IP Library › Granted Patent US 12,200,118
Granted Patent B1
US 12,200,118 · App. 18/141,268 · Granted Jan 14, 2025

Application programming interface to generate data key pairs

Inventors: Rajkumar Copparapu (Sammamish, WA); Peter Da-Ming Zieske (Seattle, WA); Benjamin Elias Seidenberg (Seattle, WA); Justin Jon Derby (Edmonds, WA)
Assignee: Amazon Technologies, Inc.
H04L9/0877G06F9/541G06F9/546H04L9/0618
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,200,118
App. No.
18/141,268
Granted
Jan 14, 2025
Kind
B1
Abstract

A computer-implemented method for providing cryptographic services, including providing key pairs. A key management service receives a web service application programming interface or other such request to generate a key pair. To respond to the request, the key management service obtains a pregenerated key pair that is securely stored and provides the key pair in response to the request.

Claims (61)

1. A computer-implemented method, comprising:

obtaining, at a web server providing an interface of a key management service, a web service application programming interface request to generate a data key pair;

obtaining an encrypted client managed key specified by a parameter of the request;

at a hardware security module (HSM) of the key management service:

decrypting the encrypted client managed key;

selecting a queue from a plurality of queues of different types of key pairs according to a type of data key pair specified in the request;

removing a pregenerated data key pair from the selected queue, the pregenerated data key pair comprising a public key and a private key;

providing the pregenerated data key pair to be included with a response to the request; and

encrypting the pregenerated data key pair using the decrypted client managed key, resulting in an encrypted data key pair; and

transmitting, from the web server, the response including the encrypted data key pair.

2. The computer-implemented method of claim 1 , wherein the encrypted client managed key is obtained as a result of being specified by a parameter of the request.

3. The computer-implemented method of claim 2 , wherein the parameter indicates the encrypted client managed key is to be obtained from a client storage location outside of the key management service.

4. The computer-implemented method of claim 1 , wherein selecting the queue is based at least in part on the request specifying the type of data key pair.

5. The computer-implemented method of claim 1 , wherein the plurality of queues comprises a first queue corresponding to a first cryptographic algorithm and a second queue corresponding to a second cryptographic algorithm, the first cryptographic algorithm different from the second cryptographic algorithm.

6. The computer-implemented method of claim 1 , further comprising:

detecting, as a result of transmitting the response, the HSM is idle;

determining an availability of key pairs in the selected queue is below a threshold;

generating an additional key pair of the type consistent with the selected queue; and

adding the additional key pair to the selected queue.

7. The computer-implemented method of claim 6 , wherein the threshold is determined based on a usage pattern of requests received by the HSM within a time interval.

8. The computer-implemented method of claim 1 , further comprising generating a quantity of additional key pairs based on a notification from a client indicating a schedule of future requests.

9. A system, comprising:

one or more processors; and

memory that stores computer-executable instructions that are executable by the one or more processors to cause the system to:

obtain a request to generate a data key pair; and

fulfill the request by at least:

obtaining, by commanding a hardware security module (HSM) to provide one of a plurality of pregenerated data key pairs internally stored by the HSM, a pregenerated data key pair;

performing an operation to prevent the pregenerated data key pair from being provided in response to another request; and

providing the pregenerated data key pair.

10. The system of claim 9 , wherein the instructions further cause the system to:

obtain an encrypted client managed key specified by the request;

by the HSM:

decrypt the encrypted client managed key; and

encrypt the pregenerated data key pair using the decrypted client managed key, resulting in an encrypted data key pair; and

provide the pregenerated data key pair by transmitting a response to the request, the response including the encrypted data key pair.

11. The system of claim 10 , wherein the encrypted client managed key is obtained from a client storage location outside of the HSM.

12. The system of claim 10 , wherein the instructions further cause the system to:

select a queue from a plurality of queues of different types of key pairs according to a type of data key pair indicated in the request; and

perform the operation by removing the pregenerated data key pair from the selected queue.

13. The system of claim 12 , wherein the instructions further cause the system to select the queue based at least in part on information in the request specifying the type of data key pair.

14. The system of claim 9 , wherein the instructions that cause the system to:

detect, as a result of providing the pregenerated data key pair, the HSM is idle;

determine a shortage of pregenerated key pairs; and

as a result of the HSM being idle, generate, by the HSM, one or more additional key pairs sufficient to resolve the shortage.

15. A non-transitory computer-readable storage medium storing thereon executable instructions that, as a result of being executed by one or more processors of a computer system, cause a first computer system to at least:

perform a set of operations to remove a pregenerated data key pair from a plurality of pregenerated data key pairs, the pregenerated data key pair comprising a public key and a private key;

generate a response to a request to generate a data key pair that comprises the removed pregenerated data key pair, at least by:

obtaining an encrypted client managed key;

decrypting the encrypted client managed key;

selecting a queue of a plurality of queues of different types of key pairs;

removing the pregenerated data key pair from the selected queue; and

encrypting the pregenerated data key pair using the decrypted client managed key, resulting in an encrypted data key pair; and

transmit the response to the request, the response including the encrypted data key pair.

