IP Library › Granted Patent US 12,457,093
Granted Patent B2
US 12,457,093 · App. 18/155,256 · Granted Oct 28, 2025

QSL—data at rest

Inventors: Christopher Cap (Bayville, NJ); Barry Van Hooser (Pleasanton, CA)
Assignee: QuSecure, Inc
H04L9/0631G06F21/64H04L9/083H04L9/0852
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,093
App. No.
18/155,256
Granted
Oct 28, 2025
Kind
B2
Abstract

A method to allow a client to communicate with a server, specifically to conduct a key management service, in order to obtain encryption/decryption keys for data-at-rest, wherein the method comprises: causing the client to use Authenticated Encryption with Associated Data (AEAD) to encrypt data according to a moving target design and causing the client, at a later time, to use AEAD to check the integrity of the data and decrypt the data according to the moving target design.

Claims (17)

1 . A method to allow a client to communicate with a server, specifically to conduct a key management service, in order to obtain encryption/decryption keys for data-at-rest, wherein the method comprises: causing the client to use Authenticated Encryption with Associated Data (AEAD) to encrypt data according to a moving target design; and

causing the client, at a later time, to use AEAD to check the integrity of the data and decrypt the data according to the moving target design, wherein the method further comprising: using a symmetric encryption algorithm with the bits-of-security reduced to one half of the classical value to provide at least 128 bits-of-security against a quantum attacker.

2 . The method according to claim 1 , wherein the method further comprising: using a hashing algorithm with the bits-of-security reduced to one half of the classical value to provide at least 128 bits-of-security against a quantum attacker.

3 . The method according to claim 1 , wherein the symmetrical encryption algorithm is a post-quantum symmetric encryption block cipher.

4 . The method according to claim 3 , wherein the post-quantum symmetric encryption block cipher outputs an EVP CIPHER initialized to aes_256_ctr.

5 . The method according to claim 3 , wherein the post-quantum symmetric encryption block cipher outputs an EVP CIPHER initialized to aes_256_gcm.

6 . A system comprising:

at least one processor, at least one computer-readable memory, and at least one computer-readable, tangible storage device wherein:

the at least one processor communicates with at least one outside processor to allow a client to communicate with a server, specifically to conduct a key management service, in order to obtain encryption/decryption keys for data-at-rest, wherein the system comprises:

a client computing device is configured to:

cause the client to use Authenticated Encryption with Associated Data (AEAD) to encrypt data according to a moving target design; and

cause the client, at a later time, to use AEAD to check the integrity of the data and decrypt the data according to the moving target design, wherein the client computing device is configured to:

use a symmetric encryption algorithm with the bits-of-security reduced to one half of the classical value to provide at least 128 bits-of-security against a quantum attacker.

7 . The system according to claim 6 , wherein the client computing device is configured to: use a hashing algorithm with the bits-of-security reduced to one half of the classical value to provide at least 128 bits-of-security against a quantum attacker.

8 . The system according to claim 6 , wherein the symmetrical encryption algorithm is a post-quantum symmetric encryption block cipher.

9 . The system according to claim 8 , wherein the post-quantum symmetric encryption block cipher outputs an EVP CIPHER initialized to aes_256_ctr.

10 . The system according to claim 8 , wherein the post-quantum symmetric encryption block cipher outputs an EVP CIPHER initialized to aes_256_gcm.

Continuity (2)
Provisional Application 63319322 · Mar 13, 2022
Related Publication 20230291545A1 · Sep 14, 2023
References Cited (2)
WO WO2022182911A1 · 2022 [cited by examiner]
Authors: Gallagher et al., “Morpheus: A Vulnerability-Tolerant Secure Architecture Based on Ensembles of Moving Target Defenses with Church”, Publisher: Association for Computing Machinery; ISBN: 978-1-4503-6240-5/19/04… [cited by examiner]