IP Library Granted Patent US 9,716,696
Granted Patent B2
US 9,716,696 · App. 15/204,601 · Granted Jul 25, 2017

Encryption in the cloud using enterprise managed keys

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,716,696
App. No.
15/204,601
Granted
Jul 25, 2017
Kind
B2
Abstract

An encryption key management system and method implements enterprise managed encryption key for an enterprise using encryption for cloud-based services. In some embodiments, the enterprise deploys a key agent on the enterprise data network to distribute encryption key material to the network intermediary on a periodic basis. The network intermediary receives the encryption key material from the enterprise and stores the encryption key material in temporary storage and uses the received encryption key material to derive a data encryption key to perform the encryption of the enterprise's data. In this manner, the enterprise can be provided with the added security assurance of maintaining and managing its own encryption key while using cloud-based data storage services. The encryption key management system and method can be applied to ensure that the enterprise's one or more encryption keys do not leave the enterprise's premises.

Claims (40)

1. A method of performing cloud-based encryption of data on behalf of an enterprise operating an enterprise data network using an enterprise managed encryption key, comprising:

receiving, at a proxy server deployed outside of the enterprise data network, a key material generated by a key agent deployed inside the enterprise data network, the key material being generated using the enterprise managed encryption key being available only within the enterprise data network;

storing the key material on the proxy server in a temporary memory for a first time period associated with a valid time period for the key material;

generating, at the proxy server, a data encryption key using the key material, the data encryption key being used to perform cloud-based encryption of data on behalf of the enterprise;

in response to the expiration of the first time period, repeating the receiving of a key material from the proxy server to generating a data encryption key based on the received key material;

providing a cloud based encryption service on the proxy server to encrypt and decrypt data on behalf of the enterprise using the key material;

receiving, at the proxy server, a first data in clear text from the enterprise data network;

transmitting the first data in clear text to a cloud service provider;

receiving, at the proxy server, a request from the cloud service provider to encrypt the first data, the request including the first data in clear text transmitted from the cloud service provider;

in response to the request from the cloud service provider, encrypting, at the proxy server, the first data received from the cloud service provider using the data encryption key; and

transmitting the encrypted first data to the cloud service provider to be stored on the cloud service provider as encrypted data at rest.

2. The method of claim 1 , further comprising:

receiving, at the proxy server, a request to decrypt an encrypted third data from the cloud service provider;

decrypting, at the proxy server, the encrypted third data on behalf of the enterprise using the data encryption key; and

providing the decrypted third data to the enterprise on behalf of the cloud service provider.

3. The method of claim 1 , wherein receiving the key material generated by the key agent deployed inside the enterprise data network comprises:

generating, at the key agent, a request to a hardware security module to decrypt an encrypted key material, wherein the hardware security module decrypts the encrypted key material using the enterprise managed encryption key being available only within the enterprise data network;

receiving, at the key agent, a decrypted key material;

storing the decrypted key material on the key agent in a temporary memory for a valid time period for the decrypted key material; and

transmitting the decrypted key material from the key agent to the proxy server as the key material.

4. The method of claim 1 , wherein receiving, at the proxy server, the request from the cloud service provider to encrypt the first data comprises:

receiving a call to the cloud based encryption service from the cloud service provider to encrypt the first data.

5. The method of claim 2 ,

wherein receiving, at the proxy server, the request to decrypt an encrypted third data from the cloud service provider comprises receiving a call to the cloud based encryption service from the cloud service provider to decrypt the third data.

6. The method of claim 1 , further comprising:

receiving, at the proxy server, the key material from the key agent on a periodic basis.

7. The method of claim 1 , wherein generating, using the proxy server, the data encryption key using the key material comprises:

generating, using a key derivation function, the data encryption key using the key material.

8. A system for performing cloud-based encryption of data on behalf of an enterprise operating an enterprise data network using an enterprise managed encryption key, comprising:

a hardware proxy server deployed outside of the enterprise data network, the hardware proxy server being configured to receive a key material generated by a key agent deployed inside the enterprise data network wherein the key material is generated using the enterprise managed encryption key being available only within the enterprise data network,

to store the key material on the hardware proxy server in a temporary memory for a first time period associated with a valid time period for the key material to generate a data encryption key using the key material where the data encryption key is used to perform cloud-based encryption of data on behalf of the enterprise, in response to the expiration of the first time period,

to repeat the receiving of a key material from the hardware proxy server to generating a data encryption key using the received key material to provide a cloud based encryption service on the hardware proxy server to encrypt and decrypt data on behalf of the enterprise based on the key material to receive a first data in clear text from the enterprise data network,

to transmit the first data in clear text to a cloud service provider, to receive a request from the cloud service provider to encrypt the first data, in response to the request from the cloud service provider, to encrypt the first data received from the cloud service provider using the data encryption key, and

to transmit the encrypted first data to the cloud service provider to be stored on the cloud service provider as encrypted data at rest.

9. The system of claim 8 , wherein the proxy server is further configured to receive a request to decrypt an encrypted third data from the cloud service provider, to decrypt the encrypted third data on behalf of the enterprise using the data encryption key, and to provide the decrypted third data to the enterprise on behalf of the cloud service provider.

10. The system of claim 8 , wherein the key agent is configured to generate a request to a hardware security module to decrypt an encrypted key material where the hardware security module decrypts the encrypted key material using the enterprise managed encryption key being available only within the enterprise data network, to receive a decrypted key material, to store the decrypted key material on the key agent in a temporary memory for a valid time period for the decrypted key material, and to transmit the decrypted key material from the key agent to the proxy server as the key material.

11. The system of claim 8 , wherein the proxy server is further configured to receive a call to the cloud based encryption service from the cloud service provider to encrypt the first data.

12. The system of claim 9 , wherein the proxy server is further configured to receive a call to the cloud based encryption service from the cloud service provider to decrypt the third data.

13. The system of claim 8 , wherein the proxy server is further configured to receive the key material from the key agent on a periodic basis.

14. The system of claim 8 , wherein the proxy server is further configured to generate the data encryption key using the key material and a key derivation function.

Assignments (16)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded May 9, 2022
From: SKYHIGH NETWORKS, LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 059912/0601 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2022
From: NARAYAN, KAUSHIK; GRUBBS, PAUL
To: SKYHIGH NETWORKS, INC
Reel/Frame 059762/0809 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 046416/0286 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: SKYHIGH NETWORKS, LLC
Reel/Frame 054211/0739 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 046416 FRAME: 0286. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 19, 2020
From: SKYHIGH NETWORKS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 054560/0325 →
CHANGE OF NAME Recorded Dec 27, 2018
From: SKYHIGH NETWORKS, INC.
To: SKYHIGH NETWORKS, LLC
Reel/Frame 047985/0853 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0225 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0286 →