IP Library Granted Patent US 11,436,341
Granted Patent B2
US 11,436,341 · App. 16/637,198 · Granted Sep 6, 2022

System and method for cryptographic keys security in the cloud

Inventor: Bushra Abbas Mohammed Al Belooshi (Sharjah, AE)
G06F21/602G06F12/1408G06F21/62G06F21/71H04L9/0631H04L9/0637H04L9/0662H04L9/0897
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,436,341
App. No.
16/637,198
Granted
Sep 6, 2022
Kind
B2
Abstract

An improved method or security solution for securing cryptographic keys in a virtual machine RAM. A security solution is proposed to hide cryptographic keys in the cloud, without the necessity of any architectural modifications. The present solution requires the availability of a Trusted Platform Module (TPM) capable of creating and holding a protected public/private key pair. It lends itself to security-as-a-service scenarios where third parties perform encryption or decryption on behalf of data owners. This allows the present solution to be easily integrated and coupled with other existing cloud architectures. A decrypt-scatter or gather-decrypt solution which allows users to carry out encryption or decryption while protecting keys from unauthorized peeks by the cloud administrators is proposed.

Claims (28)

1. A method of securing a key in a cloud using decrypt-scatter and gather-decrypt techniques, the key comprising a plurality of key chunks, the method comprising the steps of:

creating a Virtual Machine, wherein the Virtual Machine has a Random Access Memory;

generating a plurality of scattered memory addresses in the Random Access Memory of the Virtual Machine;

storing the plurality of key chunks in the plurality of generated scattered memory addresses, such that each scattered memory address stores a single key chunk among the plurality of key chunks; and

generating a plurality of temporary memory addresses, wherein each temporary memory address stores a temporary value used for calculating a round key,

wherein the plurality of key chunks are scattered by columns within the plurality of scattered memory addresses rather than scattering by row.

2. The method of claim 1 , wherein the plurality of temporary memory addresses each storing a temporary value used to calculate the round keys are located at an end of the plurality of scattered memory addresses scattered by columns.

3. The method of claim 1 , wherein the plurality of temporary memory addresses each storing a temporary value used to calculate the round keys are located at a beginning of the plurality of scattered memory addresses scattered by columns.

4. The method according to claim 1 , wherein the round key is calculated only when decrypting data, and the round key calculated is the minimum required to decrypt data.

5. The method according to claim 1 , wherein the plurality of key chunks are stored in the form of bytes.

6. The method according to claim 1 , wherein the plurality of scattered memory addresses are randomly generated memory address locations that are spread across rows and columns.

7. The method according to claim 1 , wherein the plurality of scattered memory addresses are randomly generated using a Pseudo Random Number Generator (PRNG).

8. The method according to claim 1 , wherein the method further comprises implementing an Advanced Encryption Standard (AES) encryption algorithm on the plurality of key chunks.

9. The method according to claim 8 , wherein the calculated round key is XORed with an array of plain text chunks on which the Advanced Encryption Standard (AES) algorithm is implemented.

10. A method of securing a key in a cloud using decrypt-scatter and gather-decrypt techniques, the key comprising a plurality of key chunks, the method comprising the steps of:

creating a Virtual Machine, wherein the Virtual Machine has a Random Access Memory;

generating a plurality of scattered memory addresses in the Random Access Memory of the Virtual Machine;

storing the plurality of key chunks in the plurality of generated scattered memory addresses, such that each scattered memory address stores a single key chunk among the plurality of key chunks; and

generating a plurality of temporary memory addresses, wherein each temporary memory address stores a temporary value used for calculating a round key,

wherein the plurality of key chunks are scattered by rows within the plurality of scattered memory addresses rather than scattering by column.

11. The method of claim 10 , wherein the plurality of temporary memory addresses each storing a temporary value used to generate a round key are located at an end of the plurality of the scattered memory addresses scattered by rows.

12. The method of claim 10 , wherein the plurality of temporary memory addresses each storing a temporary value used to generate a round key are located at a beginning of the plurality of scattered memory addresses scattered by rows.

13. The method according to claim 10 , wherein the round key is calculated only when decrypting data, and the round key calculated is the minimum required to decrypt data.

14. The method according to claim 10 , wherein the plurality of key chunks are stored in the form of bytes.

15. The method according to claim 10 , wherein the plurality of scattered memory addresses are randomly generated memory address locations that are spread across rows and columns.

16. The method according to claim 10 , wherein the plurality of scattered memory addresses are randomly generated using a Pseudo Random Number Generator (PRNG).

17. The method according to claim 10 , wherein the method further comprises implementing an Advanced Encryption Standard (AES) encryption algorithm on the plurality of key chunks.

18. The method according to claim 17 , wherein the calculated round key is XORed with an array of plain text chunks on which the Advanced Encryption Standard (AES) algorithm is implemented.

Continuity (2)
Provisional Application 62655363 · Apr 10, 2018
Related Publication 20200250318A1 · Aug 6, 2020