IP Library Granted Patent US 11,227,058
Granted Patent B2
US 11,227,058 · App. 16/526,464 · Granted Jan 18, 2022

System and method for shredding a forum of secrets

Inventors: Naizhong Chiu (Newton, MA); Gregory W. Lazar (Upton, MA); Grace L. Heard (Seattle, WA)
Assignee: EMC IP HOLDING COMPANY, LLC
G06F21/6227G06F21/602H04L9/0894G06F2221/0751
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,227,058
App. No.
16/526,464
Granted
Jan 18, 2022
Kind
B2
Abstract

A method, computer program product, and computer system for storing, by a computing device, a data encryption key in a keystore. A plurality of stable system values may be generated, wherein a threshold number of the plurality of stable system values is required to access the data encryption key from the keystore. The plurality of stable system values may be stored in different locations. More stable system values of the plurality of stable system values than the threshold number of the plurality of stable system values required to access the data encryption key from the keystore may be deleted.

Claims (36)

1. A computer-implemented method comprising:

storing, by a computing device, —a data encryption key in a keystore;

generating a plurality of system values, wherein a threshold number of the plurality of system values is required to access the data encryption key from the keystore;

storing the plurality of system values in a plurality of different locations;

deleting more system values of the plurality of system values than the threshold number of the plurality of system values required to access the data encryption key from the keystore;

removing the data encryption key from the keystore, wherein deleting more system values of the plurality of system values than the threshold number of the plurality of system values required to access the data encryption key includes reprogramming at least a portion of the plurality of system values with new system values after the data encryption key has been removed; and

writing a new copy of the keystore from the data encryption key such that the new copy of the keystore is protected with the new system values.

2. The computer-implemented method of claim 1 wherein at least one location of the plurality of different locations includes electrically erasable programmable read-only memory.

3. The computer-implemented method of claim 1 wherein at least one location of the plurality of different locations includes a self-encrypting hard drive (SED).

4. The computer-implemented method of claim 3 wherein a range on the SED stores one or more of the plurality of system values.

5. The computer-implemented method of claim 4 further comprising locking the range on the SED with a unique PIN.

6. The computer-implemented method of claim 3 wherein the data encryption key is a unique data encryption key provisioned for the SED.

7. The computer-implemented method of claim 1 wherein writing the new copy of the keystore from the data encryption key includes the keystore becoming inaccessible in response to removing the data encryption key from the keystore.

8. A computer program product residing on a non-transitory computer readable storage medium having a plurality of instructions stored thereon which, when executed across one or more processors, causes at least a portion of the one or more processors to perform operations comprising:

storing —a data encryption key in a keystore;

generating a plurality of system values, wherein a threshold number of the plurality of system values is required to access the data encryption key from the keystore;

storing the plurality of system values in a plurality of different locations;

deleting more system values of the plurality of system values than the threshold number of the plurality of system values required to access the data encryption key from the keystore;

removing the data encryption key from the keystore, wherein deleting more system values of the plurality of system values than the threshold number of the plurality of system values required to access the data encryption key includes reprogramming at least a portion of the plurality of system values with new system values after the data encryption key has been removed; and

writing a new copy of the keystore from the data encryption key such that the new copy of the keystore is protected with the new system values.

9. The computer program product of claim 8 wherein at least one location of the plurality of different locations includes electrically erasable programmable read-only memory.

10. The computer program product of claim 8 wherein at least one location of the plurality of different locations includes a self-encrypting hard drive (SED).

11. The computer program product of claim 10 wherein a range on the SED stores one or more of the plurality of system values.

12. The computer program product of claim 11 wherein the operations further comprise locking the range on the SED with a unique PIN.

13. The computer program product of claim 10 wherein the data encryption key is a unique data encryption key provisioned for the SED.

14. A computing system including one or more processors and one or more memories configured to perform operations comprising:

storing a data encryption key in a keystore;

generating a plurality of system values, wherein a threshold number of the plurality of system values is required to access the data encryption key from the keystore;

storing the plurality of system values in a plurality of different locations;

deleting more system values of the plurality of system values than the threshold number of the plurality of system values required to access the data encryption key from the keystore;

removing the data encryption key from the keystore, wherein deleting more system values of the plurality of system values than the threshold number of the plurality of system values required to access the data encryption key includes reprogramming at least a portion of the plurality of system values with new system values after the data encryption key has been removed; and

writing a new copy of the keystore from the data encryption key such that the new copy of the keystore is protected with the new system values.

15. The computing system of claim 14 wherein at least one location of the plurality of different locations includes one of an electrically erasable programmable read-only memory and a self-encrypting hard drive (SED).

16. The computing system of claim 15 wherein a range on the SED stores one or more of the plurality of system values.

17. The computing system of claim 16 wherein the operations further comprise locking the range on the SED with a unique PIN.

18. The computing system of claim 15 wherein the data encryption key is a unique data encryption key provisioned for the SED.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053311/0169) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060438/0742 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0571) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060436/0088 →
RELEASE OF SECURITY INTEREST AT REEL 050406 FRAME 421 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058213/0825 →
SECURITY INTEREST Recorded Jun 5, 2020
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 053311/0169 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0571 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050406/0421 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2019
From: CHIU, NAIZHONG; LAZAR, GREGORY W.; HEARD, GRACE L.
To: EMC IP HOLDING COMPANY, LLC
Reel/Frame 049906/0546 →