首页> 外国专利> Remote key encryption key management in a collaborative cloud based environment

Remote key encryption key management in a collaborative cloud based environment

机译:基于协作云的环境中的远程密钥加密密钥管理

摘要

Content item 402 indicated by content request 401 is encrypted using a CEK (content encryption key) 404. The CEK is encrypted using a local KEK (key encryption key), e.g. at server 100 (fig. 1). A reason code is determined which enumerates the reason for the request. A remote key encryption request 406 is initiated, typically to a remote key service engine 420 at a client 102 (fig. 1), which includes the once-encrypted KEK and the reason code. Preferably, a twice-encrypted key, encrypted with a remote KEK, is returned in response and stored locally 415 with the local and remote KEKs and encrypted data item 403. Subsequent access (see fig. 4B) to the item identifies a reason code which enumerates the reason for that request. The twice-encrypted key is accessed from the data store and a remote key decryption request initiated which includes the twice-encrypted key, reason code and remote KEK. Preferably, the once-encrypted key, decrypted using the remote KEK, is returned in response and decrypted locally using the local KEK. The CEK can then be used to decrypt the item. A remote key request is accepted or rejected based on a set of preconfigured rules and the reason.
机译:由内容请求401指示的内容项402使用CEK(内容加密密钥)404进行加密。使用本地KEK(密钥加密密钥)例如通过加密将CEK加密。在服务器100上(图1)。确定原因码,该原因码列举了请求的原因。通常向客户端102处的远程密钥服务引擎420(图1)发起远程密钥加密请求406,该请求包括一次加密的KEK和原因码。优选地,作为响应,返回用远程KEK加密的两次加密密钥,并将其与本地和远程KEK以及加密数据项403一起本地存储415。随后对该项的访问(见图4B)标识了原因码,列举该请求的原因。从数据存储区访问两次加密的密钥,并启动一个远程密钥解密请求,该请求包括两次加密的密钥,原因码和远程KEK。优选地,使用远程KEK解密的曾经加密过的密钥作为响应被返回并且使用本地KEK在本地解密。然后可以使用CEK解密项目。根据一组预配置的规则和原因,接受或拒绝远程密钥请求。

著录项

  • 公开/公告号GB2507191A

    专利类型

  • 公开/公告日2014-04-23

    原文格式PDF

  • 申请/专利权人 BOX INC.;

    申请/专利号GB20130018373

  • 发明设计人 ANDY KIANG;CHRIS BYRON;JEFF QUEISSER;

    申请日2013-10-17

  • 分类号G06F21/62;G06F21/60;H04L9/08;H04L9/14;H04L29/06;

  • 国家 GB

  • 入库时间 2022-08-21 15:35:48

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号