Encryption key management for international data residency
Abstract
Problem to be solved.To provide a medium, a method and a system for providing encryption key management for international data residence. An organization using a group-based communication system should store a specific geopolitical area in which the organization's data can be stored and an encryption key used to encrypt and decrypt the data. You can specify different geopolitical areas (which may be the same or different). Users of the organization can post messages to the group-based communication system or access previously posted messages from any geopolitical area, which allows the system to come from the appropriate area. Messages and encryption keys can be automatically stored and retrieved, giving users transparent access to group-based communication systems while maintaining security and data residency requirements. [Selection diagram] Fig. 1A

Term
14 yearsto projected expiry
Projected expiry 8 October 2040, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
20 claims: 5 independent, 15 dependent
- 1プロセッサによって実行されるとき、国際データレジデンシのための暗号化キー管理を提供するための方法を実行する、コンピュータで実行可能な命令を記憶した1つもしくは複数の非一時性コンピュータ可読媒体であって、前記方法は、第1の地政学的領域に位置するユーザから、組織に関連付けられたグループベース通信システムに投稿されるメッセージを受信するステップと、前記組織に基づいて、前記組織に 関連付けられたデータのレジデンシとして、第2の地政学的領域が判別されたことに応答して、前記第2の地政学的領域に配置されたキーサーバに、暗号化キーの要求を送信するステップであって、前記第2の地政学的領域は、前記第1の地政学的領域とは異なる、ステップと、前記第2の地政学的領域に配置された前記キーサーバから、組織特有の暗号化キーを受信するステップと、前記組織特有の暗号化キーを使用して、前記メッセージを暗号化するステップと、暗号化メッセージを、前記第2の地政学的領域の第2のデータストレージに記憶するステップと、前記暗号化メッセージのストレージ位置を識別する情報を、前記第1の地政学的領域に前記暗号化メッセージを記憶することなく、前記第1の地政学的領域の第1のデータストレージに記憶するステップと、を含む、非一時性コンピュータ可読媒体。
- 2前記キーサーバから前記組織特有のキーを受信する前記ステップは、前記組織特有のキーが前記第1の地政学的領域のキーキャッシュに存在しないと判別されたことに応答する、請求項1記載の媒体。
- 3前記組織特有のキーは、前記組織に関係付けられたキー階層のサブキーである、請求項1記載の媒体。
- 4前記組織のための前記キー階層は、マスタ組織キー、ワークスペースキー、チャネルキーおよびセッションキーを含み、前記メッセージを暗号化するために使用される前記組織特有のキーは、前記セッションキーである、請求項3記載の媒体。
- 5前記第2の地政学的領域の前記第2のデータストレージは、前記組織に関連付けられた検索インデクスを記憶する、請求項1記載の媒体。
- 6前記第2の地政学的領域の前記第2のデータストレージは、前記組織のロギングデータを記憶する、請求項1記載の媒体。
- 7前記方法は、前記暗号化メッセージを、前記第1の地政学的領域の前記第1のデータストレージに、所定のキャッシュ期間だけ、キャッシュするステップをさらに含む、請求項1記載の媒体。
- 8国際データレジデンシのための暗号化キー管理を提供するための方法であって、前記方法は、組織に関連付けられたグループベース通信システムに投稿された暗号化メッセージへのアクセスをユーザが試行したという指標をクライアントデバイスから受信するステップと、前記暗号化メッセージのストレージ位置を識別する情報を、第1の地政学的領域の第1のデータストレージから取得するステップであって、前記暗号化メッセージの前記ストレージ位置を識別する前記情報は、前記暗号化メッセージが第2の地政学的領域の第2のデータストレージに記憶されていることを示しており、前記第2の地政学的領域は、前記第1の地政学的領域とは異なる、ステップと、前記暗号化メッセージを、前記第2の地政学的領域の前記第2のデータストレージから取得するステップと、前記暗号化メッセージに関連付けられた復号化キーが前記第1の地政学的領域のキーキャッシュに記憶されていないと判別されたことに応答して、前記復号化キーを、第3の地政学的領域に配置されたキーサーバから取得するステップであって、前記第3の地政学的領域は、前記第1の地政学的領域とは異なる、ステップと、プレーンテキストメッセージを取得するために、前記復号化キーを使用して前記暗号化メッセージを復号化するステップと、前記ユーザに表示するために、前記プレーンテキストメッセージを前記クライアントデバイスに送信するステップと、を含む、方法。
- 9暗号化メッセージにアクセスする前記ユーザの試行の前記指標は、前記グループベース通信システムのグループを閲覧するための、該グループの前記ユーザによる選択を含む、請求項8記載の方法。
- 10前記第3の地政学的領域は、前記第2の地政学的領域とは異なる、請求項8記載の方法。
- 11前記プレーンテキストメッセージを前記クライアントデバイスに送信する前記ステップは、トランスポート層の暗号化を使用して、前記プレーンテキストメッセージを前記クライアントデバイスに送信することを含む、請求項8記載の方法。
- 12前記クライアントデバイスは、前記第1の地政学的領域にある、請求項8記載の方法。
- 13前記組織特有のキーは、前記組織に関係付けられたキー階層のサブキーであり、前記組織のための前記キー階層は、マスタ組織キー、ワークスペースキー、チャネルキーおよびセッションキーを含み、メッセージを暗号化するために使用される前記組織特有のキーは、前記セッションキーである、請求項8記載の方法。
- 14前記第2の地政学的領域の前記第2のデータストレージは、前記組織に関連付けられた検索インデクスを記憶する、請求項8記載の方法。
- 15プロセッサによって実行されるとき、国際データレジデンシのための暗号化キー管理を提供するための方法を実行する、コンピュータで実行可能な命令を記憶した1つもしくは複数の非一時性コンピュータ可読媒体であって、前記方法は、組織に関連付けられたグループベース通信システムに投稿された暗号化メッセージにアクセスする試行の指標を、第2の地政学的領域のクライアントデバイスから受信するステップと、前記暗号化メッセージのストレージ位置を前記第2の地政学的領域の第2のデータストレージとして識別する、前記暗号化メッセージに関連付けられた情報に基づいて、第1の地政学的領域の第1のデータストレージから、前記暗号化メッセージに関連付けられた情報を取得するステップであって、前記第2の地政学的領域は、前記第1の地政学的領域とは異なる、ステップと、前記暗号化メッセージを、前記第2の地政学的領域の前記第2のデータストレージから取得するステップと、前記暗号化メッセージに関連付けられた組織特有の復号化キーを、第3の地政学的領域に配置されたキーサーバから取得するステップであって、前記第3の地政学的領域は、前記第1の地政学的領域とは異なる、ステップと、プレーンテキストメッセージを取得するために、前記組織特有の復号化キーを使用して前記暗号化メッセージを復号化するステップと、ユーザに表示するために、前記プレーンテキストメッセージを前記クライアントデバイスに送信するステップと、を含む、非一時性コンピュータ可読媒体。
- 16前記第1の地政学的領域は、前記第3の地政学的領域と同じである、請求項15記載の媒体。
- 17前記第2の地政学的領域は、前記第3の地政学的領域と同じである、請求項15記載の媒体。
- 18前記組織特有のキーは、前記組織に関連付けられたキー階層のサブキーである、請求項15記載の媒体。
- 19前記組織のための前記キー階層は、マスタ組織キー、ワークスペースキー、チャネルキーおよびセッションキーを含み、メッセージを復号化するために使用される前記組織特有のキーは、前記セッションキーである、請求項18記載の媒体。
- 20前記暗号化メッセージへのアクセスの前記試行の指標は、前記プレーンテキストメッセージが検索結果となる、グループベース通信システムでの検索を実行することを含む、請求項15記載の媒体。
Independent claims20
58 paragraphs, as filed
Embodiments of the invention are generally based on the management of cryptographic keys for international data residency, and more specifically, the requirements for storing data and / or key materials in a particular geopolitical area. A technique for retrieving and storing encrypted messages.
