IP Library Granted Patent US 12,598,060
Granted Patent B2
US 12,598,060 · App. 17/472,644 · Granted Apr 7, 2026

Distributed encryption key allocation

Inventors: John Kennedy (Los Olivos, CA); Prasanna Kumar Malaiyandi (Santa Clara, CA); Karthik Raman (New York, NY); Jan Zila (Seattle, WA)
Assignee: Zoom Communications, Inc.
H04L9/0827H04L9/083H04L9/0833H04L9/0894H04L63/062H04L63/065
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,060
App. No.
17/472,644
Granted
Apr 7, 2026
Kind
B2
Abstract

Customers of a software platform, such as a unified communications as a service platform, are enabled to control their own encryption keys used to encrypt and decrypt data from various communication services in the software platform. A key broker server is employed to map encryption and decryption requests from servers in the platform to key management servers of customers based on user identifiers. Examples of data encrypted may includes conference recordings, webinar recordings, phone call recordings, voicemails, emails, and calendar tokens.

Claims (71)

1 . A method comprising:

receiving an encryption request from a first server that includes an identifier for one or more users, wherein the identifier includes at least one of a customer identification number, a host email address, or a telephone number;

selecting a key management server based on the identifier;

transmitting a request for a data encryption key to the selected key management server;

receiving a plaintext key and an encrypted key from the key management server;

in response to the encryption request, transmitting the plaintext key and the encrypted key to the first server; and

deleting the plaintext key.

2 . The method of claim 1 , comprising:

encrypting a recording of a conference conducted by the first server using the plaintext key to obtain an encrypted recording; and

storing the encrypted recording with the encrypted key in non-volatile memory.

3 . The method of claim 1 , comprising:

encrypting a recording of a phone call conducted by the first server using the plaintext key to obtain an encrypted recording; and

storing the encrypted recording with the encrypted key in non-volatile memory.

4 . The method of claim 1 , comprising:

encrypting a voicemail received by the first server using the plaintext key to obtain an encrypted recording; and

storing the encrypted recording with the encrypted key in non-volatile memory.

5 . The method of claim 1 , comprising:

encrypting a calendar token generated by the first server using the plaintext key to obtain an encrypted token; and

storing the encrypted token with the encrypted key in non-volatile memory.

6 . The method of claim 1 , comprising:

encrypting a recording of a webinar conducted by the first server using the plaintext key to obtain an encrypted recording; and

storing the encrypted recording with the encrypted key in non-volatile memory.

7 . The method of claim 1 , comprising:

configuring the key management server to generate data keys; and

associating the key management server with a group of one or more users.

8 . The method of claim 1 , comprising:

receiving an encryption algorithm identifier from the key management server; and

selecting an encryption algorithm to be applied with the plaintext key based on the encryption algorithm identifier.

9 . The method of claim 1 , comprising:

receiving a destination address from the key management server; and

storing the encrypted key and data encrypted with the plaintext key in non-volatile memory at the destination address.

10 . The method of claim 1 , wherein the first server is a media server configured to host conference software.

11 . The method of claim 1 , wherein the first server is part of a UCaaS system configured to support multiple modes of communication via one or more electronic communications networks.

12 . The method of claim 1 , wherein selecting the key management server comprises:

selecting the key management server based on an indication, included in the encryption request, of a type of data to be encrypted.

13 . The method of claim 1 , wherein selecting the key management server comprises:

selecting the key management server based on an indication, included in the encryption request, of a geographic region associated with data to be encrypted.

14 . The method of claim 13 , wherein the indication of the geographic region is an internet protocol address.

15 . The method of claim 1 , wherein the key management server is a first key management server, the plaintext key is a first plaintext key, and the encrypted key is a first encrypted key, comprising:

selecting a second key management server based on the identifier;

transmitting a request for a data encryption key to the second key management server;

receiving a second plaintext key and a second encrypted key from the second key management server;

in response to the encryption request, transmitting the second plaintext key and the second encrypted key to the first server;

encrypting data accessed by the first server using the first plaintext key and using the second plaintext key to obtain an encrypted data; and

storing the encrypted data with the first encrypted key and the second encrypted key in non-volatile memory; and

deleting the second plaintext key.

16 . A system comprising:

a network interface,

a processor, and

a memory, wherein the memory stores instructions executable by the processor to:

receive an encryption request from a first server that includes an identifier for one or more users, wherein the identifier includes at least one of a customer identification number, a host email address, or a telephone number;

select a key management server based on the identifier;

transmit, using the network interface, a request for a data encryption key to the selected key management server;

receive, using the network interface, a plaintext key and an encrypted key from the key management server;

in response to the encryption request, transmit the plaintext key and the encrypted key to the first server; and

delete the plaintext key.

