US2023021749A1PendingUtilityA1

Wrapped Keys with Access Control Predicates

Assignee: GOOGLE LLCPriority: Dec 10, 2019Filed: Oct 3, 2022Published: Jan 26, 2023
Est. expiryDec 10, 2039(~13.4 yrs left)· nominal 20-yr term from priority
H04L 9/0877H04L 9/3213H04L 9/0866H04L 9/0822H04L 9/0825H04L 63/101H04L 9/0897H04L 63/06H04L 2463/062H04L 63/0815
60
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for wrapped keys with access control predicates includes obtaining a cryptographic key for content. The method also includes encrypting the content using the cryptographic key and generating an encryption request. The encryption request requests that a third party cryptography service encrypts an encapsulation of the cryptographic key and an access control condition governing access to the content. The method also includes communicating the encryption request to the third party cryptography service. The encryption request includes the cryptographic key.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A computer-implemented method when executed by data processing hardware causes the data processing hardware to perform operations comprising:
 retrieving encrypted content;   receiving, from a service provider, an authentication token for a user, the authentication token indicating that the user is authorized to use one or more services of a key manager;   sending, to the key manager, a key request for a cryptographic key stored at the key manager, the key request comprising:
 the authentication token; and 
 one or more properties to be evaluated against a control condition; 
   responsive to the key manager determining that the user is authorized based on the authentication token and the one or more properties, receiving the cryptographic key from the key manager; and   decrypting the encrypted content using the cryptographic key.   
     
     
         2 . The method of  claim 1 , wherein the key manager comprises a key service manager (KSM) of a distributed storage system. 
     
     
         3 . The method of  claim 1 , wherein the key manager comprises a hardware security module (HSM) device of a distributed storage system. 
     
     
         4 . The method of  claim 1 , wherein the control condition requires authentication from an entity remote from the key manager. 
     
     
         5 . The method of  claim 1 , wherein the operations further comprise:
 obtaining new content;   encrypting the new content using the cryptographic key; and   communicating, to the key manager, a wrapping request requesting that the key manager wraps the cryptographic key.   
     
     
         6 . The method of  claim 5 , wherein the key manager wraps the cryptographic key using a key encryption key (KEK). 
     
     
         7 . The method of  claim 1 , wherein the control condition comprises a dynamic access control condition requiring at least two properties to satisfy the dynamic access control condition. 
     
     
         8 . The method of  claim 7 , wherein the at least two properties are chained together to satisfy the dynamic access control condition. 
     
     
         9 . The method of  claim 1 , wherein the authentication token comprises a JavaScript object notation (JSON) web token. 
     
     
         10 . The method of  claim 9 , wherein the JSON web token comprises a signature based on a public key infrastructure (PKI) certificate. 
     
     
         11 . A system comprising:
 data processing hardware; and   memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:
 retrieving encrypted content; 
 receiving, from a service provider, an authentication token for a user, the authentication token indicating that the user is authorized to use one or more services of a key manager; 
 sending, to the key manager, a key request for a cryptographic key stored at the key manager, the key request comprising:
 the authentication token; and 
 one or more properties to be evaluated against a control condition; 
 
 responsive to the key manager determining that the user is authorized based on the authentication token and the one or more properties, receiving the cryptographic key from the key manager; and 
 decrypting the encrypted content using the cryptographic key. 
   
     
     
         12 . The system of  claim 11 , wherein the key manager comprises a key service manager (KSM) of a distributed storage system. 
     
     
         13 . The system of  claim 11 , wherein the key manager comprises a hardware security module (HSM) device of a distributed storage system. 
     
     
         14 . The system of  claim 11 , wherein the control condition requires authentication from an entity remote from the key manager. 
     
     
         15 . The system of  claim 11 , wherein the operations further comprise:
 obtaining new content;   encrypting the new content using the cryptographic key; and   communicating, to the key manager, a wrapping request requesting that the key manager wraps the cryptographic key.   
     
     
         16 . The system of  claim 15 , wherein the key manager wraps the cryptographic key using a key encryption key (KEK). 
     
     
         17 . The system of  claim 11 , wherein the control condition comprises a dynamic access control condition requiring at least two properties to satisfy the dynamic access control condition. 
     
     
         18 . The system of  claim 17 , wherein the at least two properties are chained together to satisfy the dynamic access control condition. 
     
     
         19 . The system of  claim 11 , wherein the authentication token comprises a JavaScript object notation (JSON) web token. 
     
     
         20 . The system of  claim 19 , wherein the JSON web token comprises a signature based on a public key infrastructure (PKI) certificate.

Join the waitlist — get patent alerts

Track US2023021749A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.