IP Library › Granted Patent US 12,500,875
Granted Patent B2
US 12,500,875 · App. 18/764,683 · Granted Dec 16, 2025

System and method for two way trust between an external key management system and a cloud computing infrastructure

Inventors: Apurv Awasthi (Woodinville, WA); Frederick Anthonisamy Bosco (Redmond, WA); Bharat Shivram (Delhi, IN); Madhu Manjunath (Bengaluru, IN); Deepak Kumar (Bengaluru, IN); Raj Miglani (Lucknow, IN); Akshay Mall (Lucknow, IN); Mayank Bajpai (Bengaluru, IN); Jun Tong (Seattle, WA); Mukesh Shah (Bengaluru, IN); Mauruthi Geetha Mohan (Seattle, WA)
Assignee: Oracle International Corporation
H04L63/062H04L9/0825H04L9/0866H04L9/0894
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,500,875
App. No.
18/764,683
Granted
Dec 16, 2025
Kind
B2
Abstract

An identity service in a cloud environment is communicatively coupled to a proxy key vault in the cloud environment and to an external key manager (EKM) located outside of the cloud environment. The identity service receives a token request for a communication credential from the proxy key vault and verifies the request based on a client credential associated with the proxy key vault. The identity service generates the client credential and signs the communication credential with a private key associated with the EKM. The identify service transmits the signed communication credential to the proxy key vault. The communication credential can be used to substantiate cryptographic operation requests to the EKM.

Claims (89)

1 . One or more non-transitory computer readable media comprising instructions which, when executed by one or more hardware processors, cause performance of operations comprising:

receiving, by an identity service from a proxy key vault, a token request for a communication credential, wherein the token request is substantiated based at least on a client credential stored in association with the proxy key vault, wherein the proxy key vault is located within a cloud computing environment;

verifying, by the identity service, the client credential, wherein verifying the client credential comprises:

determining, by the identity service, that the proxy key vault is associated with a client application implemented by the identity service;

verifying that the client credential is associated with the client application associated with the proxy key vault;

responsive to verifying the client credential, generating, by the identity service, the communication credential, wherein generating the communication credential comprises:

identifying, by the identity service, a resource application implemented by the identity service that has a mapping with the client application;

retrieving, by the identity service, a private key of a public/private key pair associated with the resource application;

signing, by the identity service, the communication credential using the private key; and

transmitting, by the identity service to the proxy key vault, the communication credential;

wherein the communication credential is used to substantiate cryptographic operation requests to an external key manager mapped to the resource application, wherein the external key manager is located outside of the cloud computing environment.

2 . The non-transitory media of claim 1 , the operations further comprising:

creating, by the identity service, the resource application, wherein the resource application is associated with the external key manager wherein configured to access an external hardware device configured to store external cryptographic keys;

creating, by the identity service, the client application, wherein the client application is associated with the client credential;

creating, by the identity service, a mapping between the resource application and one or more client applications comprising the client application; and

creating, by a key management service (KMS), the proxy key vault, wherein creating the proxy key vault comprises storing the client credential in association with the proxy key vault.

3 . The non-transitory media of claim 1 , the operations further comprising:

receiving, by the proxy key vault, a first request to perform a cryptographic operation using an external cryptographic key;

obtaining, by the proxy key vault, the communication credential generated by the identity service; and

transmitting, by the proxy key vault to the external key manager, a second request to perform the cryptographic operation using the external cryptographic key, wherein the second request is substantiated based at least on the communication credential.

4 . The non-transitory media of claim 3 , wherein obtaining the communication credential comprises retrieving, by the proxy key vault, the communication credential from a cache.

5 . The non-transitory media of claim 4 , the operations further comprising:

determining at least one of: that the communication credential in the cache is expired or that the cache does not contain a communication credential; and

responsive to the determining, requesting, by the proxy key vault, a second communication credential from the identity service.

6 . The non-transitory media of claim 3 , the operations further comprising:

receiving, by the identity service from the external key manager, a third request for a public key of the public/private key pair associated with the resource application;

responsive to verifying, by the identity service, that the resource application is mapped to the client application, transmitting the public key; and

receiving, by the proxy key vault, encrypted or decrypted data based on performance of the cryptographic operation using the external cryptographic key.

7 . The non-transitory media of claim 1 , further comprising a second client application implemented by the identity service and mapped to the resource application; and wherein the client application is mapped to a first vault of a cloud computing entity and the second client application is mapped to a second vault of the cloud computing entity.

