IP Library › Granted Patent US 10,200,194
Granted Patent B2
US 10,200,194 · App. 15/639,698 · Granted Feb 5, 2019

Theft and tamper resistant data protection

Inventors: Scott A. Field (Redmond, WA); Aravind N. Thoram (Sammamish, WA); John Michael Walton (Redmond, WA); Dayi Zhou (Redmond, WA); Alex M. Semenko (Issaquah, WA); Avraham Michael Ben-Menahem (Sammamish, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L9/0822G06F12/1408H04L9/0825H04L63/045H04L63/0853G06F21/10G06F21/64G06F21/72G06F21/78G06F2221/0797
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,200,194
App. No.
15/639,698
Granted
Feb 5, 2019
Kind
B2
Abstract

Systems and methods are provided for adding security to client data by maintaining decryption keys at a server that provide access to encrypted keys that are maintained at a client system with encrypted client data. A specialized protocol is utilized for accessing the decryption keys from the server. Once obtained, the decryption key is used to decrypt the encrypted key at the client and then the newly decrypted decryption key is used to decrypt the encrypted data. A server can also perform policy checks or trigger additional authentication such as SMS, phone, or email notification before allowing access to the server decryption key. Furthermore, in some instances, the server can also prevent access to the server decryption keys in response to anomalies, such as decommissioning and other asset management events.

Claims (17)

1. A method implemented by a client system for keeping encrypted data tamper resistant, comprising:

encrypting a cluster of data using an encryption key;

creating a unique key identifier of the cluster of encrypted data;

encrypting the decryption key using a public key, wherein the decryption key is interrelated to the encryption key and configured for decrypting the cluster of encrypted data;

storing the encrypted decryption key and the unique key identifier in the cluster of encrypted data as metadata;

sending a private key and the unique key identifier to a server that has access to a key ID database that stores private keys and unique key identifiers, wherein the private key is interrelated to the public key and configured for decrypting the encrypted decryption key;

initiating boot of the client system;

sending a communication request to a server that has access to the key ID database;

receiving a response from the server granting the request;

sending the unique key identifier and the encrypted decryption key to the server;

receiving a decrypted decryption key from the server; and

decrypting the cluster of encrypted data using the decrypted decryption key.

2. The method of claim 1 , wherein the unique key identifier is certificate thumbprint.

3. The method of claim 1 , wherein the server is a PXE server, wherein the communication request is a PXE discover, and wherein the communication response is a response to the PXE discover.

4. The method of claim 1 , wherein the request for boot code is a request for boot code via TFTP.

5. The method of claim 1 , wherein the unique key identifier includes a hash value of the cluster of encrypted data.

6. The method of claim 1 , wherein the unique key identifier includes a hash value of the cluster of encrypted data and the public key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2017
From: FIELD, SCOTT A.; THORAM, ARAVIND N.; WALTON, JOHN MICHAEL; ZHOU, DAYI; SEMENKO, ALEX M.; BEN-MENAHEM, AVRAHAM MICHAEL
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 042927/0213 →
Continuity (2)
Continuation 15639613 · Jun 30, 2017
Related Publication 20190007204A1 · Jan 3, 2019