IP Library Granted Patent US 12,452,041
Granted Patent B2
US 12,452,041 · App. 18/156,100 · Granted Oct 21, 2025

Distributed encryption management

Inventors: John Carl Kennedy (Los Olivos, CA); Prasanna Kumar Malaiyandi (Santa Clara, CA); Martin Josef Pagel (Seattle, WA); Karthik Raman (New York, NY); Jan Zila (Seattle, WA)
Assignee: Zoom Communications, Inc.
H04L9/0833H04L9/0618H04L9/0891H04L63/0876H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,041
App. No.
18/156,100
Granted
Oct 21, 2025
Kind
B2
Abstract

Customers of a software platform, such as a unified communications as a service platform, are enabled to control their own encryption keys used to encrypt and decrypt data from various communication services in the software platform. A key broker server is employed to map encryption and decryption requests from servers in the platform to key management servers of customers based on user identifiers. Examples of data encrypted may include conference recordings, webinar recordings, phone call recordings, voicemails, emails, and calendar tokens.

Claims (86)

1. A method comprising:

receiving an encryption request from a first server that includes a data type indication and an identifier for one or more users;

selecting a security management policy from a set of security management policies stored in a data structure based on the identifier and based on the data type indication;

selecting a key management server based on the selected security management policy;

transmitting a request for a data encryption key to the selected key management server;

receiving a plaintext key and an encrypted key from the selected key management server;

in response to the encryption request, transmitting the plaintext key to the first server;

determining a context identifier based on the encryption request;

storing the encrypted key in a record associated with the context identifier;

recevieving a decryption request including the context identifier;

accessing the encrypted key in the record associated with the context identifier;

determining the plaintext key based on the encrypted key; and

transmitting the plaintext key in response to the decryption request.

2. The method of claim 1 , wherein the encryption request includes a role indication for a user associated with the identifier, and the security management policy is selected based on the role indication.

3. The method of claim 1 , wherein the encryption request includes a data label, and the security management policy is selected based on the data label.

4. The method of claim 1 , wherein the selected key management server is a cloud server.

5. The method of claim 1 , wherein the selected key management server is a hardware security module.

6. The method of claim 1 , wherein the selected key management server is in a customer cloud.

7. The method of claim 1 , comprising:

selecting a database server based on the selected security management policy; and

storing encrypted data, which has been encrypted using the plaintext key, in the selected database server.

8. The method of claim 7 , wherein the selected security management policy includes a pointer and credentials that are used to select the database server and store the encrypted data in the selected database server.

9. The method of claim 1 , wherein the record associated with the context identifier includes data identifying the selected key management server.

10. The method of claim 1 , wherein determining the plaintext key based on the encrypted key comprises:

transmitting the encrypted key to the selected key management server; and

receiving the plaintext key from the selected key management server.

11. The method of claim 1 , comprising:

receiving a re-keying request;

determining a set of one or more context identifiers based on the re-keying request, wherein the set of one or more context identifiers includes the context identifier;

identifying a next key management server based on the re-keying request;

responsive to the re-keying request, determining the plaintext key based on the encrypted key using the selected key management server;

determining a new encrypted key based on the plaintext key using the next key management server;

storing the new encrypted key in a record associated with the context identifier; and

deleting the encrypted key and the plaintext key.

12. A system comprising:

a network interface,

a processor, and

a memory, wherein the memory stores instructions executable by the processor to:

receive an encryption request from a first server that includes a data type indication and an identifier for one or more users;

select a security management policy from a set of security management policies stored in a data structure based on the identifier and based on the data type indication;

select a key management server based on the selected security management policy;

transmit, using the network interface, a request for a data encryption key to the selected key management server;

receive, using the network interface, a plaintext key and an encrypted key from the selected key management server;

in response to the encryption request, transmit the plaintext key to the first server;

determine a context identifier based on the encryption request;

store the encrypted key in a record associated with the context identifier;

receive a decryption request including the context identifier;

access the encrypted key in the record associated with the context identifier;

determine the plaintext key based on the encrypted key; and

transmit the plaintext key in response to the decryption request.

13. The system of claim 12 , wherein the memory stores instructions executable by the processor to:

select a database server based on the selected security management policy; and

store encrypted data, which has been encrypted using the plaintext key, in the selected database server.

14. The system of claim 12 , wherein the memory stores instructions executable by the processor to:

receive a re-keying request;

determine a set of one or more context identifiers based on the re-keying request, wherein the set of one or more context identifiers includes the context identifier;

identify a next key management server based on the re-keying request;

responsive to the re-keying request, determine the plaintext key based on the encrypted key using the selected key management server;

determine a new encrypted key based on the plaintext key using the next key management server;

store the new encrypted key in a record associated with the context identifier; and

delete the encrypted key and the plaintext key;

obtain an encrypted recording; and

store the encrypted recording with the encrypted key in non-volatile memory.