8 . The non-transitory media of claim 1 , wherein the client credential comprises at least one of a client application identifier and a client secret.

9 . A method comprising:

receiving, by an identity service from a proxy key vault, a token request for a communication credential, wherein the token request is substantiated based at least on a client credential stored in association with the proxy key vault, wherein the proxy key vault is located within a cloud computing environment;

verifying, by the identity service, the client credential, wherein verifying the client credential comprises:

determining, by the identity service, that the proxy key vault is associated with a client application implemented by the identity service;

verifying that the client credential is associated with the client application associated with the proxy key vault;

responsive to verifying the client credential, generating, by the identity service, the communication credential, wherein generating the communication credential comprises:

identifying, by the identity service, a resource application implemented by the identity service that has a mapping with the client application;

retrieving, by the identity service, a private key of a public/private key pair associated with the resource application;

signing, by the identity service, the communication credential using the private key; and

transmitting, by the identity service to the proxy key vault, the communication credential;

wherein the communication credential is used to substantiate cryptographic operation requests to an external key manager mapped to the resource application, wherein the external key manager is located outside of the cloud computing environment; and

wherein the method is performed by at least one device including a hardware processor.

10 . The method of claim 9 , further comprising:

creating, by the identity service, the resource application, wherein the resource application is associated with the external key manager wherein configured to access an external hardware device configured to store external cryptographic operation keys;

creating, by the identity service, the client application, wherein the client application is associated with the client credential;

creating, by the identity service, a mapping between the resource application and one or more client applications comprising the client application; and

creating, by a key management service (KMS), the proxy key vault, wherein creating the proxy key vault comprises storing the client credential in association with the proxy key vault.

11 . The method of claim 9 , further comprising:

receiving, by the proxy key vault, a first request to perform a cryptographic operation using an external cryptographic key;

obtaining, by the proxy key vault, the communication credential generated by the identity service; and

transmitting, by the proxy key vault to the external key manager, a second request to perform the cryptographic operation using the external cryptographic key, wherein the second request is substantiated based at least on the communication credential.

12 . The method of claim 11 , wherein obtaining the communication credential comprises retrieving, by the proxy key vault, the communication credential from a cache.

13 . The method of claim 12 , further comprising:

determining at least one of: that the communication credential in the cache is expired or that the cache does not contain a communication credential; and

responsive to the determining, requesting, by the proxy key vault, a second communication credential from the identity service.

14 . The method of claim 11 , further comprising:

receiving, by the identity service from the external key manager, a third request for a public key of the public/private key pair associated with the resource application;

responsive to verifying, by the identity service, that the resource application is mapped to the client application, transmitting the public key; and

receiving, by the proxy key vault, encrypted or decrypted data based on performance of the cryptographic operation using the external cryptographic key.

15 . A system comprising:

at least one device including a hardware processor;

the system being configured to perform operations comprising:

receiving, by an identity service from a proxy key vault, a token request for a communication credential, wherein the token request is substantiated based at least on a client credential stored in association with the proxy key vault, wherein the proxy key vault is located within a cloud computing environment;

verifying, by the identity service, the client credential, wherein verifying the client credential comprises:

determining, by the identity service, that the proxy key vault is associated with a client application implemented by the identity service;

verifying that the client credential is associated with the client application associated with the proxy key vault;

responsive to verifying the client credential, generating, by the identity service, the communication credential, wherein generating the communication credential comprises:

identifying, by the identity service, a resource application implemented by the identity service that has a mapping with the client application;

retrieving, by the identity service, a private key of a public/private key pair associated with the resource application;

signing, by the identity service, the communication credential using the private key; and

transmitting, by the identity service to the proxy key vault, the communication credential;

wherein the communication credential is used to substantiate cryptographic operation requests to an external key manager mapped to the resource application, wherein the external key manager is located outside of the cloud computing environment.

16 . The system of claim 15 , the operations further comprising:

creating, by the identity service, the resource application, wherein the resource application is associated with the external key manager wherein configured to access an external hardware device configured to store external cryptographic operation keys;

creating, by the identity service, the client application, wherein the client application is associated with the client credential;

creating, by the identity service, a mapping between the resource application and one or more client applications comprising the client application; and

creating, by a key management service (KMS), the proxy key vault, wherein creating the proxy key vault comprises storing the client credential in association with the proxy key vault.

