IP Library Granted Patent US 11,431,488
Granted Patent B1
US 11,431,488 · App. 16/895,660 · Granted Aug 30, 2022

Protecting local key generation using a remote key management service

Inventor: Constantine Sapuntzakis (Mountain View, CA)
Assignee: Pure Storage, Inc.
H04L9/085H04L9/083H04L9/0822H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,431,488
App. No.
16/895,660
Granted
Aug 30, 2022
Kind
B1
Abstract

Protecting local key generation using a remote key management service, including: transforming a local secret to generate a transformed local secret; transmitting the transformed local secret to a key management service; and decrypting, based on an encryption key received from the key management service, a data encryption key for encrypting or decrypting local data.

Claims (38)

1. A method comprising:

transforming a local secret to generate a transformed local secret;

transmitting the transformed local secret to a key management service;

transforming an encryption key received from the key management service to generate a key-encrypting key, wherein the encryption key is a one-way cryptographic hash using, as input, the transformed local secret transmitted to the key management service; and

decrypting, based on the key-encrypting key, a local data encryption key for encrypting or decrypting local data.

2. The method of claim 1 , further comprising:

in response to transmitting the transformed local secret to the key management service, receiving, from the key management service, the encryption key based on the transformed local secret.

3. The method of claim 1 , further comprising:

decrypting, based on the local data encryption key, the local data.

4. The method of claim 1 , wherein transforming the local secret comprises:

generating, based on a cryptographic hash function using the local secret, the transformed local secret.

5. The method of claim 4 , wherein the cryptographic hash function is used by a hash-based message authentication code protocol.

6. The method of claim 1 , further comprising:

reconstructing the local secret based on multiple portions of the local secret distributed among a plurality of storage devices.

7. The method of claim 1 , wherein transforming the encryption key comprises performing a one-way cryptographic hash of the encryption key.

8. An apparatus comprising a computer processor, a computer memory operatively coupled to the computer processor, the computer memory having disposed within it computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:

transforming a local secret to generate a transformed local secret;

transmitting the transformed local secret to a key management service;

transforming an encryption key received from the key management service to generate a key-encrypting key, wherein the encryption key is a one-way cryptographic hash using, as input, the transformed local secret transmitted to the key management service; and

decrypting, based on the key-encrypting key, a local data encryption key for encrypting or decrypting local data.

9. The apparatus of claim 8 , further comprising computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:

receiving, in response to transmitting the transformed local secret to the key management service, from the key management service, the encryption key based on the transformed local secret.

10. The apparatus of claim 8 , further comprising computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:

decrypting, based on the local data encryption key, the local data.

11. The apparatus of claim 8 , further comprising computer program instructions that, when executed by the computer processor, cause the apparatus to carry out the steps of:

generating, based on a cryptographic hash function using the local secret, the transformed local secret.

12. The apparatus of claim 11 , wherein the cryptographic hash function is used by a hash-based message authentication code protocol.

13. The apparatus of claim 8 , wherein transforming the encryption key comprises performing a one-way cryptographic hash of the encryption key.

14. A computer program product disposed upon a non-transitory computer readable medium, the computer program product comprising computer program instructions that, when executed, cause a computer to carry out the steps of:

transforming a local secret to generate a transformed local secret;

transmitting the transformed local secret to a key management service;

transforming an encryption key received from the key management service to generate a key-encrypting key, wherein the encryption key is a one-way cryptographic hash using, as input, the transformed local secret transmitted to the key management service; and

decrypting, based on the key-encrypting key, a local data encryption key for encrypting or decrypting local data.

15. The computer program product of claim 14 , further comprising computer program instructions that, when executed, cause the computer to carry out the steps of:

receiving, in response to transmitting the transformed local secret to the key management service, from the key management service, the encryption key based on the transformed local secret.

16. The computer program product of claim 14 , further comprising computer program instructions that, when executed, cause the computer to carry out the steps of:

decrypting, based on the local data encryption key, the local data.

17. The computer program product of claim 14 , wherein transforming the encryption key comprises performing a one-way cryptographic hash of the encryption key.

Assignments (3)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 11, 2025
From: BARCLAYS BANK PLC, AS ADMINISTRATIVE AGENT
To: PURE STORAGE, INC.
Reel/Frame 071558/0523 →
SECURITY INTEREST Recorded Aug 26, 2020
From: PURE STORAGE, INC.
To: BARCLAYS BANK PLC AS ADMINISTRATIVE AGENT
Reel/Frame 053867/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2020
From: SAPUNTZAKIS, CONSTANTINE
To: PURE STORAGE, INC.
Reel/Frame 052868/0159 →
Cited By (5)
US 12,231,537 US 12,353,609 US 12,556,377 US 12,561,193 US 12,627,470