IP Library Granted Patent US 11,886,301
Granted Patent B2
US 11,886,301 · App. 17/200,310 · Granted Jan 30, 2024

Encryption key management

Inventors: Deepika Dixit (Santa Clara, CA); Julio Lopez (Mountain View, CA); Thomas Manville (Mountain View, CA); Vaibhav Kamra (Sunnyvale, CA)
Assignee: KASTEN, INC.
G06F11/1464G06F11/1461G06F11/1469H04L9/0863H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,886,301
App. No.
17/200,310
Granted
Jan 30, 2024
Kind
B2
Abstract

Disclosed herein are system, method, and computer program product embodiments for encryption key management. An embodiment operates by executing an initial non-backup instance of an application and generates a primary key using a cryptographic algorithm. The embodiment requests a customer to create a passphrase configured to encrypt and decrypt the primary key. The embodiment generates a derived key using a cryptographic algorithm and the customer passphrase as input. The embodiment then encrypts the primary key using the generated derived key and stores the encrypted primary key in a catalog.

Claims (65)

1. A computer-implemented method, comprising:

executing an initial non-backup instance of an application;

generating a primary key using a cryptographic algorithm;

receiving a passphrase configured to encrypt and decrypt the primary key;

generating a derived key from the passphrase using the cryptographic algorithm;

encrypting the primary key using the derived key, thereby producing an encrypted primary key;

storing the encrypted primary key in a catalog;

executing a first instance of the application for backup;

decrypting the encrypted primary key in the catalog, thereby retrieving the primary key;

determining that the primary key is to be used for a first purpose of a backup repository end point for the first instance of the application; and

generating a derived key for the first instance of the application based on the primary key and the first purpose, wherein the derived key for the first instance of the application is distinct from a derived key for a second instance of the application, wherein the derived key for the second instance of the application is to be used for a second purpose of a policy for an operation for the second instance of the application.

2. The method of claim 1 , further comprising:

adding or removing passphrases.

3. The method of claim 1 , wherein the decrypting the encrypted primary key comprises:

requesting a user to provide a user passphrase corresponding to the passphrase;

retrieving the user passphrase; and

decrypting the encrypted primary key using the user passphrase, wherein the retrieved user passphrase is identical to the passphrase configured to encrypt and decrypt the primary key.

4. The method of claim 1 , wherein the generating the derived key for the first instance of the application comprises:

generating the derived key for the first instance of the application using the cryptographic algorithm, wherein the cryptographic algorithm is a ChaCha20Poly1305 algorithm.

5. The method of claim 1 , wherein the generating the primary key comprises:

generating the primary key using the cryptographic algorithm, wherein the cryptographic algorithm is a ChaCha20Poly1305 algorithm.

6. A system, comprising:

a memory; and

at least one processor coupled to the memory and configured to:

execute an initial non-backup instance of an application;

generate a primary key using a cryptographic algorithm;

receive a passphrase configured to encrypt and decrypt the primary key;

generate a derived key from the passphrase using the cryptographic algorithm;

encrypt the primary key using the derived key, thereby producing an encrypted primary key;

store the encrypted primary key in a catalog;

execute a first instance of the application for backup;

decrypt the encrypted primary key in the catalog, thereby retrieving the primary key;

determine that the primary key is to be used for a first purpose of a backup repository end point for the first instance of the application; and

generate a derived key for the first instance of the application based on the primary key and the first purpose, wherein the derived key for the first instance of the application is distinct from a derived key for a second instance of the application, wherein the derived key for the second instance of the application is to be used for a second purpose of a policy for an operation for the second instance of the application.

7. The system of claim 6 , wherein the at least one processor is further configured to:

add or remove passphrases.

8. The system of claim 6 , wherein to decrypt the encrypted primary key, the at least one processor is further configured to:

request a user to provide a user passphrase corresponding to the passphrase;

retrieve the user passphrase; and

decrypt the encrypted primary key using the user passphrase, wherein the retrieved user passphrase is identical to the passphrase configured to encrypt and decrypt the primary key.

9. The system of claim 6 , wherein to generate the derived key for the first instance of the application, the at least one processor further configured to:

generate the derived key for the first instance of the application using the cryptographic algorithm, wherein the cryptographic algorithm is a ChaCha20Poly1305 algorithm.

10. The system of claim 6 , wherein to generate the primary key, the at least one processor is further configured to:

generate the primary key using the cryptographic algorithm, wherein the cryptographic algorithm is a ChaCha20Poly1305 algorithm.

11. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations comprising:

executing an initial non-backup instance of an application;

generating a primary key using a cryptographic algorithm;

receiving a passphrase configured to encrypt and decrypt the primary key;

generating a derived key from the passphrase using the cryptographic algorithm;

encrypting the primary key using the generated derived key, thereby producing an encrypted primary key;

storing the encrypted primary key in a catalog;

executing a first instance of the application for backup;

decrypting the encrypted primary key in the catalog, thereby retrieving the primary key;

determining that the primary key is to be used for a first purpose of a backup repository end point for the first instance of the application; and

generating a derived key for the first instance of the application based on the primary key and the first purpose, wherein the derived key for the first instance of the application is distinct from a derived key for a second instance of the application, wherein the derived key for the second instance of the application is to be used for a second purpose of a policy for an operation for the second instance of the application.

12. The non-transitory computer-readable medium of claim 11 , the operations further comprising:

adding or removing passphrases.

13. The non-transitory computer-readable medium of claim 11 , wherein the decrypting the encrypted primary key comprises:

requesting a user to provide a user passphrase corresponding to the passphrase;

retrieving the user passphrase; and

decrypting the encrypted primary key using the user passphrase, wherein the retrieved user passphrase is identical to the passphrase configured to encrypt and decrypt the primary key.

14. The non-transitory computer-readable medium of claim 11 , wherein the generating the derived key for the first instance of the application comprises:

generating the derived key for the first instance of the application using the cryptographic algorithm, wherein the cryptographic algorithm is a ChaCha20Poly1305 algorithm.

15. The non-transitory computer-readable medium of claim 11 , wherein the generating the primary key comprises:

generating the primary key using the cryptographic algorithm, wherein the cryptographic algorithm is a ChaCha20Poly1305 algorithm.

Assignments (2)
SECURITY INTEREST Recorded May 22, 2026
From: KASTEN, INC.; SECURITI, LLC; VEEAM SOFTWARE GROUP GMBH; VEEAM VAAS CORPORATION
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 074738/0015 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2021
From: DIXIT, DEEPIKA; LOPEZ, JULIO; MANVILLE, THOMAS; KAMRA, VAIBHAV
To: KASTEN, INC.
Reel/Frame 056744/0026 →
Continuity (1)
Related Publication 20220291999A1 · Sep 15, 2022