Traditionally, data for group-based communication systems is stored in a central location by the provider of the group-based communication system, regardless of the organization that uses the group-based communication system. However, some organizations want to store sensitive data in specific geopolitical areas in order to meet legal, rule or political constraints. At the same time, some organizations want to store their data in encrypted form to protect their privacy from potential intruders. However, due to the combination of managed encryption keys and geopolitical data storage constraints, traditionally per geopolitical area where data is stored in order to maintain consistency and latency at acceptable levels. A separate system was needed. The result is inefficient and unnecessary resource duplication. Therefore, there is a need for systems that enable customer-managed encryption keys and customer-specified data residency, while enabling central access points for coordination and interaction.
An embodiment of the invention allows a group to store and retrieve encrypted messages in any geopolitical area using similarly managed keys in any geopolitical area. The above need is addressed by providing technology that enables a central first access point for the base communication system. In particular, in a first embodiment, the invention stores a computer-executable instruction that, when executed by a processor, performs a method for providing cryptographic key management for international data residency. One or more non-transitory computer-readable media, the method is a step of receiving a message posted to a channel-based communication system associated with an organization from a user located in a first geopolitical area. And, based on the organization, as a residency of the data associated with the organization, in response to the determination of the second geopolitical area, the encryption to the key server located in the second geopolitical area. The step of sending the encryption key request, the second geopolitical area is different from the first geopolitical area, from the step and the key server located in the second geopolitical area. A step to receive an organization-specific encryption key, a step to encrypt a message using an organization-specific encryption key, and a second data storage in a second geopolitical area. The steps to store and the information that identifies the storage location of the encrypted message are stored in the first data storage of the first geopolitical area without storing the encrypted message in the first geopolitical area. Includes non-temporary computer-readable media, including steps.
In a second embodiment, the invention is a method for providing cryptographic key management for international data residency, the method being a cryptographic posting to a group-based communication system associated with an organization. The step of receiving an indicator from the client device that the user has attempted to access the encrypted message, and the step of retrieving the information that identifies the storage location of the encrypted message from the first data storage in the first geopolitical area. And the information identifying the storage location of the encrypted message indicates that the encrypted message is stored in the second data storage of the second geopolitical area, and the second geopolitical The domain is different from the first geopolitical domain, the steps to retrieve the encrypted message from the second data storage in the second geopolitical domain, and the decryption associated with the encrypted message. In the step of retrieving the decryption key from the key server located in the third geopolitical area in response to the determination that the key is not stored in the key cache of the first geopolitical area. There, the third geopolitical area is different from the first geopolitical area, the step and the step of decrypting the encrypted message using the decryption key to get the plain text message. Includes a method, including, and a step of sending a plain text message to a client device for display to the user.
In a third embodiment, the invention is one that stores computer-executable instructions that, when executed by a processor, perform a method for providing cryptographic key management for international data residency. Alternatively, multiple non-transitory computer-readable media, the method presents an indicator of an attempt to access an encrypted message posted to a group-based communication system associated with an organization, a client in the second geopolitical domain. A first geopolitical area based on the information associated with the encrypted message, identifying the steps received from the device and the storage location of the encrypted message as the second data storage in the second geopolitical area. The second geopolitical area is different from the first geopolitical area, which is the step of retrieving the information associated with the encrypted message from the first data storage of the step and the encrypted message. From the second data storage in the second geopolitical area, and the organization-specific decryption key associated with the encrypted message from the key server located in the third geopolitical area. The third geopolitical area, which is the step to acquire, is different from the first geopolitical area, and is encrypted using the step and the organization-specific decryption key to acquire the plain text message. Includes non-transitory computer-readable media, including a step of decrypting a encrypted message and a step of sending a plain text message to a client device for display to the user.
This overview is provided to introduce in a simplified form the selection of concepts further described in the detailed description below. This summary is not intended to identify the material features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter. No. Other aspects and advantages of the invention will become apparent from the following detailed description of embodiments and accompanying drawings.
Embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
<figref num="1A">It is a figure which shows the exemplary hardware platform of the specific embodiment of this invention.</figref><figref num="1B">It is an exemplary figure which shows the component of the system for carrying out the embodiment of this invention.</figref><figref num="2">It is a flowchart which shows the operation of the method for storing the encrypted message in the designated geopolitical area by embodiment of this invention.</figref><figref num="3">It is a swim lane diagram which shows the flow of responsibility of the element of the process for storing an encrypted message in the designated geopolitical area according to the embodiment of this invention.</figref><figref num="4">It is a flowchart showing the operation of the method for accessing the encrypted message stored in the designated geopolitical area.</figref><figref num="5A">It is a figure which collectively shows the swimlane diagram which shows the flow of the responsibility of the element of processing for accessing the encrypted message stored in the designated geopolitical area by embodiment of this invention.</figref><figref num="5B">It is a figure which collectively shows the swimlane diagram which shows the flow of the responsibility of the element of processing for accessing the encrypted message stored in the designated geopolitical area by embodiment of this invention.</figref>
The drawings do not limit the invention to the particular embodiments disclosed and described herein. The drawings are not necessarily full scale, but instead the emphasis is on clearly explaining the principles of the invention.
