IP Library Granted Patent US 11,196,558
Granted Patent B1
US 11,196,558 · App. 17/196,341 · Granted Dec 7, 2021

Systems, methods, and computer-readable media for protecting cryptographic keys

Inventors: Septimiu F. Mare (Timisoara, RO); Najwa Aaraj (Abu Dhabi, AE); Marcos Manzano (Abu Dhabi, AE); Alvaro Garcia (Abu Dhabi, AE)
Assignee: TECHNOLOGY INNOVATION INSTITUTE
H04L9/0897H04L9/085H04L9/0819
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,196,558
App. No.
17/196,341
Granted
Dec 7, 2021
Kind
B1
Abstract

Systems, methods, and computer-readable media for protecting cryptographic keys are provided. Each cryptographic key is divided into multiple shares for storage at remote locations and for storage on a local device.

Claims (55)

1. A method implemented in a terminal device, comprising:

generating a page key for use in encrypting a data page;

encrypting the page key to provide an encrypted page key;

applying a key distribution scheme to the encrypted page key to generate a plurality of remote shares and at least one local share;

discarding the encrypted page key after the key distribution scheme has been applied to the encrypted key;

distributing the remote shares to a plurality of remote servers;

storing the at least one local share on the terminal device;

reconstructing the encrypted page key comprising:

fetching the remote shares from the plurality of remote servers;

retrieving the at least one local share from the terminal device; and

combining the fetched remote shares and the retrieved at least one local share to reconstruct the encrypted page key;

discarding the remote shares from the terminal device after the remote shares are distributed to the plurality of remote servers or after the encrypted page key has been reconstructed; and

instructing the plurality of remote servers not to provide any remote shares stored therein in response to an active panic mode.

2. The method of claim 1 , wherein said applying the key distribution scheme comprises:

splitting the encrypted page key into N shares, wherein K shares are required to reconstruct the encrypted page key;

designating R shares as the plurality of remote shares; and

designating L shares as the at least one local share.

3. The method of claim 2 , wherein when K is equal to N, R+L=N, and wherein when N>K, R<K<N.

4. The method of claim 1 , further comprising discarding the page key after the page key has been encrypted to provide the encrypted page key.

5. The method of claim 1 , further comprising encrypting the data page with the page key.

6. The method of claim 1 , further comprising decrypting the encrypted page key to provide the page key after the encrypted page key has been reconstructed.

7. The method of claim 6 , further decrypting an encrypted data page using the page key.

8. A computer-readable storage medium containing program instructions for a method being executed by an application, the application comprising code for one or more components that are called by the application during runtime, wherein execution of the program instructions by one or more processors of a computer system causes the one or more processors to perform steps comprising:

generating a page key for use in encrypting a data page;

encrypting the page key to provide an encrypted page key;

applying a key distribution scheme to the encrypted page key to generate a plurality of remote shares and at least one local share;

discarding the encrypted page key after the key distribution scheme has been applied to the encrypted key;

distributing the remote shares to a plurality of remote servers;

storing the at least one local share on the terminal device;

reconstructing the encrypted page key comprising:

fetching the remote shares from the plurality of remote servers;

retrieving the at least one local share from the terminal device; and

combining the fetched remote shares and the retrieved at least one local share to reconstruct the encrypted page key;

discarding the remote shares from the terminal device after the remote shares are distributed to the plurality of remote servers or after the encrypted page key has been reconstructed; and

instructing the plurality of remote servers not to provide any remote shares stored therein in response to an active panic mode.

9. The computer readable storage medium of claim 8 , wherein said applying the key distribution scheme comprises:

splitting the encrypted page key into N shares, wherein K shares are required to reconstruct the encrypted page key;

designating R shares as the plurality of remote shares; and

designating L shares as the at least one local share.

10. The computer readable storage medium of claim 9 , wherein K is equal to N or K is less than N.

11. The computer readable storage medium of claim 8 , the method further comprising discarding the page key after the page key has been encrypted to provide the encrypted page key.

12. The computer readable storage medium of claim 8 , the method further comprising encrypting the data page with the page key.

13. The computer readable storage medium of claim 8 , the method comprising decrypting the encrypted page key to provide the page key after the encrypted page key has been reconstructed.

14. The computer readable storage medium of claim 13 , the method further decrypting an encrypted data page using the page key.

15. A system comprising:

a terminal device operative to:

generate a page key for use in encrypting a data page;

encrypt the page key to provide an encrypted page key;

apply a key distribution scheme to the encrypted page key to generate a plurality of remote shares and at least one local share;

discard the encrypted page key after the key distribution scheme has been applied to the encrypted key;

distribute the remote shares to a plurality of remote servers;

store the at least one local share on the terminal device;

reconstruct the encrypted page key by fetching the remote shares from the plurality of remote servers, retrieving the at least one local share from the terminal device, and combining the fetched remote shares and the retrieved at least one local share to reconstruct the encrypted page key;

discard the remote shares from the terminal device after the remote shares are distributed to the plurality of remote servers or after the encrypted page key has been reconstructed; and

instruct the plurality of remote servers not to provide any remote shares stored therein in response to an active panic mode.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 17, 2022
From: MARE, SEPTIMIU F.; AARAJ, NAJWA; MANZANO, MARCOS; GARCIA, ALVARO
To: TECHNOLOGY INNOVATION INSTITUTE - SOLE PROPRIETORSHIP LLC
Reel/Frame 060239/0079 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2021
From: MARE, SEPTIMIU F.; AARAJ, NAJWA; MANZANO, MARCOS; GARCIA, ALVARO
To: TECHNOLOGY INNOVATION INSTITUTE
Reel/Frame 055536/0704 →
Cited By (2)
US 12,430,631 US 12,591,698