IP Library › Granted Patent US 12,200,105
Granted Patent B1
US 12,200,105 · App. 17/855,563 · Granted Jan 14, 2025

Asymmetric computer-implemented storage cryptography

Inventors: Panagiotis Kampanakis (Apex, NC); Jake Massimo (London, GB); Brian Igleheart (Seattle, WA)
Assignee: Amazon Technologies, Inc.
H04L9/0631H04L9/085H04L9/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,200,105
App. No.
17/855,563
Granted
Jan 14, 2025
Kind
B1
Abstract

Techniques and systems can obtain a first private key usable with a classical cryptography algorithm and a second private key usable with a post-quantum cryptography algorithm based on classical and post-quantum public keys hosted by a computer-implemented storage of an online service provider. A plurality of keys to perform a cryptography operation on data hosted by the computer-implemented storage can be generated, the plurality of keys generated based on at least the first and second private keys and a cryptography derivation function identified in the computer-implemented storage. The plurality of keys can be used to perform the cryptography operation on the data hosted by the computer-implemented storage.

Claims (58)

1. A computer-implemented method, comprising:

utilizing, in a computer-implemented storage including data, metadata to identify cryptography information including at least:

a plurality of public encryption keys comprising at least a first public key usable with a classical cryptography algorithm, an ephemeral public key usable with the classical cryptography algorithm, and a second public key usable with a post-quantum cryptography algorithm,

ciphertext encapsulating at least a post-quantum shared secret, and

an identifier of a key derivation function (KDF) and an information parameter;

based at least on a portion of the cryptography information, obtaining from a computer-implemented service a first private key usable with the classical cryptography algorithm and a second private key usable with the post-quantum cryptography algorithm;

deriving, based at least on the first and second private keys and the ephemeral public key and the ciphertext, a shared secret comprising a classical shared secret and the post-quantum shared secret;

generating a plurality of keys, usable with an XEX Tweakable Block Ciphertext Stealing (XTS)-Advanced Encryption Standard (AES) encryption algorithm, based on the KDF that at least is to process the shared secret and the information parameter as inputs; and

performing a cryptography operation on the data using the plurality of keys usable with the XTS-AES encryption algorithm.

2. The computer-implemented method according to claim 1 , further comprising executing an encapsulation algorithm to generate the ciphertext encapsulating at least the post-quantum shared secret, wherein the encapsulation algorithm is executed using the second public key.

3. The computer-implemented method according to claim 1 , wherein deriving the post-quantum shared secret comprises executing a decapsulation algorithm on the ciphertext to determine the post-quantum shared secret, wherein the decapsulation algorithm is executed using the second private key.

4. The computer-implemented method according to claim 1 , further comprising:

in advance of deriving the shared secret, storing the first and second private keys in a volatile memory accessible by the computer-implemented storage including the data; and

subsequent to generating the plurality of keys, removing the first and second private keys from the volatile memory negating access to the first and second private keys by the computer-implemented storage including the data.

5. A system, comprising:

one or more processors; and

memory that stores computer-executable instructions that, if executed, cause the one or more processors to:

utilize metadata to identify cryptography information including at least:

a plurality of public encryption keys comprising at least a first public key usable with a classical cryptography algorithm, an ephemeral public key usable with the classical cryptography algorithm, and a second public key usable with a post-quantum cryptography algorithm,

ciphertext encapsulating at least a post-quantum shared secret, and

an identifier of a key derivation function (KDF) and an information parameter;

based at least on a portion of the cryptography information, obtain a first private key usable with the classical cryptography algorithm and a second private key usable with the post-quantum cryptography algorithm;

derive, based at least on the first and second private keys and the ephemeral public key and the ciphertext, a shared secret comprising a classical shared secret and the post-quantum shared secret;

generate a plurality of keys, usable with an XEX Tweakable Block Ciphertext Stealing (XTS)-Advanced Encryption Standard (AES) encryption algorithm, based on the KDF that at least is to process the shared secret and the information parameter as inputs; and

perform a cryptography operation on data using the plurality of keys usable with the XTS-AES encryption algorithm.

6. The system of claim 5 , wherein the memory that stores the computer-executable instructions that are executable by the one or more processors are further to cause the system to:

communicate identifying information associated with the ephemeral public key and the second public key to a cryptography service; and

in response to communicating the identifying information associated with the ephemeral public key and the second public key to the cryptography service, obtain the first private key and the second private key from the cryptography service.

