Revocable shredding of security credentials
Abstract
Customers accessing resources and/or data in a multi-tenant environment can obtain assurance that a provider of that environment will honor only requests associated with the customer. A multi-tenant cryptographic service can be used to manage cryptographic key material and/or other security resources in the multi-tenant environment. The cryptographic service can provide a mechanism in which the service can receive requests to use the cryptographic key material to access encrypted customer data, export key material out of the cryptographic service, destroy key material managed by the cryptographic service, among others. Such an approach can enable a customer to manage key material without exposing the key material outside a secure environment.
Claims
exact text as granted — not AI-modifiedWat is claimed is:
1 . A computer implemented method, comprising:
encrypting a cryptographic key with a restore key and encrypting metadata with the restore key to generate an encrypted cryptographic key and encrypted metadata; sending the encrypted cryptographic key and the encrypted metadata; receiving a copy of the encrypted cryptographic key and a copy of the encrypted metadata; and determining whether to authorize a restore request based at least in part on comparing the copy of the encrypted metadata with the encrypted metadata.
2 . The computer implemented method of claim 1 , further comprising:
storing, in a data store managed by a key management service, the cryptographic key for use in encrypting data for a customer of a service provider associated with the cryptographic key, the key management service being operated in a service provider environment of the service provider, the cryptographic key associated with the metadata.
3 . The computer implemented method of claim 1 , further comprising:
updating the metadata with audit information indicating at least one of a customer initiating a suspend request or a time of initiating the suspend request.
4 . The computer implemented method of claim 1 , further comprising:
receiving a suspend request to suspend storage of the cryptographic key; generating the restore key. retaining a copy of the encrypted metadata; and destroying any copy of the cryptographic key.
5 . The computer implemented method of claim 1 , further comprising:
receiving a restore request to cause to store a copy of the cryptographic key, the restore request including the copy of the encrypted cryptographic key and the copy of the encrypted metadata; decrypting the copy of the encrypted cryptographic key using the restore key to generate a local copy of the cryptographic key; and making available the local copy of the cryptographic key to a customer to perform one or more operations using the local copy of the cryptographic key.
6 . The computer implemented method of claim 1 , further comprising:
sending the encrypted cryptographic key to a first customer; and sending the encrypted metadata to a second customer.
7 . A computing system, comprising:
at least one processor; and memory including instructions that, when executed by the at least one processor, cause the computing system to: encrypt a cryptographic key with a restore key and encrypt metadata with the restore key to generate an encrypted cryptographic key and encrypted metadata; send the encrypted cryptographic key and the encrypted metadata; receive a copy of the encrypted cryptographic key and a copy of the encrypted metadata; and determine whether to authorize a restore request based at least in part on comparing the copy of the encrypted metadata with the encrypted metadata.
8 . The computing system of claim 7 , wherein the instructions, when executed, further cause the computing system to:
receive a restore request to cause to store a copy of the cryptographic key, the restore request including the copy of the encrypted cryptographic key and the copy of the encrypted metadata; and send a notification to a customer.
9 . The computing system of claim 8 , wherein the instructions, when executed, further cause the computing system to:
decrypt the copy of the encrypted cryptographic key using the restore key at an expiration of a predetermined period of time.
10 . The computing system of claim 7 , wherein the instructions, when executed, further cause the computing system to:
flag the encrypted cryptographic key as pending deletion; and destroy any copy of the cryptographic key when an acknowledgment of receipt of the encrypted cryptographic key is received; or provide a copy of the encrypted cryptographic key when a determined amount of time passes before the acknowledgment of receipt is received.
11 . The computing system of claim 7 , wherein the instructions, when executed, further cause the computing system to:
encrypt the restore key using a second restore key at an expiration of an interval of time; and send a copy of the restore key encrypted under the second restore key; or receive the copy of the encrypted cryptographic key, decrypt the encrypted cryptographic key, and encrypt the cryptographic key using the second restore key.
12 . The computing system of claim 7 , wherein the instructions, when executed, further cause the computing system to:
encrypt the restore key under a second restore key; send the encrypted cryptographic key to a primary account; send a copy of the restore key encrypted under the second restore key to a secondary account; receive the copy of the encrypted cryptographic key from the primary account; receive the copy of the restore key encrypted under the second restore key from the secondary account; restore the restore key encrypted under the second restore key using a second key; and restore the encrypted cryptographic key using the restore key.
13 . The computing system of claim 7 , wherein the instructions, when executed, further cause the computing system to:
store, in a data store managed by a key management service, the cryptographic key for use in encrypting data for a customer of a service provider associated with the cryptographic key, the key management service being operated in a service provider environment of the service provider, the cryptographic key associated with the metadata.
14 . A non-transitory computer-readable storage medium including instructions that, when executed by at least one processor of a computing device, cause the computing device to:
encrypt a cryptographic key with a restore key and encrypt metadata with the restore key to generate an encrypted cryptographic key and encrypted metadata; send the encrypted cryptographic key and the encrypted metadata; receive a copy of the encrypted cryptographic key and a copy of the encrypted metadata; and determine whether to authorize a restore request based at least in part on comparing the copy of the encrypted metadata with the encrypted metadata.
15 . The non-transitory computer-readable storage medium of claim 14 , wherein the instructions, when executed further enable the computing device to:
receive a restore request to cause to store a copy of the cryptographic key, the restore request including the copy of the encrypted cryptographic key and the copy of the encrypted metadata; and send a notification to a customer.
16 . The non-transitory computer-readable storage medium of claim 14 , wherein the instructions, when executed further enable the computing device to:
decrypt the copy of the encrypted cryptographic key using the restore key at an expiration of a predetermined period of time.
17 . The non-transitory computer-readable storage medium of claim 14 , wherein the instructions, when executed further enable the computing device to:
flag the encrypted cryptographic key as pending deletion; and destroy any copy of the cryptographic key when an acknowledgment of receipt of the encrypted cryptographic key is received; or provide a customer a copy of the encrypted cryptographic key when a determined amount of time passes before the acknowledgment of receipt is received.
18 . The non-transitory computer-readable storage medium of claim 14 , wherein the instructions, when executed further enable the computing device to:
encrypt the restore key using a second restore key at an expiration of an interval of time; and send a copy of the restore key encrypted under the second restore key; or receive the copy of the encrypted cryptographic key, decrypt the encrypted cryptographic key, and encrypt the cryptographic key using the second restore key.
19 . The non-transitory computer-readable storage medium of claim 14 , wherein the instructions, when executed further enable the computing device to:
encrypt the restore key under a second restore key; send the encrypted cryptographic key to a primary account; send a copy of the restore key encrypted under the second restore key to a secondary account; receive the copy of the encrypted cryptographic key from the primary account; receive the copy of the restore key encrypted under the second restore key from the secondary account; restore the restore key encrypted under the second restore key using a second key; and restore the encrypted cryptographic key using the restore key.
20 . The non-transitory computer-readable storage medium of claim 14 , wherein the instructions, when executed further enable the computing device to:
update the metadata with audit information indicating at least one of a customer initiating a suspend request or a time of initiating the suspend request.Join the waitlist — get patent alerts
Track US2018167381A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.