IP Library › Granted Patent US 12,238,210
Granted Patent B2
US 12,238,210 · App. 17/686,757 · Granted Feb 25, 2025

Keystore service for encryption in a secure service enclave

Inventors: Kranthi Kumar Bathula (Sammamish, WA); Nachiketh Rao Potlapally (McLean, VA); Rakesh Basanta Parida (Sammamish, WA); Ricky Alan Mangus (Bellevue, WA)
Assignee: Oracle International Corporation
H04L9/0894H04L9/0822H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,238,210
App. No.
17/686,757
Granted
Feb 25, 2025
Kind
B2
Abstract

The present embodiments relate to a keystore service for encryption for a computing device of a cloud computing system. The computing device of the cloud computing system can receive a key identification, an encrypted key encryption key, an identity of a client device, and a request from the client device to store the key identification and the encrypted key identification key. The computing device can verify, based at least in part on the identity, an authority of the client device to store the key identification and encrypted key encryption key. The computing device can transmit, based at least in part on the verification, the key identification, the encrypted key encryption key, and request to store the key identification and the encrypted key encryption key to a keystore.

Claims (70)

1. A computer-implemented method, the method comprising:

receiving, by a computing device of a cloud computing system, a key identification, an encrypted key-encryption key, an identity of a client device, and a request from the client device to store the key identification and the encrypted key-encryption key, wherein the encrypted key-encryption key is generated by encrypting a key-encryption key;

verifying, by a control plane of the computing device, the request based at least in part on:

validating the identity of the client device, and

validating whether the client device is authorized to store the key identification and encrypted key-encryption key;

transmitting, by the control plane of the computing device and based at least in part on verifying the request, the key identification, the encrypted key-encryption key, and the request to store the key identification and the encrypted key-encryption key to a keystore,

wherein a logical sequence number is generated based on the request to store the key identification and the encrypted key-encryption key;

polling, by a data plane of the computing device, the keystore for the logical sequence number and the encrypted key-encryption key;

reading, by the data plane of the computing device and in response to detecting the logical sequence number, the key identification and the encrypted key-encryption key from the keystore;

storing, by the data plane of the computing device, the logical sequence number, the key identification, and the encrypted key-encryption key in a storage of the computing device; and

transmitting, by the data plane of the computing device, the stored logical sequence number to the keystore.

2. The computer-implemented method of claim 1 , wherein verifying the authority of the client device comprises:

receiving, by a control plane of the computing device, the identity of the client device; and

verifying, by the control plane of the computing device, the authority of the client device by comparing the identity of the client device to a list of authorized client devices.

3. The computer-implemented method of claim 1 , wherein reading the key identification and the encrypted key-encryption key from the keystore comprises reading the key identification and the encrypted key-encryption key from a write ahead log of the keystore based at least in part on the logical sequence number.

4. The computer-implemented method of claim 3 , wherein:

polling the keystore for the logical sequence number comprises: responsive to detecting a new logical sequence number, reading, by the data plane, the write ahead log for a newest logical sequence number, an associated key identifier, and an associated encrypted key-encryption key; and

the method further comprises:

storing, by the data plane, in a local storage of the data plane, the newest logical sequence number, the associated key identifier, and the associated encrypted key-encryption key; and

publishing, by the data plane, the newest logical sequence number to the keystore.

5. The computer-implemented method of claim 4 , comprising

in response to a control plane write instruction:

incrementing the logical sequence number; and

writing, to the write ahead log, the incremented logical sequence number, the key identifier, and the encrypted key-encryption key.

6. The computer-implemented method of claim 1 , wherein the key identification, the encrypted key-encryption key, and the request to store the key identification and the encrypted key-encryption key to the keystore are received from the client device via a domain name system.

7. The computer-implemented method of claim 6 , wherein the domain name system selects the computing device based on a round-robin format.

8. The computer-implemented method of claim 1 , wherein:

the client device uses the key-encryption key to encrypt one or more encryption keys.

