IP Library Granted Patent US 11,943,341
Granted Patent B2
US 11,943,341 · App. 17/222,720 · Granted Mar 26, 2024

Contextual key management for data encryption

Inventors: Mark Ian Gargett (Brighton, GB); Shashank Visweswara (Crawley, GB); Wayne Helm Gibson (Crawley, GB); David Paul Webb (Seaford, GB)
Assignee: McAfee, LLC
H04L9/083G06F21/62
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,943,341
App. No.
17/222,720
Granted
Mar 26, 2024
Kind
B2
Abstract

Example methods, apparatus, systems and articles of manufacture (e.g., physical storage media) to implement contextual key management for data encryption are disclosed. Example apparatus disclosed are to determine whether a key mapping is associated with a combination of two or more context rules defined for a set of context values associated with input data to be encrypted. Disclosed example apparatus are also to, in response to a determination that no key mapping is associated with the combination of two or more context rules, map a key identifier to the combination of two or more context rules and generate a key corresponding to the key identifier. Disclosed example apparatus are further to encrypt the input data based on the key to obtain encrypted data.

Claims (53)

1. An apparatus to perform contextual encryption key management, the apparatus comprising:

memory;

computer readable instructions; and

processor circuitry to execute the computer readable instructions to at least:

in response to a request to encrypt first input data, parse the first input data to determine a combination of two or more context values from the first input data;

determine that the combination of two or more context values was not detected in second input data that was encrypted previously;

in response to the combination of two or more context values not being detected in the second input data that was previously encrypted, map a key identifier to a combination of two or more context rules corresponding to the combination of two or more context values, and generate a key corresponding to the key identifier; and

encrypt the first input data based on the key to obtain encrypted data.

2. The apparatus of claim 1 , wherein the processor circuitry is to associate the key identifier with the encrypted data.

3. The apparatus of claim 2 , wherein the processor circuitry is to include the key identifier in header information of the encrypted data to associate the key identifier with the encrypted data.

4. The apparatus of claim 2 , wherein the processor circuitry is to include the key identifier in metadata associated with the encrypted data to associate the key identifier with the encrypted data.

5. The apparatus of claim 1 , wherein the encrypted data is first encrypted data, and the processor circuitry is to:

store the key and a map of the key identifier to the combination of two or more context rules in the memory;

determine that the combination of two or more context rules is associated with third input data to be encrypted after encryption of the first input data based on the key;

retrieve the key from the memory based on the map of the key identifier to the combination of two or more context rules; and

encrypt the third input data based on the key to obtain second encrypted data.

6. The apparatus of claim 5 , wherein the processor circuitry is to:

include the key identifier in header information of the first encrypted data to associate the first encrypted data with the key identifier; and

include the key identifier in header information of the second encrypted data to associate the second encrypted data with the key identifier.

7. The apparatus of claim 1 , wherein the key is a first key, and individual ones of the two or more context rules are mapped to respective keys different from the first key.

8. A non-transitory computer readable storage medium comprising computer readable instructions to cause one or more processors to at least:

in response to a request to encrypt first input data, parse the first input data to determine a combination of two or more context values from the first input data;

determine that the combination of two or more context values was not detected in second input data that was encrypted previously;

in response to the combination of two or more context values not being detected in the second input data that was previously encrypted, map a key identifier to a combination of two or more context rules corresponding to the combination of two or more context values, and generate a key corresponding to the key identifier; and

encrypt the first input data based on the key to obtain encrypted data.

9. The storage medium of claim 8 , wherein the instructions cause the one or more processors to associate the key identifier with the encrypted data.

10. The storage medium of claim 9 , wherein the instructions cause the one or more processors to include the key identifier in header information of the encrypted data to associate the key identifier with the encrypted data.

11. The storage medium of claim 9 , wherein the instructions cause the one or more processors to include the key identifier in metadata associated with the encrypted data to associate the key identifier with the encrypted data.

12. The storage medium of claim 8 , wherein the encrypted data is first encrypted data, and the instructions cause the one or more processors to:

store the key and a map of the key identifier to the combination of two or more context rules in memory;

determine that the combination of two or more context rules is associated with third input data to be encrypted after encryption of the first input data based on the key;

retrieve the key from the memory based on the map of the key identifier to the combination of two or more context rules; and

encrypt the third input data based on the key to obtain second encrypted data.

13. The storage medium of claim 12 , wherein the instructions cause the one or more processors to:

include the key identifier in header information of the first encrypted data to associate the first encrypted data with the key identifier; and

include the key identifier in header information of the second encrypted data to associate the second encrypted data with the key identifier.

14. The storage medium of claim 8 , wherein the key is a first key, and individual ones of the two or more context rules are mapped to respective keys different from the first key.

15. A method comprising:

parsing input data to be encrypted, the parsing to determine a combination of two or more context values from the input data;

mapping a first key identifier to a first context rule defined for a first one of the two or more context values, and generating a first key corresponding to the first key identifier;

mapping a second key identifier to a second context rule defined for a second one of the two or more context values, and generating a second key corresponding to the second key identifier;

mapping a third key identifier to a combination of context rules defined for the combination of two or more context values, and generating a third key corresponding to the third key identifier, the combination of context rules including the first context rule and the second context rule; and

encrypting the input data based on the third key to obtain encrypted data.

16. The method of claim 15 , further including associating the third key identifier with the encrypted data.

17. The method of claim 16 , wherein the third key identifier is included in header information of the encrypted data to associate the third key identifier with the encrypted data.

18. The method of claim 15 , wherein the input data is first input data, the encrypted data is first encrypted data, and further including:

storing the third key and a map of the third key identifier to the combination of context rules in memory;

determining that the combination of context rules is associated with second input data to be encrypted after encryption of the first input data based on the third key;

retrieving the third key from the memory based on the map of the third key identifier to the combination of context rules; and

encrypting the second input data based on the third key to obtain second encrypted data.

19. The method of claim 18 , wherein:

the third key identifier is included in header information of the first encrypted data to associate the first encrypted data with the third key identifier; and

the third key identifier is included in header information of the second encrypted data to associate the second encrypted data with the third key identifier.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2021
From: GARGETT, MARK IAN; VISWESWARA, SHASHANK; GIBSON, WAYNE HELM; WEBB, DAVID PAUL
To: MCAFEE, LLC
Reel/Frame 056174/0950 →
Continuity (2)
Continuation 16050972 · Jul 31, 2018
Related Publication 20210226778A1 · Jul 22, 2021