IP Library › Granted Patent US 12,174,988
Granted Patent B2
US 12,174,988 · App. 17/857,781 · Granted Dec 24, 2024

System and method for managing transparent data encryption of database

Inventors: Maximilian Alastair Buchan (Slough, GB); Dzmitry Maskaliou (Slough, GB); Michael Antipin (Slough, GB); Yann Golanski (Slough, GB)
G06F21/6227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,174,988
App. No.
17/857,781
Granted
Dec 24, 2024
Kind
B2
Abstract

Disclosed is a system for managing transparent data encryption of a database. The system comprises an encrypted vault application and an application server. The encrypted vault application stores at least one encryption key for the database. The application server is configured to provide an authorization token to the encrypted vault application after unsealing of the encrypted vault application; receive an access token from the encrypted vault application, after authentication of the application server; provide the access token to the encrypted vault application to receive at least one encryption key therefrom; and communicate the at least one encryption key, via a key talker, to the database; and wherein the database comprises a key listener that listens for the at least one encryption key and provides the at least one encryption key to the database.

Claims (32)

1. A system for managing transparent data encryption of a database, the system comprising:

a physical server:

an application server comprising a graphical user interface, wherein

the physical server is configured to host the application server, and

the graphical user interface is configured to manage the physical server; and

an encrypted vault application for storing at least one encryption key for the database, wherein the encrypted vault application requires a plurality of administrator keys for unsealing thereof, wherein the

application server is configured to:

provide an authorization token to the encrypted vault application after unsealing of the encrypted vault application, wherein the authorization token is characteristic to the application server and is used for authentication of the application server;

receive an access token from the encrypted vault application, after authentication of the application server;

provide the access token to the encrypted vault application to receive at least one encryption key therefrom;

communicate the at least one encryption key, via a key talker, to the database; and

raise an alarm in an event of not receiving the at least one encryption key after providing the access token,

wherein the database comprises a key listener that listens for the at least one encryption key and provides the at least one encryption key to the database, wherein the key talker upon receiving the at least one encryption key, immediately connects to the key listener and sends the at least one encryption key to the key listener, and wherein the at least one encryption key is encrypted in transit.

2. The system of claim 1 , wherein the application server is configured to employ Kubernetes service account to authenticate the application server.

3. The system of claim 1 , wherein the access token is time sensitive and is used only once to obtain the at least one encryption key from the encrypted vault application.

4. The system of claim 1 , wherein the encrypted vault application is a Hashicorp Vault.

5. The system of claim 1 , wherein the plurality of administrator keys for unsealing of the encrypted vault application are shared using Shamir's Secret Sharing (SSS) algorithm.

6. The system of claim 1 , wherein the at least one encryption key is communicated and provided using Transport Layer Security (TSL).

7. A method for managing transparent data encryption of a database, wherein the method is implemented using a system comprising:

an encrypted vault application for storing at least one encryption key for the database, wherein the encrypted vault application requires a plurality of administrator keys for unsealing thereof; and

an application server;

wherein the method comprises:

providing an authorization token to the encrypted vault application after unsealing of the encrypted vault application, wherein the authorization token is characteristic to the application server and is used for authentication of the application server;

receiving an access token from the encrypted vault application, after authentication of the application server;

providing the access token to the encrypted vault application to receive at least one encryption key therefrom;

communicating the at least one encryption key, via a key talker, to the database; and

raising an alarm in an event of not receiving the at least one encryption key, at the application server, after providing the access token,

wherein the database comprises a key listener that listens for the at least one encryption key and provides the at least one encryption key to the database, wherein the key talker upon receiving the at least one encryption key, immediately connects to the key listener and sends the at least one encryption key to the key listener, and wherein the at least one encryption key is encrypted in transit.

8. The method of claim 7 , wherein the method comprises employing Kubernetes service account to authenticate the application server.

9. The method of claim 7 , wherein the access token is time sensitive and is used only once to obtain the at least one encryption key from the encrypted vault application.

10. The method of claim 7 , wherein the method comprises using Shamir's Secret Sharing (SSS) algorithm for sharing the plurality of administrator keys for unsealing of the encrypted vault application.

11. The method of claim 7 , wherein the method comprises using Transport Layer Security (TSL) for communicating and providing the at least one encryption key.

Priority Claims (1)
GB 2109573 · Jul 2, 2021 · national
Continuity (1)
Related Publication 20230004671A1 · Jan 5, 2023