IP Library Granted Patent US 10,491,403
Granted Patent B2
US 10,491,403 · App. 15/881,550 · Granted Nov 26, 2019

Data loss prevention with key usage limit enforcement

Inventors: Marcel Andrew Levy (Seattle, WA); Darren Ernest Canavor (Redmond, WA); Zachary Ganwise Fewtrell (Redmond, WA); Andrew Alphus Kimbrough (Seattle, WA); Jonathan Kozolchyk (Seattle, WA); Darin Keith McAdams (Seattle, WA); Pradeep Ramarao (Kirkland, WA); Gregory Branchek Roth (Seattle, WA)
Assignee: Amazon Technologies, Inc.
H04L9/3247H04L2209/72
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,491,403
App. No.
15/881,550
Granted
Nov 26, 2019
Kind
B2
Abstract

In a distributed system, a computer system responsible, at least in part, for complying with a cryptographic key usage limit for a cryptographic key, obtains results of cryptographic operations generated based at least in part on the cryptographic key and transmits the obtained results over a network. The computer system digitally signs the results and provides the results with digital signatures of the results. Another device intercepts the results and allows the results to proceed to their destination contingent on successful validation of the digital signature.

Claims (36)

1. A computer-implemented method, comprising:

identifying one or more parameters associated with data, the data indicated in a request for delivery to a network destination, the one or more parameters indicative of the data being encrypted using a cryptographic key subject to a policy, the policy defining a usage limit on the cryptographic key;

processing the data to determine the data was encrypted using the cryptographic key outside of the usage limit;

preventing, in response to determining that the data was encrypted using the cryptographic key outside of the usage limit, the data from reaching the network destination;

re-encrypting the data using a different cryptographic key in compliance with the policy, thereby generating re-encrypted data; and

transmitting the re-encrypted data to the network destination.

2. The computer-implemented method of claim 1 , wherein the usage limit is based at least in part on a time of validity for the cryptographic key.

3. The computer-implemented method of claim 1 , wherein the data is identified as a result of receiving a trigger associated with enforcing the policy.

4. The computer-implemented method of claim 1 , wherein the network destination is on a different network than a source sending the data to the network destination.

5. The computer-implemented method of claim 1 , wherein identifying the data includes intercepting the data prior to the data reaching the network destination.

6. The computer-implemented method of claim 1 , wherein the different cryptographic key is a symmetric cryptographic key.

7. The computer-implemented method of claim 1 , wherein:

the method further comprises obtaining a second request to re-encrypt the data; and

the data is re-encrypted in response to the obtaining of the second request.

8. The computer-implemented method of claim 1 , wherein the cryptographic key is persisted in data storage.

9. A system, comprising:

one or more processors; and

memory including instructions that, as a result of execution by the one or more processors, cause the system to:

identify-a data transmission encrypted using a cryptographic key subject to a policy that defines a usage limit on the cryptographic key;

process, by determining validity of an attestation of a system state attributable to the cryptographic key, the data to determine that the data transmission was encrypted using the cryptographic key in violation of the policy, wherein the system state is associated with a computing environment that generates the cryptographic key; and

block, as a result of the violation of the policy, the data transmission from reaching a network destination.

10. The system of claim 9 , wherein the one or more services process the data by determining validity of a digital signature associated with the cryptographic key.

11. The system of claim 10 , wherein the data transmission includes the digital signature.

12. The system of claim 10 , wherein the one or more services further process the digital signature to determine that the cryptographic key was used after the usage limit was fulfilled.

13. The system of claim 9 , wherein the instructions further include instructions that, as a result of execution by the one or more processors of a computer system, further cause the computer system to re-encrypt the data transmission with a current cryptographic key.

14. A non-transitory computer-readable storage medium comprising executable instructions that, as a result of execution by one or more processors of a computer system, cause the computer system to at least:

enforce a policy that defines a usage limit on a cryptographic key, wherein the usage limit is associated with a rotation schedule, by at least:

identifying one or more markers associated with a data transmission indicative of the data transmission being encrypted using the cryptographic key;

processing the data to determine that the data transmission was encrypted using the cryptographic key in violation of the policy; and

preventing, as a result of the violation of the policy, the data transmission from reaching a network destination.

15. The non-transitory computer-readable storage medium of claim 14 , wherein the instructions, as a result of execution, further cause the computer system to detect that the data transmission is intended for the network destination.

16. The non-transitory computer-readable storage medium of claim 14 , wherein the computer system generates the cryptographic key.

17. The non-transitory computer-readable storage medium of claim 14 , wherein the instructions, as a result of execution, further cause the computer system to identify the data transmission at an edge of a network to which the network destination is associated.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the data transmission is from a different network than the network.

19. The non-transitory computer-readable storage medium of claim 14 , wherein the instructions, as a result of execution, further cause the computer system to allow unencrypted data to reach the network destination.

20. The non-transitory computer-readable storage medium of claim 14 , wherein the rotation schedule is associated with a clock-based trigger.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2018
From: LEVY, MARCEL ANDREW; CANAVOR, DARREN ERNEST; FEWTRELL, ZACHARY GANWISE; KIMBROUGH, ANDREW ALPHUS; KOZOLCHYK, JONATHAN; MCADAMS, DARIN KEITH; RAMARAO, PRADEEP; ROTH, GREGORY BRANCHEK
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 044744/0683 →
Continuity (2)
Continuation 14318422 · Jun 27, 2014
Related Publication 20180167220A1 · Jun 14, 2018