At a high level, embodiments of the present invention make it possible to store and retrieve encrypted messages in any geopolitical area using similarly managed keys in any geopolitical area. On the other hand, it provides a technology that enables a central primary access point for group-based communication systems. In some embodiments, the group-based communication system is a channel-based messaging platform. These techniques, and the exemplary environment in which they are performed, are described in more detail below.
Although the subject matter of embodiments of the present invention is described in detail below to meet legal requirements, the specification itself is not intended to limit the scope of the claims. Rather, the claimed subject matter, along with other current or future techniques, can be embodied in other ways, including different steps or combinations of steps similar to those described herein. The minor variations from the following description are obvious to those skilled in the art and are intended to be captured within the scope of the claimed invention. The term should not be construed as meaning any particular order of the various steps described, unless the order of the individual steps is explicitly stated.
The following detailed description of embodiments of the invention will refer to the accompanying drawings showing specific embodiments in which the invention is feasible. This embodiment is intended to explain aspects of the invention in sufficient detail so that those skilled in the art can practice the invention. Other embodiments are available and modifications can be made without departing from the scope of the invention. Therefore, the following detailed description should not be construed in a limited sense. The scope of the embodiments of the present invention is defined only by the appended claims, along with the full scope of the equivalents to which the claims are entitled.
As used herein, reference to "one embodiment," "one embodiment," or "embodiment" includes one or more features referred to in at least one embodiment of the art. Means that. Separate references to "one embodiment," "one embodiment," or "embodiments" herein do not necessarily refer to the same embodiment, and unless otherwise stated. And / or not mutually exclusive, except as readily apparent to those of skill in the art from the specification. For example, the features, structures or functions described in one embodiment may be included in other embodiments, but are not essential. Accordingly, the art can include various combinations and / or integrations of embodiments described herein.
First, with reference to FIG. 1A, an exemplary hardware platform for a particular embodiment of the invention is shown. The computer 102 may be any other form factor for desktop computers, laptop computers, server computers, mobile devices such as smartphones and tablets, or general purpose or special purpose computing devices. For purposes of illustration, computer 102 shows several components. In some embodiments, the particular components may or may not be arranged differently. There may also be additional components. The computer 102 includes a system bus 104, which allows other components of the computer 102 to communicate with each other. In certain embodiments, there may be multiple buses, or the components may communicate directly with each other. A central processing unit (CPU) 106 is connected to the system bus 104. Further, one or a plurality of random access memory (RAM) modules 108 are connected to the system bus 104. A graphic card 110 is connected to the system bus 104. In some embodiments, the graphics card 110 may be integrated into a motherboard or CPU 106 rather than a physically separate card. In some embodiments, the graphics card 110 has a separate graphics processing unit (GPU) 112, which GPU 112 may be used for graphics processing or general purpose computing (GPGPU). The graphic card 110 also has a GPU memory 114. A display 116 for user dialogue is connected (directly or indirectly) to the graphics card 110. In some embodiments, the display is absent, in other embodiments the display is embedded in the computer 102. Similarly, peripherals such as keyboard 118 and mouse 120 can be found on System Bus 1. It is connected to 04. Like the display 116, these peripherals may or may not be built into the computer 102. A local storage 122 is also connected to the system bus 104, and the local storage 122 may be any form of computer-readable medium, and even if it is installed inside the computer 102, it can be removed externally. It may be attached.
Computer-readable media include both volatile and non-volatile media, removable and non-removable media, and may be media readable by a database. For example, computer-readable media include RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROMs, digital versatile disks (DVDs), holographic media or other optical disc storage, magnetic cassettes, magnetic tapes, magnetics. Examples include, but are not limited to, disk storage and other magnetic storage devices. These techniques can store data temporarily or permanently. However, unless explicitly specified, the term "computer-readable medium" is a physical but temporary form of signal transmission, such as radio broadcasting, electrical signals over wires, or optical pulses over fiber optic cables. Should not be construed as containing. Examples of stored information include computer-enabled instructions, data structures, program modules, and other data representations.
Finally, the network interface card (NIC) 124 is also attached to the system bus 104, allowing the computer 102 to communicate over a network such as network 126. NIC124 can be Ethernet, ATM, fiber, Bluetooth, or Wi-Fi (ie IEEE802. It can be any form of network interface known in the art, such as 11 standard families). The NIC 124 connects the computer 102 to the local network 126, which can also include one or more other computers such as the computer 128 and network storage such as the data storage device 130. In general, the data storage such as the data storage device 130 may be any repository that can store and acquire information as needed. Examples of data storage include relational or object-oriented databases, spreadsheets, file systems, flat files, directory services such as LDAP and Active Directory, or email storage systems. Data storage is accessible through complex APIs (eg, structured query languages), simple APIs that provide only read, write, and seek operations, or any level of complexity in between. Some data storages may further provide management functions for datasets stored in the data storage, such as backup and versioning. The data storage may be local to a single computer such as computer 128, accessible on a local network such as local network 126, or remotely accessible via the internet 132. There may be. The local network 126 is then connected to the internet 132, which in turn connects many networks such as the local network 126, the remote network 134, or a directly connected computer such as the computer 136. In some embodiments, the computer 102 itself may be directly connected to the internet 132. It is connected to many networks such as computers. In some embodiments, the computer 102 itself may be directly connected to the internet 132. It is connected to many networks such as computers. In some embodiments, the computer 102 itself may be directly connected to the internet 132.