17 . The system of claim 15 , the operations further comprising:

receiving, by the proxy key vault, a first request to perform a cryptographic operation using an external cryptographic key;

obtaining, by the proxy key vault, the communication credential generated by the identity service; and

transmitting, by the proxy key vault to the external key manager, a second request to perform the cryptographic operation using the external cryptographic key, wherein the second request is substantiated based at least on the communication credential.

18 . The system of claim 17 , wherein obtaining the communication credential comprises retrieving, by the proxy key vault, the communication credential from a cache.

19 . The system of claim 18 , the operations further comprising:

determining at least one of: that the communication credential in the cache is expired or that the cache does not contain a communication credential; and

responsive to the determining, requesting, by the proxy key vault, a second communication credential from the identity service.

20 . The system of claim 17 , the operations further comprising:

receiving, by the identity service from the external key manager, a third request for a public key of the public/private key pair associated with the resource application;

responsive to verifying, by the identity service, that the resource application is mapped to the client application, transmitting the public key; and

receiving, by the proxy key vault, encrypted or decrypted data based on performance of the cryptographic operation using the external cryptographic key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2024
From: AWASTHI, APURAV; BOSCO, FREDERICK ANTHONISAMY; SHIVRAM, BHARAT; MANJUNATH, MADHU; KUMAR, DEEPAK; MIGLANI, RAJ; MALL, AKSHAY; BAJPAI, MAYANK; TONG, JUN; SHAH, MUKESH; MOHAN, MAURUTHI GEETHA
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 068037/0861 →
Continuity (2)
Provisional Application 63525105 · Jul 5, 2023
Related Publication 20250015977A1 · Jan 9, 2025
References Cited (21)
US 9569630B2 · Cabrera et al. · 2017 [cited by applicant]
US 10956600B2 · Ye et al. · 2021 [cited by applicant]
US 11575508B2 · Anand et al. · 2023 [cited by applicant]
US 11652616B2 · Zee et al. · 2023 [cited by applicant]
US 20170006119A1 · Pogrebinsky et al. · 2017 [cited by applicant]
US 20190132299A1 · Tucker · 2019 [cited by examiner]
US 20190354692A1 · Thoram et al. · 2019 [cited by applicant]
US 20210036851A1 · Villapakkam · 2021 [cited by examiner]
US 20210218722A1 · Gaylor · 2021 [cited by examiner]
US 20210368514A1 · Xing · 2021 [cited by applicant]
US 20220271929A1 · Villapakkam · 2022 [cited by examiner]
WO 2019212773A1 · 2019 [cited by applicant]
“Cloud External Key Manager,” Retrieved from https://cloud.google.com/kms/docs/ekm, Mar. 4, 2024, pp. 5. [cited by applicant]
“External Key Management for AWS by T-Systems, AWS Premier Consulting and Security Competency Partner,” Retrieved from https://www.t-systems.com/resource/blob/565764/35be2fbd609320ec590eea9c5fbdf592/DL-Flyer-External-Ke… [cited by applicant]
“External key stores,” Retrieved from https://docs.aws.amazon.com/kms/latest/developerguide/keystore-external.html, Mar. 4, 2024, pp. 16. [cited by applicant]
“Integrating Skyhigh CASB On-Prem Proxy with aKey Management Server,” Retrieved from https://success. skyhighsecurity.com/Skyhigh_CASB/Skyhigh_CASB_Settings/On-Prem_Proxy/zIntegrating_MVISION_Cloud_On-Prem_Proxy_with_a_… [cited by applicant]
“Key Management Interoperability Protocol (KMIP),” Retrieved from https://www.encryptionconsulting.com/education-center/kmip/#:˜:text=KMIP%20is%20an%20extensible%20communication,by%20simplifying%20encryption%20key%20man… [cited by applicant]
“Sepior's Cloud Encryption Technology Now Supports Key Management Interoperability Protocol (KMIP),” Sepior, Nov. 10, 2017, pp. 4. [cited by applicant]
“StorMagic-SvKMS-Data-Sheet,” Retrieved from https://stormagic.com/pdf/data-sheet/StorMagic-SvKMS-Data-Sheet.pdf, 2023, pp. 4. [cited by applicant]
Microsoft Learn, “Azure Key Vault REST API reference”, Apr. 19, 2023, Available online at <https://learn.microsoft.com/en-us/rest/api/keyvault/>, 12 pages. [cited by applicant]
Microsoft Learn: “Connect to a Key Vault via private endpoint—Code Samples”, Jul. 6, 2022, Available online at <https://learn.microsoft.com/en-us/samples/azure/azure-quickstart-templates/key-vault-private-endpoint/>, 5 … [cited by applicant]