IP Library › Granted Patent US 9,660,801
Granted Patent B2
US 9,660,801 · App. 14/746,853 · Granted May 23, 2017

Methods and devices for key management in an as-a-service context

Inventor: Gilad Parann-Nissany (Ramat Hasharon, IL)
Assignee: Porticor Ltd.
H04L9/008H04L9/0825H04L63/06H04L67/34H04L2209/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,660,801
App. No.
14/746,853
Granted
May 23, 2017
Kind
B2
Abstract

The present invention discloses methods and devices for key management in an as-a-service (aaS) context. Methods include the steps of: upon receiving a creation request in a provider computing-environment, creating a specific key in at least one location in the provider computing-environment by repetitively computing respective specific-key contributions: in a set of N computing resources in the provider computing-environment; and in a set of M customer locations in a customer computing-environment; and applying the respective specific-key contributions to change a specific-key value in the computing resources, wherein the respective specific-key contributions are never revealed to any computing resources, and to any customer locations, other than respective contributors; wherein at least one location is a region of memory located in a computing resource operationally connected to the provider computing-environment, wherein the customer locations are regions of memory located in a computing resource operationally connected to the customer computing-environment.

Claims (29)

1. A method for key management in an as-a-service (aaS) context, the method comprising the steps of:

(a) upon receiving a creation request in a provider computing-environment, creating a specific key in at least one location in said provider computing-environment by repetitively computing respective specific-key contributions:

(i) in a set of N computing resources in said provider computing-environment, wherein N is a non-negative integer, and wherein said set of N computing resources includes all computing resources in said provider computing environment; and

(ii) in a set of M customer locations in a customer computing-environment, wherein M is a non-negative integer, wherein said set of M customer locations includes all customer locations in said customer computing environment, and wherein said customer computing-environment is outside of said provider computing-environment; and

(b) applying said respective specific-key contributions to change a specific-key value in said computing resources, wherein said respective specific-key contributions are never revealed in unencrypted form to any of said computing resources, and to any of said customer locations, other than respective creation-request contributors associated with said respective specific-key contributions during request initiation;

wherein said at least one location is a region of memory located in a given computing resource of said set of N computing resources, operationally connected to said provider computing-environment, wherein said customer locations are regions of memory located in a given computing resource of said set of M customer locations, operationally connected to said customer computing-environment, wherein said provider computing-environment is a computing environment of an aaS service provider, wherein said customer computing-environment is a computing environment of a customer of said aaS service provider, and wherein said provider computing-environment and said customer computing-environment are configured to exchange data with each other.

2. The method of claim 1 , wherein said repetitively computing includes computing at least three said specific-key contributions.

3. The method of claim 1 , wherein said step of applying is performed using at least one technique selected from the group consisting of: key joining, blinding encryption, partially-homomorphic encryption, and fully-homomorphic encryption.

4. A device for key management in an as-a-service (aaS) context, the device comprising:

(a) a server including:

(i) a CPU for performing computational operations;

(ii) a memory module for storing data; and

(iii) a network connection for communicating across a network; and

(b) a protection module, residing on said server, configured for:

(i) upon receiving a creation request in a provider computing-environment, creating a specific key in at least one location in said provider computing-environment by repetitively computing respective specific-key contributions:

(A) in a set of N computing resources in said provider computing-environment, wherein N is a non-negative integer, and wherein said set of N computing resources includes all computing resources in said provider computing environment; and

(B) in a set of M customer locations in a customer computing-environment, wherein M is a non-negative integer, wherein said set of M customer locations includes all customer locations in said customer computing environment, and wherein said customer computing-environment is outside of said provider computing-environment; and

(ii) applying said respective specific-key contributions to change a specific-key value in said computing resources, wherein said respective specific-key contributions are never revealed in unencrypted form to any of said computing resources, and to any said customer locations, other than respective creation-request contributors associated with said respective specific-key contributions during request initiation;

wherein said at least one location is a region of memory located in a given computing resource of said set of N computing resources, operationally connected to said provider computing-environment, wherein said customer locations are regions of memory located in a given computing resource of said set of M customer locations, operationally connected to said customer computing-environment, wherein said provider computing-environment is a computing environment of an aaS service provider, wherein said customer computing-environment is a computing environment of a customer of said aaS service provider, and wherein said provider computing-environment and said customer computing-environment are configured to exchange data with each other.

5. The device of claim 4 , wherein said repetitively computing includes computing at least three said specific-key contributions.

6. The device of claim 4 , wherein said applying is performed using at least one technique selected from the group consisting of: key joining, blinding encryption, partially-homomorphic encryption, and fully-homomorphic encryption.

7. A non-transitory computer-readable medium, having computer-readable code embodied on the non-transitory computer-readable medium for key management in an as-a-service (aaS) context, the computer-readable code comprising:

(a) program code for, upon receiving a creation request in a provider computing-environment, creating a specific key in at least one location in said provider computing-environment by repetitively computing respective specific-key contributions:

(i) in a set of N computing resources in said provider computing-environment, wherein N is a non-negative integer, and wherein said set of N computing resources includes all computing resources in said provider computing environment; and

(ii) in a set of M customer locations in a customer computing-environment, wherein M is a non-negative integer, wherein said set of M customer locations includes all customer locations in said customer computing environment, and wherein said customer computing-environment is outside of said provider computing-environment; and

(b) program code for, applying said respective specific-key contributions to change a specific-key value in said computing resources, wherein said respective specific-key contributions are never revealed in unencrypted form to any of said computing resources, and to any said customer locations, other than respective creation-request contributors associated with said respective specific-key contributions during request initiation;

wherein said at least one location is a region of memory located in a given computing resource of said set of N computing resources, operationally connected to said provider computing-environment, wherein said customer locations are regions of memory located in a given computing resource of said set of M customer locations, operationally connected to said customer computing-environment, wherein said provider computing-environment is a computing environment of an aaS service provider, wherein said customer computing-environment is a computing environment of a customer of said aaS service provider, and wherein said provider computing-environment and said customer computing-environment are configured to exchange data with each other.

8. The non-transitory computer-readable medium of claim 7 , wherein repetitively computing includes computing at least three said specific-key contributions.

9. The non-transitory computer-readable medium of claim 7 , wherein said applying is performed using at least one technique selected from the group consisting of: key joining, blinding encryption, partially-homomorphic encryption, and fully-homomorphic encryption.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2015
From: PARANN-NISSANY, GILAD
To: PORTICOR LTD.
Reel/Frame 035879/0740 →
Continuity (2)
Provisional Application 62015547 · Jun 23, 2014
Related Publication 20150372812A1 · Dec 24, 2015