IP Library › Granted Patent US 11,646,884
Granted Patent B2
US 11,646,884 · App. 17/339,509 · Granted May 9, 2023

Database key management

Inventor: Ashton Mozano (San Diego, CA)
Assignee: ServiceNow, Inc.
H04L9/0891G06F21/602H04L9/083H04L9/0861H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,646,884
App. No.
17/339,509
Granted
May 9, 2023
Kind
B2
Abstract

An indication that a secure connection has been established with a key management service is received. The secure connection is associated with an automatically generated session encryption key utilized for encryption of data communication through the secure connection. In response to the indication that the secure connection has been established with the key management service, a determination is made to perform a rotation of a local encryption key utilized in encrypting locally stored data. The rotation of the local encryption key is performed based at least in part on the automatically generated session encryption key.

Claims (31)

1. A method, comprising:

establishing a secure connection from a first server to a second server with a key management service, wherein the secure connection is associated with an automatically generated session encryption key utilized for encryption of data communication through the secure connection between the first server and the second server;

determining to perform a rotation of a local encryption key utilized in encrypting locally stored data; and

performing the rotation of the local encryption key based at least in part on the automatically generated session encryption key including by obtaining the automatically generated session encryption key from an operating system of the first server and determining a replacement key for the local encryption key based on the automatically generated session encryption key previously used to encrypt network communication between the first server and the second server.

2. The method of claim 1 , wherein the local encryption key is a database master encryption key.

3. The method of claim 1 , wherein the local encryption key is a database tablespace encryption key.

4. The method of claim 1 , wherein the secure connection is a Hypertext Transfer Protocol Secure (HTTPS) connection.

5. The method of claim 1 , wherein the automatically generated session encryption key is generated in response to performing a Transport Layer Security (TLS) handshake.

6. The method of claim 1 , wherein the automatically generated session encryption key is a symmetric encryption key.

7. The method of claim 1 , wherein the key management service is hosted by an independent third party different from the first server.

8. The method of claim 1 , wherein the local encryption key is utilized for encrypting database data, email data, or file data.

9. The method of claim 1 , wherein the secure connection is established in response to an automated key rotation schedule.

10. The method of claim 1 , wherein the secure connection is established in response to a security notification.

11. A system, comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory is configured to provide the one or more processors with instructions which when executed cause the one or more processors to:

establishing a secure connection from a first server to a second server with a key management service, wherein the secure connection is associated with an automatically generated session encryption key utilized for encryption of data communication through the secure connection between the first server and the second server;

determine to perform a rotation of a local encryption key utilized in encrypting locally stored data; and

perform the rotation of the local encryption key based at least in part on the automatically generated session encryption key including by being configured to obtain the automatically generated session encryption key from an operating system of the first server and determine a replacement key for the local encryption key based on the automatically generated session encryption key previously used to encrypt network communication between the first server and the second server.

12. The system of claim 11 , wherein the local encryption key is a database master encryption key or a database tablespace encryption key.

13. The system of claim 11 , wherein the secure connection is a Hypertext Transfer Protocol Secure (HTTPS) connection.

14. The system of claim 11 , wherein the automatically generated session encryption key is generated in response to performing a Transport Layer Security (TLS) handshake.

15. The system of claim 11 , wherein the automatically generated session encryption key is a symmetric encryption key.

16. The system of claim 11 , wherein the key management service is hosted by an independent third party different from the first server.

17. The system of claim 11 , wherein the local encryption key is utilized for encrypting database data, email data, or file data.

18. The system of claim 11 , wherein the secure connection is established in response to an automated key rotation schedule.

19. The system of claim 11 , wherein the secure connection is established in response to a security notification.

20. A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

establishing a secure connection from a first server to a second server with a key management service, wherein the secure connection is associated with an automatically generated session encryption key utilized for encryption of data communication through the secure connection between the first server and the second server;

determining to perform a rotation of a local encryption key utilized in encrypting locally stored data; and

performing the rotation of the local encryption key based at least in part on the automatically generated session encryption key including by obtaining the automatically generated session encryption key from an operating system of the first server and determining a replacement key for the local encryption key based on the automatically generated session encryption key previously used to encrypt network communication between the first server and the second server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2021
From: MOZANO, ASHTON
To: SERVICENOW, INC.
Reel/Frame 057173/0465 →
Continuity (1)
Related Publication 20220393868A1 · Dec 8, 2022
Cited By (1)
US 12,688,318