Next, with reference to FIG. 1B, an exemplary diagram showing the components of the system for carrying out the embodiments of the present invention is shown, which is referenced in its entirety by reference number 150. The system 150 comprises a plurality of computers such as the computer 102 and data storage such as the data storage device 130. As shown, the components of the system 150 are located in two separate geopolitical areas, the component to the left of the dashed line is the first geopolitical area and the component to the right is the second. It is located in the geopolitical area. For example, the first geopolitical territory may be the United States and the second geopolitical territory may be the European Union. Alternatively, the first geopolitical area may be California and the second geopolitical area may be Virginia. In some embodiments, the components of the system may be present in more than one geopolitical area. For example, the first set of components of the system 150 may be located in the United States, the second set in the European Union, and the third set in the Russian Federation. Embodiments of the invention are particularly useful when different geopolitical areas have different laws regarding data storage, privacy and retention. For example, an organization constructed under the law of a first geopolitical territory may be required (or may preferentially memorize) to store such data in that geopolitical territory. However, embodiments of the present invention are conceivable across any set of geopolitical areas.
The first client device 152 is located in the first geopolitical area. For the sake of brevity here, the first geopolitical area is the United States, but one of ordinary skill in the art will understand that it may be any other geopolitical area. Alternatively, the first client may be located in a second geopolitical area or a third geopolitical area (not shown). In general, the client device 152 may be any type of computer device described above with respect to FIG. 1, but in typical embodiments, the first client device 152 may be a desktop computer, laptop computer, smartphone, or the like. It may be a mobile device of. The first client device 152 allows the user to interact with the group-based communication system. In some embodiments, the first client device 152 may execute software dedicated to the group-based communication system. In another embodiment, the user can access the group-based communication server by visiting the website using the web browser of the first client device 152. Although only a single client device is illustrated in the first geopolitical domain, a group-based communication system may have a large number of users in any given geopolitical domain. Each of the users can access the group-based communication system from any number of client devices. In some embodiments, the group-based communication system is a channel-based messaging platform.
In addition, a group-based communication server 154 is located in the first geopolitical area. The group-based communication server is communicably connected to the first client device 152 over a network such as network 126 or internet 132, and the various client devices of the user post the message to the group. Can be exchanged. The group-based communication server 154 is also communicably connected to the group-based communication system data storage device 156. In the illustration, the group-based communication server 154 is directly connected to the group-based communication system data storage device 156, but the group-based communication server 154 (eg, the group-based communication system data storage device 156 is network-based storage). An embodiment connected to a group-based communication system data storage device 156 (such as cloud storage) is also conceivable. The group-based communication system data storage device 156 stores a part of data for a group-based communication system, including message data, group (or channel) data, and user data. In particular, the group-based communication system data storage device 156 stores data designated to be stored in the first geopolitical area. For data designated to be stored in a different geopolitical area (such as a second geopolitical area), the group-based communication system data storage device 156 instead uses a pointer to the data or storage of the data. Other information that identifies the location can be stored. As will be described later, a part or all of the data of the group-based communication system data storage device 156 can be stored in an encrypted form. For example, data can be encrypted and stored using customer-managed keys.
Recently used that can decode data in group-based communication system data storage device 156 to reduce the latency associated with fetching a key (eg, if the key is stored in a second geopolitical area). The key can be cached in the key cache 158. For example, the key may remain valid for 5 minutes after being first fetched from the key server. If the same key is needed within that period (for example, to decrypt another message stored in group-based communication system data storage device 156), it is refetched from the key storage (possibly out of region). Instead, it can be retrieved from the key cache 158, which reduces latency. One of skill in the art will appreciate that each key can be cached for a different period of time, and that different keys can only be cached for different lengths of time. Those skilled in the art also have the potential to reduce the latency associated with accessing the key from the key cache and to minimize the increase in cache size (and the time the key is placed outside the specified storage area). You will understand the trade-offs with customer requirements).
Next, referring to the second region, the group-based communication system server 160 in the second region is, in some embodiments, a client located in the second geopolitical area (such as a second client device 168). ) May be similar to the group-based communication system data storage device 156. In other embodiments, the client (such as the first client device 152 and the second client device 168) is a single group-based communication system server (eg, group-based communication system) regardless of the region in which they are located. Communicating with the server 154), the central group-based communication system server stores and retrieves (properly encrypted) message data in the appropriate geopolitical area. In such an embodiment, the group-based communication system server 160 in the second region does not have to face the client, instead the central group-based communication system server is the regional data storage (here, the second region). It may be an interface for interacting with a regional group-based communication system data storage device 162). In some embodiments, the group-based communication system data storage device 162 in the second region further stores tissue and channel metadata. For example, an organization's channel membership data and search index can be stored in a designated area. Similarly, the organization's logging data can be stored in the group-based communication system data storage device 162 in the second region, if specified by the organization.
As mentioned above, certain data can be specified for storage in a particular geopolitical area. The designation may be based on the customer's setting in that particular geopolitical area or the local law associated with the customer. In response to such designation, the group-based communication system with which the client device communicates is the group-based communication system data storage in the appropriate geopolitical area (group-based communication data storage device 156 in the first region or second. Store (and acquire data from) data in, for example, a regional group-based communication system data storage device 162. This process will be examined in detail below.
Also, in the second geopolitical area, there is a key server 164 in the second region and a key data storage device 166 in the second region. Broadly speaking, the key server 164 in the second region manages all aspects of the encryption key for the second geopolitical area. For example, the key server 164 in the second region generates a new encryption key as needed, rotates and revoke the key for the second geopolitical area, and stores the key data in the second region. Stores and retrieves the encryption key with and from 166. In some embodiments, the key server 164 in the second region does not face the client, but rather simply interacts with the appropriate group-based communication system server to provide the required keys and encrypt the data before storage. And decrypt the data at the time of acquisition. In some embodiments, the key used to encrypt a particular data item (eg, a particular message posted to a group-based communication system) is the same geopolitics in which the data item is stored. It is stored in the target area. Therefore, for example, the key for decoding the data stored in the group-based communication system data storage device 162 in the second region is stored in the key data storage device 166 in the second region. In other embodiments, the encrypted data and the corresponding encryption key are stored in separate geopolitical areas. This can be advantageous, for example, to ensure that a single jurisdiction does not have access to the data alone. In some embodiments, there is only a single physical server in a particular geopolitical area that implements the above functions for that geopolitical area. For example, the group-based communication system server 160 in the second region may be the same physical server as the key server 164 in the second region. In some such embodiments, different servers may run on different virtual machines or containers on the same physical server. In other embodiments, different servers can spin up additional group-based communication system servers and / or key servers on demand.