7. The system of claim 5 , wherein the memory that stores the computer-executable instructions that are executable by the one or more processors are further to cause the system to locate one or more of the cryptography algorithms using one or more identifiers comprised in the cryptography information, the cryptography algorithm implemented by the computer implemented storage comprising the data.

8. The system of claim 5 , wherein the classical shared secret is concatenated with the post-quantum shared secret.

9. The system of claim 5 , wherein the ciphertext is generated based on a post-quantum encapsulation function.

10. The system of claim 5 , wherein deriving the post-quantum shared secret comprises executing a decapsulation algorithm on the ciphertext to determine the post-quantum shared secret, wherein the decapsulation algorithm is executed using the second private key.

11. The system of claim 5 , wherein the memory that stores the computer-executable instructions that are executable by the one or more processors are further to cause the system to:

obtain ciphertext from the metadata; and

decapsulate the ciphertext using a post-quantum decapsulation function.

12. The system of claim 5 , wherein the memory that stores the computer-executable instructions that are executable by the one or more processors are further to cause the system to:

in advance of deriving the shared secret, store the first and second private keys in a volatile memory accessible; and

subsequent to generating the plurality of keys, remove the first and second private keys from the volatile memory.

13. A non-transitory computer-readable storage medium storing thereon executable instructions that, as a result of being executed by one or more processors of a computer system, cause the computer system to at least:

utilize metadata to identify cryptography information including at least:

a plurality of public encryption keys comprising at least a first public key usable with a classical cryptography algorithm, an ephemeral public key usable with the classical cryptography algorithm, and a second public key usable with a post-quantum cryptography algorithm,

ciphertext encapsulating at least a post-quantum shared secret, and

an identifier of a key derivation function (KDF) and an information parameter;

based at least on a portion of the cryptography information, obtain a first private key usable with the classical cryptography algorithm and a second private key usable with the post-quantum cryptography algorithm;

derive, based at least on the first and second private keys and the ephemeral public key and the ciphertext, a shared secret comprising a classical shared secret and the post-quantum shared secret;

generate a plurality of keys, usable with an XEX Tweakable Block Ciphertext Stealing (XTS)-Advanced Encryption Standard (AES) encryption algorithm, based on the KDF that at least is to process the shared secret and the information parameter as inputs; and

perform a cryptography operation on data using the plurality of keys usable with the XTS-AES encryption algorithm.

14. The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to:

communicate identifying information associated with the ephemeral public key and the second public key to a cryptography service; and

in response to communicating the identifying information associated with the ephemeral public key and the second public key to the cryptography service, obtain the first private key and the second private key from the cryptography service.

15. The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to locate one or more of the cryptography algorithms using identifiers comprised in the cryptography information.

16. The non-transitory computer-readable storage medium of claim 13 , wherein deriving the post-quantum shared secret comprises executing a decapsulation algorithm on the ciphertext to determine the post-quantum shared secret, wherein the decapsulation algorithm is executed using the second private key.

17. The non-transitory computer-readable storage medium of claim 16 , wherein the instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to execute an encapsulation algorithm to generate the ciphertext encapsulating at least the post-quantum shared secret, wherein the encapsulation algorithm is executed using the second public.

18. The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to locate one or more of the cryptography algorithms using one or more identifiers comprised in the cryptography information.

19. The non-transitory computer-readable storage medium of claim 13 , wherein each of the plurality of keys is usable with the XTS-AES encryption algorithm to perform the cryptography operation on data hosted by a computer-implemented storage.

20. The non-transitory computer-readable storage medium of claim 13 , wherein the instructions further comprise instructions that, as a result of being executed by the one or more processors, cause the computer system to:

store the first and second private keys in a volatile memory accessible; and

remove the first and second private keys from the volatile memory to negate access to the plurality of keys.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2023
From: MASSIMO, JAKE
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 062361/0152 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2022
From: KAMPANAKIS, PANAGIOTIS; IGLEHEART, BRIAN
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 060377/0044 →
References Cited (4)
US 20160283723A1 · Roth · 2016 [cited by examiner]
US 20190342079A1 · Rudzitis · 2019 [cited by examiner]
US 20230299953A1 · Doi · 2023 [cited by examiner]
US 20230318826A1 · Anand · 2023 [cited by examiner]
Cited By (1)
US 12,579,324