9. The computer-implemented method of claim 8 , comprising:

storing an encrypted file at the client device, the encrypted file being encrypted an encryption key of the one or more encryption keys.

10. The computer-implemented method of claim 1 , wherein:

the encrypted key-encryption key is generated by encrypting the key-encryption key using a second encryption key.

11. The computer-implemented method of claim 10 , comprising:

generating the second encryption key at the client device; and

generating the encrypted key-encryption key by encrypting the key-encryption key at the client device using the second encryption key.

12. A cloud infrastructure node, comprising:

a processor; and

a non-transitory computer-readable medium including instructions that, when executed by the processor, cause the processor to:

receive, by a computing device of a cloud computing system, a key identification, an encrypted key-encryption key, an identity of a client device, and a request from the client device to store the key identification and the encrypted key-encryption key, wherein the encrypted key-encryption key is generated by encrypting a key-encryption key;

verify, by a control plane of the computing device, the request based at least in part on:

validating the identity of the client device, and

validating whether the client device is authorized to store the key identification and encrypted key-encryption key;

transmit, by the control plane of the computing device and based at least in part on verifying the request, the key identification, the encrypted key-encryption key, and the request to store the key identification and the encrypted key-encryption key to a keystore,

wherein a logical sequence number is generated based on the request to store the key identification and the encrypted key-encryption key;

poll, by a data plane of the computing device, the keystore for the logical sequence number and the encrypted key-encryption key;

read, by the data plane of the computing device and in response to detecting the logical sequence number, the key identification and the encrypted key-encryption key from the keystore;

store, by the data plane of the computing device, the logical sequence number, the key identification, and the encrypted key-encryption key in a storage of the computing device; and

transmit, by the data plane of the computing device, the stored logical sequence number to the keystore.

13. The cloud infrastructure node of claim 12 , wherein verifying the authority of the client device comprises:

receiving, by a control plane of the cloud infrastructure node, the identity of the client device; and

verifying, by the control plane of the cloud infrastructure node, the authority of the client device by comparing the identity of the client device to a list of authorized client devices.

14. The cloud infrastructure node of claim 12 , wherein reading the key identification and the encrypted key-encryption key from the keystore comprises reading the key identification and the encrypted key-encryption key from a write ahead log of the keystore based at least in part on the logical sequence number.

15. The cloud infrastructure node of claim 12 , wherein the key identification, the encrypted key-encryption key, and the request to store the key identification and the encrypted key-encryption key to the keystore are received from the client device via a domain name system.

16. The cloud infrastructure node of claim 15 , wherein the domain name system selects the cloud infrastructure node based on a round-robin format.

17. A non-transitory computer-readable medium having stored thereon a sequence of instructions which, when executed by a processor, causes the processor to perform operations comprising:

receiving, by a computing device of a cloud computing system, a key identification, an encrypted key-encryption key, an identity of a client device, and a request from the client device to store the key identification and the encrypted key-encryption key, wherein the encrypted key-encryption key is generated by encrypting a key-encryption key;

verifying, by a control plane of the computing device, the request based at least in part on;

validating the identity of the client device, and

validating whether the client device is authorized to store the key identification and encrypted key-encryption key;

transmitting, by the control plane of the computing device and based at least in part on verifying the request, the key identification, the encrypted key-encryption key, and the request to store the key identification and the encrypted key-encryption key to a keystore,

wherein a logical sequence number is generated based on the request to store the key identification and the encrypted key-encryption key;

polling, by a data plane of the computing device, the keystore for the logical sequence number and the encrypted key-encryption key;

reading, by the data plane of the computing device and in response to detecting the logical sequence number, the key identification and the encrypted key-encryption key from the keystore;

storing, by the data plane of the computing device, the logical sequence number, the key identification, and the encrypted key-encryption key in a storage of the computing device; and

transmitting, by the data plane of the computing device, the stored logical sequence number to the keystore.

