IP Library Granted Patent US 12,401,500
Granted Patent B2
US 12,401,500 · App. 18/321,694 · Granted Aug 26, 2025

Distributed key management system

Inventors: Derek Chamorro (Austin, TX); Michael Pak (Portland, OR); Ignat Korchagin (Orpington, GB); Chase Robinson (San Francisco, CA)
Assignee: CLOUDFLARE, INC.
H04L9/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,500
App. No.
18/321,694
Granted
Aug 26, 2025
Kind
B2
Abstract

A distributed key management system (KMS) includes a central KMS server and multiple intermediate KMS servers. The central KMS server replicates managed keys to the intermediate KMS servers. An intermediate KMS server receives a KMS service request from a KMS client, where any of the intermediate KMS servers are capable of servicing the request. The intermediate KMS server performs the action requested if it has access to the necessary managed key and returns the response to the KMS client. If it does not have access to the necessary managed key, the intermediate KMS server transmits a request for the managed key to the central KMS server. The intermediate KMS server receives the managed key, performs the action requested, and returns the response to the KMS client.

Claims (62)

1. A method, comprising:

receiving, at a first one of a plurality of intermediate key management system (KMS) servers of a distributed KMS, a first KMS service request from a first KMS client, wherein each of the plurality of intermediate KMS servers is capable of servicing the first KMS service request;

determining, at the first intermediate KMS server, that the first intermediate KMS server does not have local access to a first managed key that is capable of performing an action requested in the first KMS service request;

transmitting, from the first intermediate KMS server to a central KMS server of the distributed KMS, a query for the first managed key;

receiving, from the central KMS server at the first intermediate KMS server, the first managed key;

performing, at the first intermediate KMS server, the action requested in the first KMS service request using the first managed key;

transmitting, from the first intermediate KMS server to the first KMS client, a response to the first KMS service request that includes a result of the performed action using the first managed key;

receiving, at the first one of the plurality of intermediate KMS servers from a second one of the plurality of intermediate KMS servers, a second managed key;

receiving, at the first one of the plurality of intermediate KMS servers, a second KMS service request from a second KMS client, wherein each of the plurality of intermediate KMS servers is capable of servicing the second KMS service request, and wherein the first intermediate KMS server is closest to the second KMS client out of the plurality of intermediate KMS servers;

determining, at the first intermediate KMS server, that the first intermediate KMS server has access to the second managed key that is capable of performing an action requested in the second KMS service request;

performing, at the first intermediate KMS server, the action requested in the second KMS service request using the second managed key; and

transmitting, from the first intermediate KMS server to the second KMS client, a response to the second KMS service request that includes a result of the performed action using the second managed key.

2. The method of claim 1 , further comprising:

receiving, at the first one of the plurality of intermediate key management system (KMS) servers of the distributed KMS from the central KMS server, a policy associated with the first managed key; and

enforcing the policy that is associated with the first managed key prior to performing the action requested in the first KMS service request using the first managed key.

3. The method of claim 2 , wherein enforcing policy includes:

determining an identity associated with the first KMS service request; and

determining that the action requested in the first KMS service request is allowed for the determined identity.

4. The method of claim 1 , wherein the first intermediate KMS server is closest to the first KMS client out of the plurality of intermediate KMS servers.

5. The method of claim 1 , wherein the first intermediate KMS server is part of a same datacenter as the first KMS client.

6. The method of claim 1 , wherein the first KMS client is a compute server in a distributed cloud computing network.

7. A non-transitory machine-readable storage medium that provides instructions that, when executed by a processor, will cause operations to be performed including:

receiving, at a first one of a plurality of intermediate key management system (KMS) servers of a distributed KMS, a first KMS service request from a first KMS client, wherein each of the plurality of intermediate KMS servers is capable of servicing the first KMS service request;

determining, at the first intermediate KMS server, that the first intermediate KMS server does not have local access to a first managed key that is capable of performing an action requested in the first KMS service request;

transmitting, from the first intermediate KMS server to a central KMS server of the distributed KMS, a query for the first managed key;

receiving, from the central KMS server at the first intermediate KMS server, the first managed key;

performing, at the first intermediate KMS server, the action requested in the first KMS service request using the first managed key;

transmitting, from the first intermediate KMS server to the first KMS client, a response to the first KMS service request that includes a result of the performed action using the first managed key;

receiving, at the first one of the plurality of intermediate KMS servers from a second one of the plurality of intermediate KMS servers, a second managed key;

receiving, at the first one of the plurality of intermediate KMS servers, a second KMS service request from a second KMS client, wherein each of the plurality of intermediate KMS servers is capable of servicing the second KMS service request, and wherein the first intermediate KMS server is closest to the second KMS client out of the plurality of intermediate KMS servers;

determining, at the first intermediate KMS server, that the first intermediate KMS server has access to the second managed key that is capable of performing an action requested in the second KMS service request;

performing, at the first intermediate KMS server, the action requested in the second KMS service request using the second managed key; and

transmitting, from the first intermediate KMS server to the second KMS client, a response to the second KMS service request that includes a result of the performed action using the second managed key.

8. The non-transitory machine-readable storage medium of claim 7 , wherein the operations further comprise:

receiving, at the first one of the plurality of intermediate key management system (KMS) servers of the distributed KMS from the central KMS server, a policy associated with the first managed key; and

enforcing the policy that is associated with the first managed key prior to performing the action requested in the first KMS service request using the first managed key.

