IP Library › Granted Patent US 12,316,748
Granted Patent B2
US 12,316,748 · App. 17/536,943 · Granted May 27, 2025

Enforcing multi-ownership of data on storage

Inventors: Dwarkanath P. Rao (Dublin, IE); Utz Bacher (Dettenhausen, DE)
Assignee: Kyndryl, Inc.
H04L9/0825H04L9/0877H04L9/14H04L9/3228
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,316,748
App. No.
17/536,943
Granted
May 27, 2025
Kind
B2
Abstract

A computer-implemented method for providing a secure data access service that encrypts data is disclosed. The method includes: wrapping a data encryption key by at least two customer root keys, wherein the at least two customer root keys are assigned to different user identifiers, and wherein the at least two customer root keys are stored in different hardware security modules, and wherein a wrapping structure for the at least two customer root keys is applied according to an access policy that defines which of the assigned user identifiers must concur to enable a data access to the encrypted data by the secure data access service; and encrypting the data by the secure data access service using the unwrapped data encryption key.

Claims (25)

1. A computer-implemented method for providing a secure data access service that encrypts data, said computer-implemented method comprising:

wrapping a data encryption key, which is only valid for a limited time window, by at least two customer root keys to obtain a wrapped data encryption key, wherein said at least two customer root keys are assigned to different user identifiers, said at least two customer root keys are stored in different hardware security modules which are linked to individual user identifiers of respective operators, and wherein wrapping the data encryption key further comprises a wrapping structure codified within the secure data access service for said at least two customer root keys is applied in an ascending or descending order of the at least two customer root keys according to an access policy that defines which of said assigned user identifiers must concur to enable a data access to said encrypted data by said secure data access service, wherein the data encryption key is passed from the secure data access service to another data access function for a final data access;

and encrypting data by said secure data access service using an unwrapped data encryption key, wherein prior to encrypting the data using the unwrapped data encryption key, the secure data access service requests an unwrapped operation on the wrapped data encryption key and wherein the unwrapped operation on the wrapped data encryption key is performed using the at least two customer root keys in ascending or descending order of the at least two customer root keys according to the access policy.

2. The computer-implemented method according to claim 1 , wherein said wrapping structure defines a sequence of application of said at least two customer root keys for said wrapping of said data encryption key.

3. The computer-implemented method according to claim 1 , wherein said secure data access service stores only said wrapped data encryption key.

4. The computer-implemented method according to claim 1 , wherein said different hardware security modules are virtual different hardware security modules.

5. The computer-implemented method according to claim 1 , wherein said at least two customer root keys are n customer root keys out of m customer root keys, wherein m>n.

6. The computer-implemented method according to claim 1 , wherein said at least two customer root keys are symmetric encryption/decryption keys.

7. The computer-implemented method according to claim 1 , wherein said at least two customer root keys have to be different.

8. The computer-implemented method according to claim 1 , wherein said data encryption key is a symmetrical or asymmetric key.

9. The computer-implemented method according to claim 1 , wherein said wrapping structure defines a sequence of application of said at least two customer root keys for an unwrapping of said data encryption key.

10. A data protection system for providing a secure data access service that encrypts data, said data protection system comprising:

a processor and a memory, communicatively coupled to said processor, wherein said memory stores program code portions that, when executed, enable said processor, to:

wrap a data encryption key, which is only valid for a limited time window, by at least two customer root keys to obtain a wrapped data encryption key, wherein said at least two customer root keys are assigned to different user identifiers, said at least two customer root keys are stored in different hardware security modules which are linked to individual user identifiers of respective operators, and wherein wrapping the data encryption key further comprises a wrapping structure codified within the secure data access service for said at least two customer root keys is applied in an ascending or descending order of the at least two customer root keys according to an access policy that defines which of said assigned user identifiers must concur to enable a data access to said encrypted data by said secure data access service, wherein the data encryption key is passed from the secure data access service to another data access function for a final data access;

and encrypt data by said secure data access service using an unwrapped data encryption key, wherein prior to encrypting the data using the unwrapped data encryption key, the secure data access service requests an unwrapped operation on the wrapped data encryption key and wherein the unwrapped operation on the wrapped data encryption key is performed using the at least two customer root keys in ascending or descending order of the at least two customer root keys according to the access policy.