15. A method comprising:

receiving an encryption request from a first server that includes a data type indication and an identifier for one or more users;

selecting a security management policy from a set of security management policies stored in a data structure based on the identifier and based on the data type indication;

selecting a key management server based on the selected security management policy;

transmitting a request for a data encryption key to the selected key management server;

receiving a plaintext key and an encrypted key from the selected key management server;

in response to the encryption request, transmitting the plaintext key to the first server;

determining a context identifier based on the encryption request;

storing the encrypted key in a record associated with the context identifier;

receiving a re-keying request;

determining a set of one or more context identifiers based on the re-keying request, wherein the set of one or more context identifiers includes the context identifier;

identifying a next key management server based on the re-keying request;

responsive to the re-keying request, determining the plaintext key based on the encrypted key using the selected key management server;

determining a new encrypted key based on the plaintext key using the next key management server;

storing the new encrypted key in a record associated with the context identifier; and

deleting the encrypted key and the plaintext key.

16. The method of claim 15 , wherein the record associated with the context identifier includes data identifying the selected key management server.

17. The method of claim 15 , wherein the encryption request includes a role indication for a user associated with the identifier, and the security management policy is selected based on the role indication.

18. The method of claim 15 , wherein the encryption request includes a data label, and the security management policy is selected based on the data label.

19. The method of claim 15 , wherein the selected key management server is a cloud server.

20. The method of claim 15 , comprising:

selecting a database server based on the selected security management policy; and

storing encrypted data, which has been encrypted using the plaintext key, in the selected database server.

Assignments (2)
CHANGE OF NAME Recorded Jan 7, 2025
From: ZOOM VIDEO COMMUNICATIONS, INC.
To: ZOOM COMMUNICATIONS, INC.
Reel/Frame 069839/0593 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2023
From: KENNEDY, JOHN CARL; MALAIYANDI, PRASANNA KUMAR; PAGEL, MARTIN JOSEF; RAMAN, KARTHIK; ZILA, JAN
To: ZOOM VIDEO COMMUNICATIONS, INC.
Reel/Frame 062411/0809 →
Continuity (2)
Provisional Application 63418473 · Oct 21, 2022
Related Publication 20240137388A1 · Apr 25, 2024
References Cited (30)
US 11799633B1 · Cartagena · 2023 [cited by examiner]
US 12143475B2 · Cartagena · 2024 [cited by examiner]
US 12238078B2 · Kaciulis · 2025 [cited by applicant]
US 20080297586A1 · Kurtz et al. · 2008 [cited by applicant]
US 20100128875A1 · Rosini et al. · 2010 [cited by applicant]
US 20120008753A1 · Burnett et al. · 2012 [cited by applicant]
US 20140129831A1 · Odinak · 2014 [cited by applicant]
US 20140229737A1 · Roth et al. · 2014 [cited by applicant]
US 20140229739A1 · Roth et al. · 2014 [cited by applicant]
US 20180048464A1 · Lim et al. · 2018 [cited by applicant]
US 20180109508A1 · Wall · 2018 [cited by examiner]
US 20180268159A1 · Yu · 2018 [cited by examiner]
US 20180309734A1 · Yu · 2018 [cited by examiner]
US 20190342079A1 · Rudzitis · 2019 [cited by examiner]
US 20200053065A1 · Wisniewski · 2020 [cited by examiner]
US 20200258050A1 · Wang et al. · 2020 [cited by applicant]
US 20210385070A1 · Watson et al. · 2021 [cited by applicant]
US 20220179972A1 · Sah · 2022 [cited by applicant]
US 20220239655A1 · Viswanathan Iyer et al. · 2022 [cited by applicant]
US 20220391494A1 · Yang et al. · 2022 [cited by applicant]
CN 110061957A · 2019 [cited by applicant]
Your guide to Enterprise Key Management at Slack, https://slack.com, Sep. 1, 2021, 4 pages. [cited by applicant]
Use envelope encryption with customer master keys—Financial Services Industry Lens, https://docs.aws.amazon.com/wellarchitected/latest/financial-services-industry-lens/use-envelope-encrytpion-with-customer-master-keys.h… [cited by applicant]
Google will let enterprises store their Google Workspace encryption keys, TechCrunch, https://techcrunch.com/2021/06/14/google-workspace-encryption-keys/., Zach Whittaker, Jun. 14, 2021, 9 pages. [cited by applicant]
Deployment Guide for Cisco Webex Hybrid Data Security—Getting Started with Hybrid Data Security, Cisco Webex Teams, Cisco, https://www.cisco.com., Jun. 24, 2021, 8 pages. [cited by applicant]
Key Management Service, Amazon Web Services (AWS), https://aws.amazon.com/kms/., Aug. 31, 2021, 7 pages. [cited by applicant]
International Search Report and Written Opinion mailed on Dec. 12, 2022 in corresponding PCT Application No. PCT/US2022/043060. [cited by applicant]
Anonymous: “AWS Key Management Service—Developer Guide”, Nov. 25, 2019 (Nov. 25, 2019), XP055693941, Retrieved from the Internet: URL: https://docs.aws.amazon.com/kms/latest/developerguide/kms-dg.pdf#programming-aliases… [cited by applicant]
Zoom Customer Managed Key, Bring your own encryption keys to protect certain data stored at rest within the Zoom Cloud infrastructure, https://explore.zoom.us/en/products/cmk/, Oct. 18, 2022, 9 pages. [cited by applicant]
Ryan Kurte; A Distributed Service Framework for the Internet of Things; IEEE: 2020; pp. 4166-4176. [cited by applicant]