Next, with reference to FIG. 2, a flowchart showing the operation of the method for storing an encrypted message in a designated geopolitical area according to an embodiment of the present invention is illustrated, which is referenced in its entirety by reference number 200. Will be done. The method begins with step 202 in which a user of the group-based communication system posts a message to a group of the group-based communication system. In general, this message may be textual content, a document, an image, a reaction (or approval) to another message, usage information, a change in group membership, or a group-based communication system data storage device 156 or second in the first region. It can be any information that should be shared with the group, such as any other information stored in the group-based communication system data storage, such as the regional group-based communication system data storage device 162. In embodiments of the invention described below, this message is stored in encrypted form. In some embodiments, all messages are stored in encrypted form, in other embodiments, only specific messages are stored in encrypted form. An appropriate encryption key is required to encrypt the message. In some embodiments, this encryption key can be managed by an organization (eg, a company) of which the user is a member. As mentioned above, an organization can specify a geopolitical area where (encrypted) messages are stored and a geopolitical area where encryption keys are managed (these are the same). May be different).
Processing proceeds to check 204, where the group-based communication system checks the local key cache to determine if the required key is stored locally. In some embodiments, the recently used key is local to the group-based communication system server during the cache period (eg, 5 minutes, 10 minutes, 1 hour, 1 day, or any other suitable period). Avoids the need to refetch frequently used keys held in a key cache from another geopolitical area where the keys are managed. This suggests that the principle of spatiotemporal locality suggests that a user who posted a message requiring a particular key is more likely to post a second message requiring the same key at short time intervals. It saves a lot of resources in refetching keys as needed. In some embodiments, the key is flushed from the cache after that period, and in other embodiments, the expired key is flushed from the cache. In yet another embodiment, a fixed size cache holds a fixed number of recently used keys, and when a new key is needed and fetched from the appropriate key server, the old (or expired) key is cleared. Will be done. In some embodiments, when the key is accessed from the cache, the retention period is reset or otherwise extended. In some embodiments where the key expires, the lease of the key may be renewed when the key is accessed from the key cache. If the key cannot exist in the key cache, processing proceeds to step 206, and if the key is found in the cache, processing skips to step 208 instead.
If it is determined in step 206 that the required key does not exist in the key cache, the group-based conversational system server fetches the key from the appropriate key server. In general, a suitable key server does not exist in the same geopolitical area as the group-based conversation system server, but is local if your organization designates your local area as the geopolitical area of your organization's key storage. You can use a key server in the same geopolitical area as the group-based communication system server in. In general, organizations can employ key hierarchies to allow them to manage keys. For example, an organization can have a master organization key, which can be used for authentication per workspace key and then for signature per channel key, with a session key. Can be used to generate (eg, keys that are rotated hourly). Those skilled in the art who have considered the present disclosure will appreciate that any of the various key hierarchies may be employed in the present invention. If desired, the appropriate key server may generate a new key when the group-based conversation system server requests the key. For example, if a session key is adopted every hour and no message has been posted to a particular channel since the session key was rotated, the key is requested using the key generation material stored in the key data storage. It can be generated according to. In some embodiments, multiple keys can be generated depending on the posting of the message. This can be, for example, when a message creates a new workspace or channel.
Then, after the key is generated or retrieved from the key cache, the process proceeds to step 208 and the received message is encrypted with the appropriate key. Those of skill in the art will appreciate that a variety of cryptographic algorithms, including AES, Twofish, Serpent, and Blowfish cryptographic algorithms, can be adopted for this step. In some embodiments, symmetric key encryption is used to encrypt the message, and in other embodiments, asymmetric encryption is used to encrypt the symmetric encryption key used to encrypt the message. Is used. In some embodiments, cryptoblock chains or stream ciphers can be employed to ensure that key reuse does not result in under-spreading of the ciphertext.
Inspection 210 then determines if the area designated by the user's organization for data storage is the same geopolitical area where the group-based conversation system server is located. If they are the same, the process proceeds to step 212, and if they are not the same, the process proceeds to step 214 instead. In embodiments where there is only one group-based conversation system server, the determination is whether the user's organization has designated the geopolitical area corresponding to that single server as the geopolitical area of the data residency. Just inspect. In embodiments where there are multiple group-based conversation system servers, inspection 210 instead locates a master index that indicates where the data was stored, rather than the particular group-based conversation system server with which the user is communicating. Can be compared.
If your organization has specified the geopolitical domain (or master data index) of the group-based conversation system server as the region where your organization's data should be, the encrypted message generated in step 208 will be At step 212, it is stored in the local group-based conversation system data storage. Encrypted metadata may be stored with the encrypted message to identify the appropriate key for decryption. In some embodiments, different keys may be used for each message (or for each subgroup of messages) and stored with the message (encrypted with the appropriate key in the organization's key hierarchy).
If inspection 210 determines that the geopolitical area designated for the organization is different from the first storage area, the encrypted message will instead be due to the geopolitical area specified by the user's organization. Is stored in a group-based communication system data storage (eg, group-based communication system data storage device 162 in a second region). With respect to step 212, as described above, the encrypted metadata may be stored in association with the encrypted message (following the example above, in the group-based communication system data storage device 162 in the second region). ..
Then, in step 216, the pointer (or other information that identifies the storage location of the encrypted message) is stored in the group-based communication system data storage in the first storage area. In this way, the message first looks at the group-based communication system data storage in the first storage area, and if a pointer is found, it uses the position it contains to be in the specified geopolitical area. It can be obtained by retrieving the encrypted message from the group-based conversation system data storage. In some embodiments, encrypted metadata can be stored with a pointer so that key data for decryption can be fetched in parallel with the encrypted message data in order to minimize latency. In some embodiments, newly posted encrypted messages, such as recently used keys, are cached in the first storage area for a given cache period (eg, 5 minutes, 1 hour, or 1 day). It is possible, which allows other channel members to quickly fetch them when they first browse them, without the need for refetching from the specified region.
Next, with reference to FIG. 3, a swimlane diagram showing the flow of responsibility of the processing elements for storing the encrypted message in the designated geopolitical area according to the embodiment of the present invention is shown, which is referenced. The whole is referenced by number 300. For the purposes of FIG. 300, the designated storage area of the user's organization is different from the first area of the group-based communication system server, but this is not required.