11. The data protection system according to claim 10 , wherein said wrapping structure defines a sequence of application of said at least two customer root keys for said wrapping of said data encryption key.

12. The data protection system according to claim 10 , wherein said secure data access service stores only said wrapped data encryption key.

13. The data protection system according to claim 10 , wherein said different hardware security modules are physical different hardware security modules, virtual different hardware security modules or a mixture thereof.

14. The data protection system according to claim 10 , wherein said at least two customer root keys are n customer root keys out of m customer root keys, wherein m>n.

15. The data protection system according to claim 10 , wherein said at least two customer root keys are symmetric encryption/decryption keys.

16. The data protection system according to claim 10 , wherein said at least two customer root keys have to be different.

17. A computer program product for data protection system, said computer program product comprising:

a computer readable storage medium having program instructions embodied therewith, said program instructions being executable by one or more computing systems or controllers to cause said one or more computing systems to:

wrap a data encryption key, which is only valid for a limited time window, by at least two customer root keys to obtain a wrapped data encryption key, wherein said at least two customer root keys are assigned to different user identifiers which are linked to individual user identifiers of respective operators, said at least two customer root keys are stored in different hardware security modules, and wherein wrapping the data encryption key further comprises a wrapping structure codified within the secure data access service for said at least two customer root keys is applied in an ascending or descending order of the at least two customer root keys according to an access policy that defines which of said assigned user identifiers must concur to enable a data access to said encrypted data by said secure data access service, wherein the data encryption key is passed from the secure data access service to another data access function for a final data access;

and encrypt data by said secure data access service using an unwrapped data encryption key, wherein prior to encrypting the data using the unwrapped data encryption key, the secure data access service requests an unwrapped operation on the wrapped data encryption key and wherein the unwrapped operation on the wrapped data encryption key is performed using the at least two customer root keys in ascending or descending order of the at least two customer root keys according to the access policy.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2021
From: RAO, DWARKANATH P.; BACHER, UTZ
To: KYNDRYL, INC.
Reel/Frame 058231/0744 →
Continuity (1)
Related Publication 20230171089A1 · Jun 1, 2023
References Cited (23)
US 5970149A · Johnson · 1999 [cited by examiner]
US 10461943B1 · Norum · 2019 [cited by examiner]
US 11303432B2 · Levin · 2022 [cited by examiner]
US 20120246463A1 · Shea et al. · 2012 [cited by applicant]
US 20130166911A1 · Daouphars · 2013 [cited by examiner]
US 20160285625A1 · Roth et al. · 2016 [cited by applicant]
US 20170063531A1 · Sullivan · 2017 [cited by examiner]
US 20170085377A1 · Pogmore et al. · 2017 [cited by applicant]
US 20180060596A1 · Hamel · 2018 [cited by examiner]
US 20180176013A1 · Cheng et al. · 2018 [cited by applicant]
US 20190097791A1 · Hersans et al. · 2019 [cited by applicant]
US 20190173674A1 · Agarwal et al. · 2019 [cited by applicant]
US 20200053065A1 · Wisniewski et al. · 2020 [cited by applicant]
US 20200111080A1 · Metcalfe · 2020 [cited by examiner]
US 20200169395A1 · Hong et al. · 2020 [cited by applicant]
US 20200195621A1 · Li et al. · 2020 [cited by applicant]
US 20210014044A1 · Bursell · 2021 [cited by examiner]
US 20210194678A1 · Schindewolf · 2021 [cited by examiner]
International Search Report and Written Opinion completed on Feb. 10, 2023 in corresponding Application No. PCT/EP2022/079194; 13 pages. [cited by applicant]
Disclosed Anonymously, “System and Method to Use Hybrid Data Encryption Keys for Dataat-Rest Encryption in Cloud”, An IP.com Prior Art Database Technical Disclosure, IP.com Electronic Publication Date Feb. 1, 2021, IP.c… [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing”, NIST, Special Publication 800-145, Sep. 2011, 7 pages. [cited by applicant]
Unknown author, https://cloud.ibm.com/docs/key-protect, 4 pages. downloaded on Nov. 29, 2021. [cited by applicant]
Unknown author, https://cloud.ibm.com/docs/hs-crypto, 4 pages. downloaded on Nov. 29, 2021. [cited by applicant]