17 . The system of claim 16 , wherein the first server is configured to:

encrypt a recording of a conference conducted by the first server using the plaintext key to obtain an encrypted recording; and

store the encrypted recording with the encrypted key in non-volatile memory.

18 . The system of claim 16 , wherein the memory stores instructions executable by the processor to:

receive, using the network interface, a destination address from the key management server; and

store the encrypted key and data encrypted with the plaintext key in non-volatile memory at the destination address.

19 . A method comprising:

receiving a decryption request from a first server that includes an identifier for one or more users and an encrypted key, wherein the identifier includes at least one of a customer identification number, a host email address, or a telephone number;

selecting a key management server based on the identifier;

transmitting a request for a data encryption key to the selected key management server, wherein the request includes the encrypted key;

receiving a plaintext key from the key management server;

in response to the decryption request, transmitting the plaintext key to the first server; and

deleting the plaintext key.

20 . The method of claim 19 , comprising:

decrypting an encrypted recording of a conference conducted by the first server using the plaintext key to obtain a decrypted recording.

Assignments (2)
CHANGE OF NAME Recorded Jan 7, 2025
From: ZOOM VIDEO COMMUNICATIONS, INC.
To: ZOOM COMMUNICATIONS, INC.
Reel/Frame 069839/0593 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2021
From: KENNEDY, JOHN; MALAIYANDI, PRASANNA KUMAR; RAMAN, KARTHIK; ZILA, JAN
To: ZOOM VIDEO COMMUNICATIONS, INC.
Reel/Frame 057510/0496 →
Continuity (1)
Related Publication 20230078187A1 · Mar 16, 2023
References Cited (31)
US 11799633B1 · Cartagena et al. · 2023 [cited by applicant]
US 12143475B2 · Cartagena et al. · 2024 [cited by applicant]
US 12238078B2 · Kaciulis · 2025 [cited by applicant]
US 20080297586A1 · Kurtz · 2008 [cited by examiner]
US 20100128875A1 · Rosini · 2010 [cited by examiner]
US 20120008753A1 · Burnett · 2012 [cited by examiner]
US 20140129831A1 · Odinak · 2014 [cited by examiner]
US 20140229737A1 · Roth · 2014 [cited by examiner]
US 20140229739A1 · Roth et al. · 2014 [cited by applicant]
US 20180048464A1 · Lim · 2018 [cited by examiner]
US 20180109508A1 · Wall et al. · 2018 [cited by applicant]
US 20180268159A1 · Yu · 2018 [cited by applicant]
US 20180309734A1 · Yu et al. · 2018 [cited by applicant]
US 20190342079A1 · Rudzitis et al. · 2019 [cited by applicant]
US 20200053065A1 · Wisniewski et al. · 2020 [cited by applicant]
US 20200258050A1 · Wang · 2020 [cited by examiner]
US 20210377016A1 · Perlman et al. · 2021 [cited by applicant]
US 20210385070A1 · Watson et al. · 2021 [cited by applicant]
US 20220179972A1 · Sah · 2022 [cited by examiner]
US 20220239655A1 · Viswanathan Iyer · 2022 [cited by examiner]
US 20220391494A1 · Yang et al. · 2022 [cited by applicant]
CN 110061957A · 2019 [cited by applicant]
WO 2019227557A1 · 2019 [cited by applicant]
Your guide to Enterprise Key Management at Slack, https://slack.com, Sep. 1, 2021, 4 pages. [cited by applicant]
Use envelope encryption with customer master keys—Financial Services Industry Lens, https://docs.aws.amazon.com/wellarchitected/latest/financial-services-industry-lens/use-envelope-encrytpion-with-customer-master-keys.h… [cited by applicant]
Google will let enterprises store their Google Workspace encryption keys, TechCrunch, https://techcrunch.com/2021/06/14/google-workspace-encryption-keys/., Zach Whittaker, Jun. 14, 2021, 9 pages. [cited by applicant]
Deployment Guide for Cisco Webex Hybrid Data Security—Getting Started with Hybrid Data Security, Cisco Webex Teams, Cisco, https://www.cisco.com., Jun. 24, 2021, 8 pages. [cited by applicant]
Key Management Service, Amazon Web Services (AWS), https://aws.amazon.com/kms/., Aug. 31, 2021, 7 pages. [cited by applicant]
International Search Report and Written Opinion mailed on Dec. 12, 2022 in corresponding PCT Application No. PCT/US2022/043060. [cited by applicant]
Anonymous: “AWS Key Management Service—Developer Guide”, Nov. 25, 2019 (Nov. 25, 2019), XP055693941, Retrieved from the Internet: URL: https://docs.aws.amazon.com/kms/latest/developerguide/kms-dg.pdf#programming-aliases… [cited by applicant]
Ryan Kurte; A Distributed Service Framework for the Internet of Things; IEEE: 2020; pp. 4166-4176. [cited by applicant]