The process begins at the user's client device in step 302, where the user composes and posts a message. As mentioned above, the message may be text content, a document, a pictogram / moving pictogram, or any other form of content shared with other users of the group-based communication system. The message is sent to the group-based communication system server via a communication channel established between the software running on the user's client device and the server software of the group-based communication system. In some embodiments, the communication channel here is encrypted using post-transport encryption such as SSL, TLS or HTTPS encryption.
The control then switches to the group-based communication system server that receives the message in step 304. After determining that the message should be encrypted (as specified by the user's organization), the system determines the appropriate key scope for encrypting the message, and in step 306, the message is sent to the key cache. And check the corresponding key. Control is then passed to the key cache.
In some embodiments, as described below, the key cache returns the key as soon as it is in the cache when it receives a key request from the group-based communication system server (step 308) (ie, to step 322). (Skip directly), look-through cache. Otherwise, the key cache is responsible for requesting the key from the appropriate key server (steps 310-320) and then returning the key to the group-based communication system server in step 322. In another embodiment (not shown), the key cache is a lookaside cache, and if the key is not in the cache, the key cache returns a "key not found" indicator, and the group-based communication system server, Responsible for requesting the key from the key server and storing it in the cache. Those skilled in the art who have considered this disclosure will understand how to adapt the following teachings to the use of lookaside caches instead of lookaside caches.
Assuming that the key no longer exists in the cache after receiving the key request in step 308, in step 310 the key cache makes the key request (including the key scope) geopolitical specified by the user's organization. Transfer to the region's key server and control is passed to that key server. At step 312, the key server in the specified geopolitical area receives a key request containing the requested key scope. In some embodiments, the key server has a local key cache similar to the key cache of the first geopolitical area that was first investigated to determine if the desired key was recently requested. be able to. At step 314, the key server gets or generates the requested key, as needed. For example, if the key for a particular channel has been rotated since the last time the message was posted on that channel, it may be necessary to generate a new key. In some embodiments, the encryption key is stored in its own encrypted form. Upon obtaining the requested key, the key server responds to the request with the desired key in step 316. Control can then return to the key cache.
In step 318, a response with the desired key is received in the key cache, and in step 320, the key cache stores the key to expedite future acquisition. As mentioned above, keys can only be cached for a limited period of time. In some embodiments, the key is cached for a fixed period such as 5 minutes, 1 hour, or 1 day. In other embodiments, the key (such as a session key) is cached until its scope expires. Once the key has been added to the cache (or already in the cache), at step 322, the key server can send the requested key data to the group-based communication system server, and then control Return to the server.
At step 324, the group-based communication system server receives the requested key with the appropriate scope. In embodiments that use a look-through cache, the processing (from a group-based communication system server perspective) is the same regardless of whether the key was retrieved directly from the key cache or had to be fetched from the key server. be. The group-based communication system server uses the received key to encrypt the message with the appropriate key in step 326, thereby creating an encrypted version of the message (ie, the ciphertext). Then, in step 328, the group-based communication system server sends a storage request containing an encrypted message to the group-based communication system server (or group-based communication system data storage) in the geopolitical area specified by the user's organization. Send (directly). As mentioned above, the geopolitical area designated for data storage may be the same as or different from the geopolitical area specified by the user's organization for key management.
At step 330, control is passed to the group-based communication system server / data storage in the designated region, where it receives a storage request for encrypted messages. At step 332, the group-based communication system server / data storage in the designated area stores the message in the designated geopolitical area for later retrieval. In some embodiments, the encrypted message is associated and stored with the user's organization (eg, a database shared specifically for that organization). In other embodiments, the encrypted message is stored with other encrypted data so that it is not known which encrypted data message is associated with a particular organization based solely on the encrypted message data.
After step 332 (or at the same time as steps 330,332), control returns to the group-based communication system server . At step 334, the server creates a pointer (or other information that allows access) to the encrypted message stored in the group-based communication system server. In some embodiments, the pointer is created based on the information returned by the group-based communication system server (eg, a unique row identifier). In another embodiment, the pointer is created before the storage request is sent in step 334, and the storage request contains a unique record identifier that allows for later retrieval. In some embodiments, the pointer may include a unique record identifier for the encrypted data, along with a seal of the geopolitical area where the encrypted data is stored. At step 336, the pointer is stored in the data storage of the first group-based communication system so that later messages can be retrieved. For example, a pointer can be stored in a location where an unencrypted message (or an encrypted message pointing to a first geopolitical area as a storage area) is stored and is a pointer rather than message data. Can be included. When the encrypted message data and the pointer to the encrypted message data are stored, the process 300 ends.
Next, with reference to FIG. 4, a flowchart showing the operation of the method for accessing the encrypted message stored in the designated geopolitical area is illustrated, which is referenced in its entirety by reference number 400. First, in step 402, a user using a client device, such as client device 152 or client device 168, associated with the organization is attempting to access the encrypted message. For example, a user may open a specific channel or group that contains a message in the conversation history. In some embodiments, a process similar to process 400 is performed for each message in the conversation history. In other embodiments, the conversation history may include a mixture of encrypted and unencrypted messages. In yet other embodiments, the conversation history may include messages from users associated with different organizations, each configuring its own encryption and data residency policies.
When accessing a message (encrypted or unencrypted), the data record is retrieved from the group-based communication system data storage in the first region. The data record is stored in message data (encrypted or unencrypted) or in a different geopolitical area created as described above in accordance with Method 200 and Process Flow Figure 300. It may contain a pointer to the message data. For the purposes of this discussion, the data record shall contain pointers to message data stored in different geopolitical areas, but for those skilled in the art considering this disclosure, the record may instead be encrypted message data or unencrypted. You will understand how this method can be adapted when it contains encrypted message data.
The process then proceeds to step 404, where the pointer is used to retrieve the encrypted message data from the appropriate group-based conversation system data storage. For example, pointers can be expanded to distinguish between geopolitical regions and record identifiers, as described above. The group-based conversation system server in the first region then uses the record identifier to make a request for the specified geopolitical area to the group-based conversation system server (or directly to the group-based conversation system data storage). May be sent to. The server (or data storage) can then respond with encrypted message data.