18. The non-transitory computer-readable medium of claim 17 , wherein verifying the authority of the client device comprises:

receiving, by a control plane of a cloud infrastructure node, the identity of the client device; and

verifying, by the control plane the cloud infrastructure node, the authority of the client device by comparing the identity of the client device to a list of authorized client devices.

19. The non-transitory computer-readable medium of claim 17 , wherein reading the key identification and the encrypted key-encryption key from the keystore comprises reading the key identification and the encrypted key-encryption key from a write ahead log of the keystore based at least in part on the logical sequence number.

20. The non-transitory computer-readable medium of claim 17 , wherein the key identification, the encrypted key-encryption key, and the request to store the key identification and the encrypted key-encryption key to the keystore are received from the client device via a domain name system.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF INVENTOR TO RICKY ALAN MANGUS PREVIOUSLY RECORDED ON REEL 059186 FRAME 0895. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 17, 2022
From: BATHULA, KRANTHI KUMAR; POTLAPALLY, NACHIKETH RAO; PARIDA, RAKESH BASANTA; MANGUS, RICKY ALAN
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 059423/0849 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2022
From: BATHULA, KRANTHI KUMAR; POTLAPALLY, NACHIKETH RAO; PARIDA, RAKESH BASANTA; MANGUS, RICK
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 059186/0895 →
Continuity (1)
Related Publication 20230283465A1 · Sep 7, 2023
References Cited (17)
US 20200053065A1 · Wisniewski · 2020 [cited by examiner]
US 20200394648A1 · Blackshear · 2020 [cited by examiner]
US 20210051002A1 · Cheng · 2021 [cited by examiner]
US 20220200791A1 · Le Roux · 2022 [cited by examiner]
US 20230291558A1 · Lin · 2023 [cited by examiner]
CN 102646077B · 2016 [cited by applicant]
CN 109255231A · 2019 [cited by applicant]
CN 109977039B · 2021 [cited by applicant]
Configuring External Key Management, Available Online at: https://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.pow-nve%2FGUID-DD718B42-038D-4009-84FF-20BBD6530BC2.html, Accessed from Internet on Sep. 2, 202… [cited by applicant]
Disk Encryption and Key Management with Vault Enterprise, Available Online at: https://www.datocms-assets.com/2885/1595526264-disk-encryption-and-key-management-with-vault-brief.pdf, Aug. 12, 2020, 2 pages. [cited by applicant]
Encryption at Rest, Security Guide—Chapter 14, Available Online at: https://docs.marklogic.com/guide/security/encryption, Accessed from Internet on Sep. 2, 2021, pp. 1-28. [cited by applicant]
How Amazon EMR Uses AWS KMS, Available Online at: https://docs.aws.amazon.com/kms/latest/developerguide/services-emr.html, Accessed from Internet on Sep. 2, 2021, pp. 1-5. [cited by applicant]
Moving Encryption Keys to External Storage, Available Online at: https://www.jetico.com/file-downloads/web_help/bcve4/html/04_usage/01_volume_encryption/05_moving_keys.htm, Accessed from Internet on Aug. 31, 2021, pp. 1… [cited by applicant]
Storage Management, IBM, Available Online at: https://www.ibm.com/docs/de/spp/10.1.7?topic=reference-storage-management, Accessed from Internet on Aug. 31, 2021, pp. 1-6. [cited by applicant]
Arora, HashiCorp Vault as an External Key Manager for NetApp Encryption, Available Online at: https://medium.com/hashicorp-engineering/hashicorp-vault-as-an-external-key-manager-for-netapp-encryption-7794297f6df1, Mar. … [cited by applicant]
Lanfear, Azure Disk Encryption for Windows and Linux IaaS VMs, Available Online at: https://github.com/uglide/azure-content/blob/master/articles/azure-security-disk-encryption.md, Accessed from Internet on Aug. 31, 2021… [cited by applicant]
Shinder et al., Secure Client Deployment with Trusted Boot and BitLocker, Available Online at: https://www.sciencedirect.com/science/article/pii/B9781597499804000091, 2013, pp. 239-265. [cited by applicant]