Reel/Frame 037237/0503 →
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER FROM 14308038 AND REPLACE WITH 14304038 PREVIOUSLY RECORDED AT REEL: 034590 FRAME: 0250. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 30, 2014
From: BOX, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 034769/0809 →
PATENT SECURITY AGREEMENT Recorded Dec 9, 2014
From: BOX, INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 034590/0250 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2014
From: AMIRI, KIA; QUEISSER, JEFF; BYRON, CHRIS; BABCOCK, KEVIN; WACKER, RAND
To: BOX, INC.
Reel/Frame 033637/0476 →
Continuity (1)
Related Publication 20160065363A1 · Mar 3, 2016