16. The non-transitory computer-readable storage medium of claim 15 , wherein the encrypted client managed key is obtained from a storage location outside of the computer system.

17. The non-transitory computer-readable storage medium of claim 15 , wherein the queue is selected based at least in part on the request specifying the type of data key pair.

18. The non-transitory computer-readable storage medium of claim 15 , wherein the instructions further cause the computer system to:

determine a shortage of key pairs in the selected queue;

generate one or more additional key pairs of the type consistent with the selected queue to resolve the determined shortage; and

add the one or more additional key pairs to the selected queue.

19. The non-transitory computer-readable storage medium of claim 18 , wherein the instructions further cause the computer system to detect an idle state, and wherein the shortage is determined as a result of detecting the idle state.

20. The non-transitory computer-readable storage medium of claim 18 , wherein the shortage is determined based on a prediction of future requests to be received by the computer system within a time interval, the prediction based on past usage of the computer system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2023
From: COPPARAPU, RAJKUMAR; ZIESKE, PETER DA-MING; SEIDENBERG, BENJAMIN ELIAS; DERBY, JUSTIN JON
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 063484/0146 →
Continuity (1)
Continuation 16699452 · Nov 29, 2019
References Cited (40)
US 7093295B1 · Saito · 2006 [cited by applicant]
US 7983423B1 · Agarwal · 2011 [cited by examiner]
US 9722974B1 · Fuller et al. · 2017 [cited by applicant]
US 10979403B1 · Mutescu · 2021 [cited by examiner]
US 20030021420A1 · Kamperman et al. · 2003 [cited by applicant]
US 20030126457A1 · Kohiyama et al. · 2003 [cited by applicant]
US 20050010763A1 · Matsui et al. · 2005 [cited by applicant]
US 20050144478A1 · Yamanaka et al. · 2005 [cited by applicant]
US 20060149965A1 · Sharma · 2006 [cited by examiner]
US 20070055891A1 · Plotkin et al. · 2007 [cited by applicant]
US 20070220279A1 · Northcutt et al. · 2007 [cited by applicant]
US 20080235508A1 · Ran et al. · 2008 [cited by applicant]
US 20090097642A1 · Schnell et al. · 2009 [cited by applicant]
US 20090214044A1 · Kinoshita · 2009 [cited by applicant]
US 20110038477A1 · Bilodi · 2011 [cited by applicant]
US 20120137139A1 · Kudoh et al. · 2012 [cited by applicant]
US 20130070925A1 · Yamada et al. · 2013 [cited by applicant]
US 20150270957A1 · Uzun · 2015 [cited by applicant]
US 20160065364A1 · Amiri et al. · 2016 [cited by applicant]
US 20160352518A1 · Ford et al. · 2016 [cited by applicant]
US 20170085540A1 · Avanzi et al. · 2017 [cited by applicant]
US 20170093569A1 · Roth · 2017 [cited by examiner]
US 20170279607A1 · Kent · 2017 [cited by examiner]
US 20170359174A1 · Tamura et al. · 2017 [cited by applicant]
US 20180012032A1 · Radich et al. · 2018 [cited by applicant]
US 20180041341A1 · Gulati · 2018 [cited by applicant]
US 20180062835A1 · Hamel et al. · 2018 [cited by applicant]
US 20180083933A1 · Mullen et al. · 2018 [cited by applicant]
US 20180332011A1 · Gray · 2018 [cited by applicant]
US 20180357426A1 · Pearson et al. · 2018 [cited by applicant]
US 20190089529A1 · Conway et al. · 2019 [cited by applicant]
US 20190124057A1 · Smirnoff et al. · 2019 [cited by applicant]
US 20190340251A1 · Peddada et al. · 2019 [cited by applicant]
US 20190347435A1 · Zheng et al. · 2019 [cited by applicant]
US 20200053065A1 · Wisniewski · 2020 [cited by examiner]
US 20200169401A1 · Dooley et al. · 2020 [cited by applicant]
US 20200304299A1 · Medvinsky · 2020 [cited by examiner]
US 20210051002A1 · Cheng et al. · 2021 [cited by applicant]
US 20210056547A1 · Monica et al. · 2021 [cited by applicant]
NIST, “Security Requirements for Cryptographic Modules,” Federal Information Processing Standards Publication (FIPS PUB 140-2), National Institute of Standards and Technology, Issued May 25, 2001, 69 pages. [cited by applicant]
Cited By (1)
US 12,732,360