The method follows step 406, where the encryption metadata is used to determine the appropriate key scope that can be used to decrypt the encrypted message. For example, encrypted metadata is a unique record identifier contained in the pointer and / or information indicating the type of data stored in the encrypted message (eg, but not limited to, channel posts, user data, etc.). May include shared files and encryption keys, etc.). Alternatively or additionally, the encryption metadata may include a key identifier or information that can be used to determine the key identifier of the decryption key for decrypting the message data. For example, encrypted metadata can include organization identifiers, workspace identifiers, channel identifiers and (part or all) session identifiers (such as time stamps), each of which (or a set of them). It may correspond to the key scope. As a specific example, a particular encrypted message can remember a particular channel key used to protect the session key of the channel. The encrypted metadata for encrypted messages is a unique record identifier, a type field that indicates that the encrypted message is a channel key, key lifetime data for the key, key scope for the key (here the channel identifier), and organization of the key. And can include workspace identifiers. Those skilled in the art who have considered this disclosure will appreciate that various non-sensitive information can be stored as encrypted metadata for a particular encrypted message.
In some embodiments, the encrypted metadata is stored with the encrypted message. In other embodiments, the encrypted metadata is stored with the pointer. In yet another embodiment, the encrypted metadata is determined from the conversation history as needed. For example, the appropriate key scope can be determined by knowing the organization, the channel on which the message was posted, and the time when the message was originally posted. The information may be included in the conversation history so that the encrypted metadata is stored separately from the pointer and the encrypted message data.
Processing then moves to check 408 to determine if the appropriate key exists in the key cache. If the key is in the key cache, the process can be skipped to step 412, otherwise the process proceeds to step 410 instead. At step 410, the group-based communication system server fetches the key corresponding to the previously determined key scope from the key server in the geopolitical area specified by the user's organization into the key storage. Step 410 is similar to step 206, and the same techniques and variants as described for fetching keys for encryption can be applied to fetching keys for decryption as well.
If the appropriate key is retrieved, or if the appropriate key already exists in the key cache, the process proceeds to step 412, where the encrypted message data is decrypted. Decryption at step 412 is the reverse of encryption at step 208. Those skilled in the art who have considered this disclosure will understand that a decryption algorithm corresponding to the encryption algorithm of step 208 must be employed. In some embodiments, the same key is used for encryption and decryption. In other embodiments, a separate (but corresponding) key is used for encryption and decryption. As with the cryptographic process, any currently known or later developed cryptographic algorithm may be used in the present invention. Finally, in step 414, the decryption message is sent back to the client and displayed to the user. Method 400 may exit at this point or may iteratively decode additional messages for display to the user.
Next, with reference to FIGS. 5A and 5B, a swimlane diagram showing the flow of responsibility of the processing elements for accessing the encrypted message stored in the designated geopolitical area according to the embodiment of the present invention. Is shown, and reference number 500 refers to the whole. Process 500 begins at the client device in step 502, where the client sends a message data request to the group-based communication system server in response to an attempt by the user to access the message. The user's attempt to access the message may be explicit (eg, selecting a message), implicit (eg, accessing the channel containing the message, or viewing the history of the conversation). Scroll to, etc.). In some embodiments, the messages can be decrypted one at a time. In other embodiments, the message can be decrypted in batch. For example, if the user scrolls through the conversation history for a particular channel, the client can send a single request for every message displayed in the client's view pane. Alternatively, the client can request all the messages that are displayed in the view pane, or can request additional messages that should be displayed if the user continues to scroll. Yet another alternative is to request all messages that share a particular key scope (for example, all messages that use the same session key) when the user views the first message using that session key. You can also do it.
Control then transitions to the group-based communication system server in step 504 when the server receives the message request. In some embodiments, the requests for multiple messages in the conversation history may be grouped together into a single request. In some such embodiments, the requests thus grouped are requests for messages encrypted with different keys (eg, messages controlled by different organizations or posted at different times). , Or can include requests for unencrypted messages. Such grouped requests can be deployed and processed individually, and individual or grouped responses can be provided to the client device.
Then, in step 506, the group-based communication system server acquires a data pointer from the local group-based communication system data storage. For example, the message request may include sufficient record identifiers or time stamps and channel indicators to identify the message. As described above, it is assumed that the message to be acquired for the purpose of this embodiment is stored in a geopolitical area different from that of the first group-based communication system server. However, one of ordinary skill in the art will appreciate that the techniques disclosed herein can also be applied when the encrypted message data is stored in the geopolitical domain of the first group-based communication system server. There will be. When the data pointer is retrieved from the data storage, it is used in step 508 as described above in accordance with Figure 4 to generate a request for the specified geopolitical area and the group-based communication system server or data storage. Can be sent to.
Control is then passed to the group-based communication system server / data storage in the second geopolitical area that receives the request in step 510. Based on the information contained in the request (eg, the record identifier corresponding to the encrypted message, as described above for Method 200 and Process 300), the server encrypts from the corresponding data storage in step 512. You can get the message data (or the data storage can get it directly). Finally, in step 514, the server or data storage generates a response message containing the encrypted message data corresponding to the request and sends it to the group-based communication system server in the first geopolitical area for control. Return to the server.
At step 516, the group-based communication system server in the first region receives encrypted message data from the geopolitical area for the data residency specified by the user's organization. Then, in step 518, the group-based communication system server determines the appropriate key scope for the encrypted message. As mentioned above, the appropriate key scope may be determined from another source that stores the message data pointer, message data, conversation history or related information. Based on the determined key scope, the group-based communication system server sends a request for a key matching the determined key scope to the key cache in step 520.
Upon receiving the key request, control is passed to the key cache in step 522. If the key is already stored in the key cache, process 500 can skip steps 524-534 and proceed directly to step 536. If not remembered, the key cache proceeds to step 524, where it forwards the received key request to the key server in the designated region. Those skilled in the art may forward the key request received from the group-based communication system server, or equivalently generate a new request for the same key and send it to the key server in the specified region. You will understand.
At step 526, the key server in the geopolitical area specified by the user's organization receives the request and control is transferred to the key server. Then, in step 528, the key server gets the requested key. As mentioned above, the key may itself be stored in encrypted form. Alternatively, the encryption key may be regenerated on demand. Finally, in step 530, a response containing the requested key is generated and returned to the key cache.
