EP4148554A1

Multiple authority data security and access

Abstract

Data is encrypted such that multiple keys are needed to decrypt the data. The keys are accessible to different entities so that no single entity has access to all the keys. At least one key is managed by a service provider. A customer computer system of the service provider may be configured with executable instructions directing the orchestration of communications between the various entities having access to the keys. As a result, security compromise in connection with a key does not, by itself, render the data decryptable.

EP4148554A1, drawing sheet 1
Sheet 1 of 12

Term

7.7 yearsto projected expiry

Projected expiry 16 June 2034, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

15 claims: 11 independent, 4 dependent

  1. 1
    A computer-implemented method for multiple authority data security and access, comprising:receiving, from a customer of a computing resource service provider, a request to perform one or more operations using a managed key that is inaccessible to the customer, the request indicating a key identifier that enables the computing resource service provider to select the managed key from other keys managed on behalf of customers of the computing resource service provider;providing, in response to the request and to the customer, an encrypted data key that is encrypted at least under the managed key: receiving, from the customer, data encrypted under at least the data key;and storing, at a data storage service operated by the computing resource service provider, the encrypted data key and the data encrypted under the at least the data key, to store, in persistent storage, the encrypted data key and the data encrypted under the at least the data key, wherein a customer key that is inaccessible to the computing resource service provider and the managed key that is inaccessible to the customer are collectively sufficient, but individually insufficient, to access the data in plaintext form from the persistent storage due to the encrypted data key being encrypted at least in part under the managed key.
  2. 4
    The computer-implemented method of any preceding claim, wherein the encrypted data key and the data encrypted under the data key are transmitted to the data storage service by an application programming interface request to the data storage service.
  3. 5
    The computer-implemented method of any preceding claim, wherein the request is a first application programming interface call to a cryptography service and the encrypted data key and the data encrypted under the at least the data key is transmitted to the data storage service by a second application programming interface call.
  4. 6
    The computer-implemented method of any preceding claim, wherein the data key is generated by the customer.
  5. 7
    The computer-implemented method of any preceding claim, further comprising:receiving, from the customer, a request to decrypt the encrypted data key, the request to decrypt the encrypted data key including an identifier of the managed key;and in response to decrypt the encrypted data key, using the managed key to decrypt the encrypted data key and providing the data key to enable the customer to use the data key to decrypt the encrypted data.
  6. 8
    A system for multiple authority data security and access, comprising:a first service that includes one or more first processors and first memory including first instructions that, as a result of execution by the one or more first processors, cause the first service to: receive a first request, from a customer of a computing resource service provider, to perform one or more operations using a managed key that is inaccessible to the customer, the request indicating a key identifier that enables the computing resource service provider to select the managed key from other keys managed by the first service on behalf of customers of the computing resource service provider;and provide to the customer an encrypted data key that is encrypted at least under the managed key;and a second service that includes one or more second processors and second memory including second instructions that, as a result of execution by the one or more second processors, cause the second service to: receive a second request, from the customer, to store data encrypted under at least the data key;and in response to the second request, store, in persistent storage, the encrypted data key and the data encrypted under at least the data key, wherein the data storage service is unable to decrypt the data encrypted under at least the data key without a customer key that is inaccessible to the data storage service.
  7. 11
    The system of any of claims 8-10, wherein the first instructions further cause the first service to:receive a request to decrypt the encrypted data key, the request including an identifier of the managed key;and use the managed key to decrypt the encrypted data key and provide the data key in response to the request.
  8. 12
    The system of any of claims 8-11, wherein the first request comprises additional authenticated data.
  9. 13
    The system of any of claims 8-12, wherein the first service is a cryptography service to which application programming interface calls to perform cryptographic operations can be submitted.
  10. 14
    The system of any of claims 8-13, wherein the customer is unable to decrypt the data encrypted under at least the data key without the managed key.
  11. 15
    The system of any of claims 8-14, wherein the computing resource service provider lacks access to the customer key.