IP Library Granted Patent US 11,418,331
Granted Patent B1
US 11,418,331 · App. 17/185,474 · Granted Aug 16, 2022

Importing cryptographic keys into key vaults

Inventors: Sridhar Villapakkam (Grafton, MA); Ajit Bhagwat (Lexington, MA)
Assignee: EMC IP Holding Company LLC
H04L9/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,418,331
App. No.
17/185,474
Granted
Aug 16, 2022
Kind
B1
Abstract

Techniques are provided to import a cryptographic key into a key vault in which an application programming interface for the key vault does not support importing existing cryptographic keys into the key vault. A key management system obtains a cryptographic key from a first key vault. The cryptographic key includes a key value and attributes which describe the cryptographic key. The key management system imports the cryptographic key into a second key vault by generating a surrogate key in the second key vault which corresponds to the cryptographic key. The surrogate key includes a key attribute having a value which corresponds to the key value of the cryptographic key.

Claims (56)

1. A method, comprising:

obtaining, by a key management system, a cryptographic key from a first key vault, wherein the cryptographic key comprises a key value and attributes which describe the cryptographic key; and

importing, by the key management system, the cryptographic key into a second key vault by generating and storing a surrogate key in the second key vault which corresponds to the imported cryptographic key;

wherein generating the surrogate key comprises:

creating a new cryptographic key in the second key vault using an application programming interface (API) of the second key vault, the new cryptographic key comprising attributes specified by the API;

designating the new cryptographic key as the surrogate key; and

setting a value of at least one attribute of the surrogate key to a value of a corresponding attribute of the imported cryptographic key;

wherein the surrogate key comprises a key attribute which is set to a value which corresponds to the key value of the imported cryptographic key.

2. The method of claim 1 , wherein

setting the value of at least one attribute of the surrogate key comprises setting values of the attributes of the surrogate key equal to values of corresponding attributes of the imported cryptographic key.

3. The method of claim 1 , wherein the key attribute of the surrogate key comprises a custom attribute which is created using the API of the second key vault.

4. The method of claim 1 , further comprising setting a value of a key proxy attribute of the surrogate key equal to a value of a key proxy attribute of the imported cryptographic key.

5. The method of claim 1 , wherein the value of the key attribute is set equal to the key value of the imported cryptographic key.

6. The method of claim 1 , further comprising:

encrypting the key value of the imported cryptographic key; and

setting the value of the key attribute equal to the encrypted key value of the imported cryptographic key.

7. The method of claim 1 , wherein obtaining the cryptographic key from the first key vault, comprises:

receiving, by the key management system, a cryptographic request from a client application, wherein the cryptographic request comprises a key proxy assigned to the client application and at least one of encrypted data and plaintext data;

determining, by the key management system, which key vault, among a plurality of key vaults comprising at least the first key vault and the second key vault, hosts a cryptographic key associated with the received key proxy;

obtaining, by the key management system, the cryptographic key from the first key vault in response to determining that the first vault hosts the cryptographic key which corresponds to the received key proxy; and

utilizing, by the key management system, the key value of the cryptographic key to one of (i) encrypt the received plaintext data, and (ii) decrypt the received encrypted data.

8. The method of claim 1 , wherein obtaining the cryptographic key from the first key vault is performed as part of a vault merging process performed by the key management system to consolidate the first and second vaults by importing cryptographic keys in the first vault into the second vault.

9. An article of manufacture comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code is executable by one or more processors to implement a method comprising:

obtaining, by a key management system, a cryptographic key from a first key vault, wherein the cryptographic key comprises a key value and attributes which describe the cryptographic key; and

importing, by the key management system, the cryptographic key into a second key vault by generating and storing a surrogate key in the second key vault which corresponds to the imported cryptographic key;

wherein generating the surrogate key comprises:

creating a new cryptographic key in the second key vault using an application programming interface (API) of the second key vault, the new cryptographic key comprising attributes specified by the API;

designating the new cryptographic key as the surrogate key; and

setting a value of at least one attribute of the surrogate key to a value of a corresponding attribute of the imported cryptographic key;

wherein the surrogate key comprises a key attribute which is set to a value which corresponds to the key value of the imported cryptographic key.

10. The article of manufacture of claim 9 , wherein

setting the value of at least one attribute of the surrogate key comprises setting values of the attributes of the surrogate key equal to values of corresponding attributes of the imported cryptographic key.

11. The article of manufacture of claim 9 , wherein the key attribute of the surrogate key comprises a custom attribute which is created using the API of the second key vault.

12. The article of manufacture of claim 9 , further comprising program code that is executable by the one or more processors to perform a method which comprises setting a value of a key proxy attribute of the surrogate key equal to a value of a key proxy attribute of the imported cryptographic key.

13. The article of manufacture of claim 9 , wherein the value of the key attribute is set equal to the key value of the imported cryptographic key.

14. The article of manufacture of claim 9 , further comprising program code that is executable by the one or more processors to perform a method which comprises:

encrypting the key value of the imported cryptographic key; and

setting the value of the key attribute equal to the encrypted key value of the imported cryptographic key.

15. A system, comprising:

at least one processor; and

a system memory configured to store program code, wherein the program code is executable by the at least one processor to instantiate a key management system, wherein the key management system is configured to:

obtain a cryptographic key from a first key vault, wherein the cryptographic key comprises a key value and attributes which describe the cryptographic key; and

import the cryptographic key into a second key vault by generating and storing a surrogate key in the second key vault which corresponds to the imported cryptographic key;

wherein in generating the surrogate key, the key management system is configured to:

create a new cryptographic key in the second key vault using an application programming interface (API) of the second key vault, the new cryptographic key comprising attributes specified by the API;

designate the new cryptographic key as the surrogate key; and

set a value of at least one attribute of the surrogate key to a value of a corresponding attribute of the imported cryptographic key;

wherein the surrogate key comprises a key attribute which is set to a value which corresponds to the key value of the imported cryptographic key.

16. The system of claim 15 , wherein in setting the value of at least one attribute of the surrogate key, the key management system is configured to:

set values of the attributes of the surrogate key equal to values of corresponding attributes of the imported cryptographic key.

17. The system of claim 15 , wherein the key attribute of the surrogate key comprises a custom attribute which is created using the API of the second key vault.

18. The system of claim 15 , wherein the key management system is further configured to set a value of a key proxy attribute of the surrogate key equal to a value of a key proxy attribute of the imported cryptographic key.

19. The system of claim 15 , wherein the key management system is configured to set the value of the key attribute equal to the key value of the imported cryptographic key.

20. The system of claim 15 , wherein the key management system is configured to:

encrypt the key value of the imported cryptographic key; and

set the value of the key attribute equal to the encrypted key value of the imported cryptographic key.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0280) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0255 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0124) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0012 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056295/0001) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062021/0844 →
RELEASE OF SECURITY INTEREST Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058297/0332 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0124 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0001 →
SECURITY INTEREST Recorded May 19, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056295/0280 →
CORRECTIVE ASSIGNMENT TO CORRECT THE MISSING PATENTS THAT WERE ON THE ORIGINAL SCHEDULED SUBMITTED BUT NOT ENTERED PREVIOUSLY RECORDED AT REEL: 056250 FRAME: 0541. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 17, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056311/0781 →
SECURITY AGREEMENT Recorded May 14, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 056250/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2021
From: VILLAPAKKAM, SRIDHAR; BHAGWAT, AJIT
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 055414/0964 →