IP Library › Granted Patent US 9,311,500
Granted Patent B2
US 9,311,500 · App. 14/037,292 · Granted Apr 12, 2016

Data security using request-supplied keys

Inventors: Gregory Branchek Roth (Seattle, WA); Eric Jason Brandwine (Haymarket, VA)
Assignee: Amazon Technologies, Inc.
G06F21/6209H04L9/0822H04L9/0819H04L9/3242H04L9/3247H04L2209/76
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,311,500
App. No.
14/037,292
Filed
Sep 25, 2013
Granted
Apr 12, 2016
Kind
B2
Examiner
DINH, MINH
Art Unit
2437
USPC
713/193
Abstract

Requests are submitted to a request processing entity where the requests include a cryptographic key to be used in fulfilling the request. The request processing entity, upon receipt of the request, extracts the key from the request and uses the key to perform one or more cryptographic operations to fulfill the request. The one or more cryptographic operations may include encryption/decryption of data that to be/is stored, in encrypted form, by a subsystem of the request processing entity. Upon fulfillment of the request, the request processing entity may perform one or more operations to lose access to the key in the request, thereby losing the ability to use the key.

Claims (38)

1. A computer-implemented method, comprising:

under the control of one or more computer systems of a service provider, the one or more computer systems configured with executable instructions,

receiving, from a requestor corresponding to a customer of the service provider, a request whose fulfillment involves performance of one or more cryptographic operations on data provided with the request and use of a cryptographic key that is encrypted by another key and supplied in the request, the service provider lacking access to the cryptographic key for an amount of time until receipt of the request, wherein the cryptographic key is a public key of a public-private key pair for which the service provider lacks access;

causing the request to be fulfilled by using the supplied cryptographic key as part of performing the one or more cryptographic operations on the specified data, wherein:

performing the one or more cryptographic operations includes causing the cryptographic key supplied in the request to be decrypted, thereby resulting in a decrypted supplied cryptographic key, and the one or more cryptographic operations include performance of an asymmetric algorithm using the public key; and

using the decrypted supplied cryptographic key to perform the one or more cryptographic operations;

providing a result of performing the one or more cryptographic operations to a data storage system; and

at a time after performing the one or more cryptographic operations, performing one or more operations that cause the service provider to lose access to the cryptographic key.

2. A computer-implemented method, comprising:

under the control of one or more computer systems of a service provider, the one or more computer systems configured with executable instructions,

receiving, from a requestor corresponding to a customer of the service provider, a request whose fulfillment involves performance of one or more cryptographic operations on data provided with the request and use of a cryptographic key that is encrypted by another key and supplied in the request, the service provider lacking access to the cryptographic key for an amount of time until receipt of the request;

causing the request to be fulfilled by using the supplied cryptographic key as part of performing the one or more cryptographic operations on the specified data, wherein:

performing the one or more cryptographic operations includes causing the cryptographic key supplied in the request to be decrypted, thereby resulting in a decrypted supplied cryptographic key, wherein causing the cryptographic key supplied in the request to be decrypted includes transmitting the cryptographic key to another entity for decryption; and

using the decrypted supplied cryptographic key to perform the one or more cryptographic operations;

providing a result of performing the one or more cryptographic operations to a data storage system; and

at a time after performing the one or more cryptographic operations, performing one or more operations that cause the service provider to lose access to the cryptographic key.

3. A system, comprising:

one or more processors; and

memory including instructions that, when executed by the one or more processors, cause the system to:

receive, from a requestor over a network, a request whose fulfillment involves performance of one or more cryptographic operations on data specified in the request using information that comprises a cryptographic key supplied in the request, wherein the information is usable to authenticate the request, wherein the cryptographic key supplied in the request is a public key, in encrypted form, of a public-private key pair;

as a result of receipt and authenticity of the request, perform the one or more cryptographic operations on the specified data, wherein:

performing the one or more cryptographic operations on the specified data includes decrypting the encrypted public key and encrypting the specified data with a symmetric key; and

using the public key to encrypt the symmetric key; and

provide a result of performing the one or more cryptographic operations.

4. The system of claim 3 , wherein:

the request is a request to read encrypted data out of a data storage system; and

the information is usable to authenticate the request using the cryptographic key supplied in the request.

5. The system of claim 3 , wherein the information is usable to authenticate the request by including an electronic signature generated based at least in part on a second cryptographic key different from the cryptographic key supplied in the request.

6. The system of claim 3 , wherein:

the one or more cryptographic operations include encryption of the specified data; and

providing the result of performing the one or more cryptographic operations includes transmitting the specified data in encrypted form to a data storage system for persistent storage.

7. The system of claim 3 , wherein the instructions further cause the system to perform one or more operations to lose access to the cryptographic key supplied in the request at a time after performing the one or more cryptographic operations.

8. The system of claim 3 , wherein the system lacks access to the cryptographic key for an amount of time until the request is received.

9. The system of claim 3 , wherein:

the cryptographic key supplied in the request is supplied in the request in encrypted form;

the system further comprises a subsystem configured to securely and store, inaccessibly from outside of the subsystem, a plurality of cryptographic keys that include a particular cryptographic key usable to decrypt the cryptographic key supplied in encrypted form; and

the instructions further cause the system to cause the subsystem to decrypt the cryptographic key supplied in encrypted form to be used in performing the one or more cryptographic operations.

10. The system of claim 3 , wherein the information is usable to authenticate the request by using the cryptographic key to authenticate the request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2014
From: ROTH, GREGORY BRANCHEK; BRANDWINE, ERIC JASON
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 031900/0815 →
Continuity (1)
Related Publication 20150089244A1 · Mar 26, 2015