At step 532, the key cache receives a response from the key server in the specified geopolitical area containing the requested key. At step 534, the key cache leaves room for the key (for a pre-specified period of time, until it expires, or another key) to avoid having to refetch if the key is requested again immediately. Remember (until it is eliminated to make). Finally, in step 536, the key cache sends a response with the requested key to the group-based communication system server, regardless of whether the key already existed in the cache or was retrieved from the specified key server. It sends and control returns to the server.
At step 538, the first group-based communication system server receives the key data and at step 540, using the key data, one or more of the requests received from the client device based on the user's actions. Decrypts the encrypted message of. Finally, in step 542, the group-based communication system server sends a decryption message to the client device. In some embodiments, the decrypted message can be protected by transport layer encryption (eg, SSL, HTTPS or TLS, etc.) during transfer. Control is then returned to the client device, which receives the decrypted message or message in step 544 and displays it to the user in step 546. At this point, process 500 may be terminated, the user may request an additional message or message (which causes process 500 to repeat), or the user posts a response and thereby processes. 300 may be executed. In some embodiments, messages using different key scopes are interleaveable at the time of viewing. This can be done, for example, when the user browses a shared channel or search results. In such an embodiment, the decrypted message may be retained until a response to all the messages requested to be decrypted is received. In another embodiment, the decrypted message is retained until a response to all messages appearing forward on the display is received so that the messages are displayed in sequence. In yet another embodiment, the decrypted message is displayed with a placeholder for the encrypted message for which the decryption response has not yet been received.
The various components illustrated, as well as many different components not shown, are possible without departing from the claims below. The embodiments of the present invention are described with the intention of illustration, not limitation. Alternative embodiments will become apparent to the readers of the present disclosure after reading the present disclosure and by reading the present disclosure. An alternative means of carrying out the above is complete without departing from the claims below. Certain features and sub-combinations are useful, can be adopted without reference to other features and sub-combinations, and are intended as claims. Although the present invention has been described with reference to the embodiments shown in the accompanying drawings, equivalents can be employed herein without departing from the scope of the invention described in the claims. Note that, and that substitutions are possible.
Although various embodiments of the present invention have been described in this way, what is claimed to be novel and desired to be protected by a letter patent includes the scope of the appended claims.
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| WO2025192609A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| JP2025138567A | Cited by | Japan | – | Search report | – |
| US2019379534A1 | Cites | United States of America | A | Search report | 1⌲20 |
| US2020192881A1 | Cites | United States of America | A | Search report | 1-20 |
56 members in 8 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 16918284 | United States of America | – | |
| 202016918284 | United States of America | A |
Members56
| Document | Office | Kind | |
|---|---|---|---|
| CA3093718A1 | Canada | A1 | |
| CA3175443A1 | Canada | A1 | |
| US2019379534A1 | United States of America | A1 | |
| WO2019236905A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CA3063660A1 | Canada | A1 | |
| EP3667514A1 | European Patent Office (EPO) | A1 | |
| US2020192881A1 | United States of America | A1 | |
| JP2020126600A | Japan | A | |
| US10778419B2 | United States of America | B2 | |
| US2020336472A1 | United States of America | A1 | |
| US2020374111A1 | United States of America | A1 | |
| US2020412806A1 | United States of America | A1 | |
| AU2020103430A4 | Australia | A4 | |
| KR20210014702A | Republic of Korea | A | |
| EP3777015A1 | European Patent Office (EPO) | A1 | |
| AU2020104253A4 | Australia | A4 | |
| CN112534773A | China | A | |
| US2021091933A1 | United States of America | A1 | |
| AU2020103430B4 | Australia | B4 | |
| JP2021510995A | Japan | A | |
| CA3092836A1 | Canada | A1 | |
| CN113890726A | China | A | |
| EP3933606A1 | European Patent Office (EPO) | A1 | |
| EP3933606A4 | European Patent Office (EPO) | A4 | |
| AU2021107603A4 | Australia | A4 | |
| KR20220003463A | Republic of Korea | A | |
| JP2022013554AThis record | Japan | A | |
| JP2022058631A | Japan | A | |
| EP3777015B1 | European Patent Office (EPO) | B1 | |
| JP2022084778A | Japan | A | |
| JP7086918B2 | Japan | B2 | |
| JP7092840B2 | Japan | B2 | |
| JP2022120157A | Japan | A | |
| EP4050840A1 | European Patent Office (EPO) | A1 | |
| EP3667514B1 | European Patent Office (EPO) | B1 | |
| AU2021107603B4 | Australia | B4 | |
| US11539675B2 | United States of America | B2 | |
| US2023053443A1 | United States of America | A1 | |
| KR102512764B1 | Republic of Korea | B1 | |
| EP4155972A1 | European Patent Office (EPO) | A1 | |
| EP4050840B1 | European Patent Office (EPO) | B1 | |
| US11757852B2 | United States of America | B2 | |
| CA3093718C | Canada | C | |
| JP7357704B2 | Japan | B2 | |
| CA3063660C | Canada | C | |
| US11799636B2 | United States of America | B2 | |
| JP7374264B2 | Japan | B2 | |
| JP7428742B2 | Japan | B2 | |
| JP7458565B1 | Japan | B1 | |
| US11949739B2 | United States of America | B2 | |
| JP2024050693A | Japan | A | |
| EP4155972B1 | European Patent Office (EPO) | B1 | |
| US12015699B2 | United States of America | B2 | |
| US12019607B2 | United States of America | B2 | |
| CN112534773B | China | B | |
| CA3092836C | Canada | C |
14 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Request for change of ownership or part of ownershipJAPANESE INTERMEDIATE CODE: R313113S111 | S111 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A821A521 | A521 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of change in applicantJAPANESE INTERMEDIATE CODE: A712A711 | A711 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2022013554
- Application
- 170204
Titles2
- Japanese
- 国際データレジデンシのための暗号化キー管理
- English
- Cryptographic key management for international data residency
Classification
- CPC, 10
- H04L9/0894
- G06F16/1748
- H04L9/0822
- H04L63/0428
- G06F21/6218
- G06F2221/2111
- H04L9/0836
- H04L9/088
- H04L9/14
- H04L63/062
- IPC, 2
- H04L9 08
- H04L9 32