IP Library Granted Patent US 11,595,191
Granted Patent B2
US 11,595,191 · App. 17/179,920 · Granted Feb 28, 2023

Encryption key management system and encryption key management method

Inventors: Yutaka Yoshida (Tokyo, JP); Mioko Moriguchi (Tokyo, JP)
Assignee: Hitachi, Ltd.
H04L9/0822H04L9/083H04L9/0891H04L9/0894H04L9/3236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,595,191
App. No.
17/179,920
Granted
Feb 28, 2023
Kind
B2
Abstract

A storage apparatus sends a request for a key encryption key to a key management server using a storage apparatus ID as a parameter, acquires the key encryption key, for which a request has been sent to the key management server, and its attribute information, and stores the key encryption key and its attribute information in a key encryption key list while eliminating the key encryption key that is duplicated. Then, in the order listed in the key encryption key list, decryption of the encryption key is attempted by the key encryption key stored in the key encryption key list, and the success or failure of the decryption of the encryption key is determined. When the decryption of the encryption key using the key encryption key fails, the decryption of the encryption key is attempted using a key encryption key, which has not been attempted yet, in the key encryption key list.

Claims (45)

1. An encryption key management system, comprising:

a storage apparatus that encrypts data with one or more encryption keys and stores the encrypted data; and

one or more key management servers connected to the storage apparatus through a network,

wherein each of the key management servers holds one or more key encryption keys for encrypting the encryption keys together with its attribute information,

the storage apparatus holds the encryption keys encrypted by the key encryption keys,

the storage apparatus sends a request for the key encryption key corresponding to the storage apparatus to the key management server using a storage apparatus ID for uniquely identifying the storage apparatus as a parameter,

the storage apparatus acquires the key encryption key corresponding to the storage apparatus and its attribute information from the key management server,

the storage apparatus stores the acquired key encryption key and its attribute information in a key encryption key list while eliminating the key encryption key that is duplicated, and

the storage apparatus attempts to decrypt the encryption key using the key encryption key stored in the key encryption key list, determines a success or failure of the decryption of the encryption key, and attempts to decrypt the encryption key using the key encryption key stored in the key encryption key list, which has not been attempted yet, when the decryption of the encryption key using the key encryption key fails.

2. The encryption key management system according to claim 1 ,

wherein the attribute information includes a generation date and time of the key encryption key, and

in the key encryption key list, the key encryption keys are arranged in order of a new generation date and time.

3. The encryption key management system according to claim 1 ,

wherein the storage apparatus generates a hash value from data indicating the key encryption key acquired from the key management server, and stores the hash value in the key encryption key list in association with the acquired key encryption key, and

the hash value is used to determine whether or not a duplicate key encryption key is stored in the key encryption key list.

4. The encryption key management system according to claim 1 ,

wherein the key encryption key list and the decrypted encryption key are held in a volatile memory of the storage apparatus.

5. An encryption key management system, comprising:

a storage apparatus that encrypts data with one or more encryption keys and stores the encrypted data; and

one or more key management servers connected to the storage apparatus through a network,

wherein each of the key management servers holds one or more key encryption keys for encrypting the encryption keys together with its attribute information,

the storage apparatus holds the encryption keys encrypted by the key encryption keys,

the storage apparatus sends a request for the key encryption key corresponding to the storage apparatus to the key management server using a storage apparatus ID for uniquely identifying the storage apparatus as a parameter,

the storage apparatus acquires the key encryption key corresponding to the storage apparatus and its attribute information from the key management server,

the storage apparatus stores the key encryption key and its attribute information in a key encryption key list while eliminating the key encryption key that is duplicated,

the attribute information includes a generation date and time of the key encryption key,

in the key encryption key list, the key encryption keys are arranged in order of a new generation date and time,

the storage apparatus stores a key management server number that specifies a key encryption key to acquire the key encryption key corresponding to the storage apparatus,

when there is the same key management server number, the storage apparatus sets a key encryption key having a new generation date and time as a key encryption key for update and sets a key encryption key having a next generation date and time as an old key encryption key in order of a generation date and time and attempts decryption using the old key encryption key,

when there is no same key management server number, the storage apparatus sets the key encryption key stored in the key encryption key list as an old key encryption key, requests the key management server to generate a new key encryption key for update, and acquires the key encryption key for update,

the storage apparatus determines a success or failure of the decryption using the old key encryption key, and encrypts the decrypted encryption key with the key encryption key for update when the decryption using the old key encryption key is successful,

when there is the same key management server number, the storage apparatus requests the key management server to delete key encryption keys other than the key encryption key for update, and

when there is no same key management server number, the storage apparatus requests the key management server to delete key encryption keys stored in the key encryption key list.

6. The encryption key management system according to claim 5 ,

wherein the storage apparatus periodically acquires the key encryption key, for which a request has been sent to the key management server, and its attribute information, and

the storage apparatus determines whether or not there is the same key management server number in the key encryption key list, and generates an alert or requests the key management server to perform key encryption key re-update or key encryption key synchronization when there is the same key management server number in the key encryption key list.

7. An encryption key management method using an encryption key management system in which a storage apparatus that encrypts data with one or more encryption keys and stores the encrypted data is connected to one or more key management servers through a network, the method comprising:

a step in which each of the key management servers holds one or more key encryption keys for encrypting the encryption keys together with its attribute information;

a step in which the storage apparatus sends a request for the key encryption key to the key management server using a storage apparatus ID for uniquely identifying the storage apparatus as a parameter;

a step in which the storage apparatus holds the encryption keys encrypted by the key encryption keys;

a step in which the storage apparatus sends a request for the key encryption key corresponding to the storage apparatus to the key management server using a storage apparatus ID for uniquely identifying the storage apparatus as a parameter;

a step in which the storage apparatus acquires the key encryption key, for which a request has been sent to the key management server, and its attribute information;

a step in which the storage apparatus stores the key encryption key and its attribute information in a key encryption key list while eliminating the key encryption key that is duplicated;

a step in which the storage apparatus attempts to decrypt the encryption key using the key encryption key stored in the key encryption key list; and

a step in which the storage apparatus determines a success or failure of the decryption of the encryption key and attempts to decrypt the encryption key using the key encryption key stored in the key encryption key list, which has not been attempted yet, when the decryption of the encryption key using the key encryption key fails.

Assignments (2)
COMPANY SPLIT Recorded Aug 20, 2024
From: HITACHI, LTD.
To: HITACHI VANTARA, LTD.
Reel/Frame 069518/0761 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2021
From: YOSHIDA, YUTAKA; MORIGUCHI, MIOKO
To: HITACHI, LTD.
Reel/Frame 055339/0011 →
Priority Claims (1)
JP JP2020-145933 · Aug 31, 2020 · national
Continuity (1)
Related Publication 20220069983A1 · Mar 3, 2022