IP Library Granted Patent US 10,615,968
Granted Patent B1
US 10,615,968 · App. 15/887,512 · Granted Apr 7, 2020

Shuffling cryptographic keys stored in clouds of a multi-cloud environment

Inventors: Andrew Byrne (Castlemartyr, IE); Donagh A. Buckley (Banteer, IE)
Assignee: EMC IP Holding Company LLC
H04L9/0822G06F16/2246H04L9/0643H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,615,968
App. No.
15/887,512
Granted
Apr 7, 2020
Kind
B1
Abstract

A method includes receiving, at a key management system from one or more client devices, one or more requests for cryptographic keys stored in respective clouds of a plurality of cloud service providers in a multi-cloud environment, the cryptographic keys being distributed across different ones of the respective clouds of the plurality of cloud service providers in the multi-cloud environment. The method also includes determining a location of a given one of the requested cryptographic keys on one or more of the clouds of the cloud service providers in the multi-cloud environment, retrieving the given cryptographic key from the determined location in the multi-cloud environment, providing the given cryptographic key to a given one of the client devices, and shuffling the distribution of the cryptographic keys across the clouds of the plurality of cloud service providers in the multi-cloud environment.

Claims (41)

1. A method comprising:

receiving, at a key management system from one or more client devices, one or more requests for cryptographic keys stored in respective clouds of a plurality of cloud service providers in a multi-cloud environment, the cryptographic keys being distributed across different ones of the respective clouds of the plurality of cloud service providers in the multi-cloud environment;

determining a location of a given one of the requested cryptographic keys on one or more of the clouds of the cloud service providers in the multi-cloud environment;

retrieving the given cryptographic key from the determined location in the multi-cloud environment;

providing the given cryptographic key to a given one of the client devices; and

shuffling the distribution of the cryptographic keys across the clouds of the plurality of cloud service providers in the multi-cloud environment;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The method of claim 1 wherein the key management system is implemented on an additional cloud of an additional cloud service provider distinct from the plurality of cloud service providers on which the cryptographic keys are stored.

3. The method of claim 1 wherein the given cryptographic key comprises a key encryption key (KEK) utilized to encrypt one or more data encryption keys (DEKs) that protect data stored in the multi-cloud environment.

4. The method of claim 1 wherein the cryptographic keys are distributed across the clouds of the plurality of cloud service providers in the multi-cloud environment utilizing a tree structure, and wherein portions of the cryptographic keys are stored in leaves of the tree structure.

5. The method of claim 4 wherein the tree structure comprises an unchained B+ tree structure.

6. The method of claim 4 wherein internal nodes and the leaves of the tree structure are distributed among the clouds of the plurality of cloud service providers in the multi-cloud environment.

7. The method of claim 4 wherein a given node of the tree structure comprises a logical identifier, the logical identifier comprising:

a first portion identifying a given one of the cloud service providers;

a second portion identifying a level of the tree structure; and

a third portion indicating a location on a given cloud within the given cloud service provider.

8. The method of claim 1 wherein the given cryptographic key comprises two or more portions distributed across clouds of two or more of the plurality of cloud service providers in the multi-cloud environment.

9. The method of claim 1 wherein the plurality of cloud service providers in the multi-cloud environment provide confidentiality and integrity protection for the plurality of cryptographic keys stored thereon.

10. The method of claim 9 wherein the plurality of cloud service providers utilize encryption of the cryptographic keys to provide confidentiality and keyed-hash message authentication codes (HMACs) of the cryptographic keys to provide integrity protection.

11. The method of claim 1 wherein the plurality of cloud service providers in the multi-cloud environment are not provisioned with knowledge of the ownership or associations of the cryptographic keys stored thereon.

12. The method of claim 1 wherein shuffling the distribution of the cryptographic keys across the clouds of the plurality of cloud service providers in the multi-cloud environment is performed responsive to each of the one or more requests received at the key management system.

13. The method of claim 12 wherein shuffling the distribution of the cryptographic keys across the clouds of the plurality of cloud service providers comprises moving each of the cryptographic keys from a previous location on a cloud of one of the cloud service providers in the multi-cloud environment to a new location on a cloud of a different one of the cloud service providers in the multi-cloud environment.

14. The method of claim 1 wherein shuffling the distribution of the cryptographic keys across the clouds of the plurality of cloud service providers comprises re-distributing the cryptographic keys pseudo-randomly across the clouds of the plurality of cloud service providers in the multi-cloud environment.

15. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device cause the at least one processing device:

to receive, at a key management system from one or more client devices, one or more requests for cryptographic keys stored in respective clouds of a plurality of cloud service providers in a multi-cloud environment, the cryptographic keys being distributed across different ones of the respective clouds of the plurality of cloud service providers in the multi-cloud environment;

to determine a location of a given one of the requested cryptographic keys on one or more of the clouds of the cloud service providers in the multi-cloud environment;

to retrieve the given cryptographic key from the determined location in the multi-cloud environment;

to provide the given cryptographic key to a given one of the client devices; and

to shuffle the distribution of the cryptographic keys across the clouds of the plurality of cloud service providers in the multi-cloud environment.

16. The computer program product of claim 15 wherein shuffling the distribution of the cryptographic keys across the clouds of the plurality of cloud service providers in the multi-cloud environment is performed responsive to each of the one or more requests received at the key management system, and wherein shuffling the distribution of the cryptographic keys across the clouds of the plurality of cloud service providers comprises moving each of the cryptographic keys from a previous location on a cloud of one of the cloud service providers in the multi-cloud environment to a new location on a cloud of a different one of the cloud service providers in the multi-cloud environment.

17. The computer program product of claim 15 wherein the cryptographic keys are distributed across the clouds of the plurality of cloud service providers in the multi-cloud environment utilizing a tree structure, and wherein portions of the cryptographic keys are stored in leaves of the tree structure.

18. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured:

to receive, at a key management system from one or more client devices, one or more requests for cryptographic keys stored in respective clouds of a plurality of cloud service providers in a multi-cloud environment, the cryptographic keys being distributed across different ones of the respective clouds of the plurality of cloud service providers in the multi-cloud environment;

to determine a location of a given one of the requested cryptographic keys on one or more of the clouds of the cloud service providers in the multi-cloud environment;

to retrieve the given cryptographic key from the determined location in the multi-cloud environment;

to provide the given cryptographic key to a given one of the client devices; and

to shuffle the distribution of the cryptographic keys across the clouds of the plurality of cloud service providers in the multi-cloud environment.

19. The apparatus of claim 18 wherein shuffling the distribution of the cryptographic keys across the clouds of the plurality of cloud service providers in the multi-cloud environment is performed responsive to each of the one or more requests received at the key management system, and wherein shuffling the distribution of the cryptographic keys across the clouds of the plurality of cloud service providers comprises moving each of the cryptographic keys from a previous location on a cloud of one of the cloud service providers in the multi-cloud environment to a new location on a cloud of a different one of the cloud service providers in the multi-cloud environment.

20. The apparatus of claim 18 wherein the cryptographic keys are distributed across the clouds of the plurality of cloud service providers in the multi-cloud environment utilizing a tree structure, and wherein portions of the cryptographic keys are stored in leaves of the tree structure.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045482/0131) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 061749/0924 →
RELEASE OF SECURITY INTEREST AT REEL 045482 FRAME 0395 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058298/0314 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2018
From: BYRNE, ANDREW; BUCKLEY, DONAGH A.
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 045202/0613 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 045482/0131 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 045482/0395 →
Cited By (2)
US 12,289,407 US 12,689,501