IP Library Patent Application 18156116
Patent Application
App. No. 18/156,116

Distributed Decryption Request Handling

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/156,116
Abstract

Customers of a software platform, such as a unified communications as a service platform, are enabled to control their own encryption keys used to encrypt and decrypt data from various communication services in the software platform. A key broker server is employed to map encryption and decryption requests from servers in the platform to key management servers of customers based on user identifiers. Examples of data encrypted may include conference recordings, webinar recordings, phone call recordings, voicemails, emails, and calendar tokens.

Claims (77)

1 . A system comprising:

a network interface,

a processor, and

a memory, wherein the memory stores instructions executable by the processor to:

receive a decryption request from a first server that includes a context identifier;

access an encrypted key stored in a record associated with the context identifier;

select a key management server based on the record associated with the context identifier;

transmit, using the network interface, a request for a data encryption key to the selected key management server, wherein the request includes the encrypted key;

receive, using the network interface, a plaintext key from the key management server; and

in response to the decryption request, transmit the plaintext key to the first server.

2 . The system of claim 1 , wherein the memory stores instructions executable by the processor to:

decrypting an encrypted recording of a conference conducted by the first server using the plaintext key to obtain a decrypted recording.

3 . The system of claim 1 , wherein the memory stores instructions executable by the processor to:

delete the plaintext key.

4 . The system of claim 1 , wherein the memory stores instructions executable by the processor to:

receive a re-keying request;

determine a set of one or more context identifiers based on the re-keying request, wherein the set of one or more context identifiers includes the context identifier;

identify a next key management server based on the re-keying request;

responsive to the re-keying request, determine the plaintext key based on the encrypted key using the selected key management server;

determine a new encrypted key based on the plaintext key using the next key management server;

store the new encrypted key in a record associated with the context identifier; and

delete the encrypted key and the plaintext key.

obtain an encrypted recording; and

store the encrypted recording with the encrypted key in non-volatile memory.

5 . A non-transitory computer-readable storage medium, comprising executable instructions that, when executed by a processor, facilitate performance of operations, comprising:

receiving a decryption request from a first server that includes a context identifier;

accessing an encrypted key stored in a record associated with the context identifier;

selecting a key management server based on the record associated with the context identifier;

transmitting a request for a data encryption key to the selected key management server, wherein the request includes the encrypted key;

receiving a plaintext key from the key management server; and

in response to the decryption request, transmitting the plaintext key to the first server.

6 . The non-transitory computer-readable storage medium of claim 5 , comprising executable instructions that, when executed by a processor, facilitate performance of operations, comprising:

decrypting an encrypted recording of a conference conducted by the first server using the plaintext key to obtain a decrypted recording.

7 . The non-transitory computer-readable storage medium of claim 5 , comprising executable instructions that, when executed by a processor, facilitate performance of operations, comprising:

receiving a re-keying request;

determining a set of one or more context identifiers based on the re-keying request, wherein the set of one or more context identifiers includes the context identifier;

identifying a next key management server based on the re-keying request;

responsive to the re-keying request, determining the plaintext key based on the encrypted key using the selected key management server;

determining a new encrypted key based on the plaintext key using the next key management server;

storing the new encrypted key in a record associated with the context identifier; and

deleting the encrypted key and the plaintext key.

8 . A non-transitory computer-readable storage medium, comprising executable instructions that, when executed by a processor, facilitate performance of operations, comprising:

receiving an encryption request from a first server that includes a data type indication and an identifier for one or more users;

selecting a security management policy from a set of security management policies stored in a data structure based on the identifier and based on the data type indication;

selecting a key management server based on the selected security management policy;

transmitting a request for a data encryption key to the selected key management server;

receiving a plaintext key and an encrypted key from the selected key management server; and

in response to the encryption request, transmitting the plaintext key to the first server.

9 . The non-transitory computer-readable storage medium of claim 8 , wherein the encryption request includes a role indication for a user associated with the identifier, and the security management policy is selected based on the role indication.

10 . The non-transitory computer-readable storage medium of claim 8 , wherein the encryption request includes a data label, and the security management policy is selected based on the data label.

11 . The non-transitory computer-readable storage medium of claim 8 , wherein the selected key management server is a cloud server.

12 . The non-transitory computer-readable storage medium of claim 8 , wherein the selected key management server is a hardware security module.

13 . The non-transitory computer-readable storage medium of claim 8 , wherein the selected key management server is in a customer cloud.

14 . The non-transitory computer-readable storage medium of claim 8 , comprising executable instructions that, when executed by a processor, facilitate performance of operations, comprising:

selecting a database server based on the selected security management policy; and

storing encrypted data, which has been encrypted using the plaintext key, in the selected database server.

15 . The non-transitory computer-readable storage medium of claim 14 , wherein the selected security management policy includes a pointer and credentials that are used to select the database server and store the encrypted data in the selected database server.

16 . The non-transitory computer-readable storage medium of claim 8 , comprising executable instructions that, when executed by a processor, facilitate performance of operations, comprising:

determining a context identifier based on the encryption request; and

storing the encrypted key in a record associated with the context identifier.

17 . The non-transitory computer-readable storage medium of claim 16 , wherein the record associated with the context identifier includes data identifying the selected key management server.

18 . The non-transitory computer-readable storage medium of claim 16 , comprising executable instructions that, when executed by a processor, facilitate performance of operations, comprising:

receiving a decryption request including the context identifier;

accessing the encrypted key in the record associated with the context identifier;

determining the plaintext key based on the encrypted key; and

transmitting the plaintext key in response to the decryption request.

19 . The non-transitory computer-readable storage medium of claim 18 , wherein determining the plaintext key based on the encrypted key comprises:

transmitting the encrypted key to the selected key management server; and

receiving the plaintext key from the selected key management server.

20 . The non-transitory computer-readable storage medium of claim 16 , comprising executable instructions that, when executed by a processor, facilitate performance of operations, comprising:

receiving a re-keying request;

determining a set of one or more context identifiers based on the re-keying request, wherein the set of one or more context identifiers includes the context identifier;

identifying a next key management server based on the re-keying request;

responsive to the re-keying request, determining the plaintext key based on the encrypted key using the selected key management server;

determining a new encrypted key based on the plaintext key using the next key management server;

storing the new encrypted key in a record associated with the context identifier; and

deleting the encrypted key and the plaintext key.

Assignments (2)
CHANGE OF NAME Recorded Jan 7, 2025
From: ZOOM VIDEO COMMUNICATIONS, INC.
To: ZOOM COMMUNICATIONS, INC.
Reel/Frame 069839/0593 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2023
From: KENNEDY, JOHN CARL; MALAIYANDI, PRASANNA KUMAR; PAGEL, MARTIN JOSEF; RAMAN, KARTHIK; ZILA, JAN
To: ZOOM VIDEO COMMUNICATIONS, INC.
Reel/Frame 062411/0945 →