9. The non-transitory machine-readable storage medium of claim 8 , wherein enforcing policy includes:

determining an identity associated with the first KMS service request; and

determining that the action requested in the first KMS service request is allowed for the determined identity.

10. The non-transitory machine-readable storage medium of claim 7 , wherein the first intermediate KMS server is closest to the first KMS client out of the plurality of intermediate KMS servers.

11. The non-transitory machine-readable storage medium of claim 7 , wherein the first intermediate KMS server is part of a same datacenter as the first KMS client.

12. The non-transitory machine-readable storage medium of claim 7 , wherein the first KMS client is a compute server in a distributed cloud computing network.

13. A first intermediate key management system (KMS) server of a plurality of intermediate KMS servers of a distributed KMS, comprising:

a processor; and

a non-transitory machine-readable storage medium that provides instructions that, when executed by the processor, will cause the first intermediate KMS server to carry out operations including:

receiving, at the first one of the plurality of intermediate KMS servers, a first KMS service request from a first KMS client, wherein each of the plurality of intermediate KMS servers is capable of servicing the first KMS service request;

determining, at the first intermediate KMS server, that the first intermediate KMS server does not have local access to a first managed key that is capable of performing an action requested in the first KMS service request;

transmitting, from the first intermediate KMS server to a central KMS server of the distributed KMS, a query for the first managed key;

receiving, from the central KMS server at the first intermediate KMS server, the first managed key;

performing, at the first intermediate KMS server, the action requested in the first KMS service request using the first managed key;

transmitting, from the first intermediate KMS server to the first KMS client, a response to the first KMS service request that includes a result of the performed action using the first managed key;

receiving, at the first intermediate KMS server from a second one of the plurality of intermediate KMS servers, a second managed key;

receiving, at the first intermediate KMS server, a second KMS service request from a second KMS client, wherein each of the plurality of intermediate KMS servers is capable of servicing the second KMS service request, and wherein the first intermediate KMS server is closest to the second KMS client out of the plurality of intermediate KMS servers;

determining, at the first intermediate KMS server, that the first intermediate KMS server has access to the second managed key that is capable of performing an action requested in the second KMS service request;

performing, at the first intermediate KMS server, the action requested in the second KMS service request using the second managed key; and

transmitting, from the first intermediate KMS server to the second KMS client, a response to the second KMS service request that includes a result of the performed action using the second managed key.

14. The first intermediate KMS server of claim 13 , wherein the operations further comprise:

receiving, at the first intermediate KMS server from the central KMS server, a policy associated with the first managed key; and

enforcing the policy that is associated with the first managed key prior to performing the action requested in the first KMS service request using the first managed key.

15. The first intermediate KMS server of claim 14 , wherein enforcing policy includes:

determining an identity associated with the first KMS service request; and

determining that the action requested in the first KMS service request is allowed for the determined identity.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2024
From: CHAMORRO, DEREK; PAK, MICHAEL; KORCHAGIN, IGNAT; ROBINSON, CHASE
To: CLOUDFLARE, INC.
Reel/Frame 068546/0282 →
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
Continuity (2)
Continuation 17956689 · Sep 29, 2022
Related Publication 20240113866A1 · Apr 4, 2024
References Cited (27)
US 7823190B1 · Kacarov et al. · 2010 [cited by applicant]
US 9817675B1 · Katchapalayam et al. · 2017 [cited by applicant]
US 10326597B1 · Roth · 2019 [cited by examiner]
US 11658812B1 · Chamorro et al. · 2023 [cited by applicant]
US 20090092252A1 · Noll · 2009 [cited by examiner]
US 20130031255A1 · Maloy et al. · 2013 [cited by applicant]
US 20160253515A1 · Damgård · 2016 [cited by examiner]
US 20160269370A1 · White · 2016 [cited by examiner]
US 20160316006A1 · Zhang · 2016 [cited by examiner]
US 20170085374A1 · Chen · 2017 [cited by applicant]
US 20180048464A1 · Lim et al. · 2018 [cited by applicant]
US 20180115587A1 · Roth et al. · 2018 [cited by applicant]
US 20190342079A1 · Rudzitis et al. · 2019 [cited by applicant]
US 20190372758A1 · Tevosyan et al. · 2019 [cited by applicant]
US 20190394024A1 · Vepa · 2019 [cited by examiner]
US 20210028931A1 · Ng et al. · 2021 [cited by applicant]
US 20220069983A1 · Yoshida et al. · 2022 [cited by applicant]
US 20220123920A1 · Pike et al. · 2022 [cited by applicant]
US 20220240083A1 · Goel et al. · 2022 [cited by applicant]
CN 103107889A · 2013 [cited by applicant]
WO 2020114377A1 · 2020 [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 17/956,689, Dec. 1, 2022, 6 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/322,265, Aug. 3, 2023, 38 pages. [cited by applicant]
Non-Final Office Action, U.S. Appl. No. 18/433,124, Oct. 9, 2024, 40 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 17/956,689, Jan. 13, 2023, 8 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 18/322,265, Nov. 21, 2023, 34 pages. [cited by applicant]
Notice of Allowance, U.S. Appl. No. 18/433,124, Feb. 26, 2025, 35 pages. [cited by applicant]