Nova Patents
US20260031986A1

Untitled record

Claim Score by NHIP

Read claim 9, the broadest

Abstract

Techniques are described for efficient and secure key rotation for backup storage. An example method comprises generating, by a data platform implemented by a computing system, a first encrypted key and a second encrypted key, wherein the data platform stores one or more encrypted chunks encrypted using a first encryption key of the first encrypted key and a second encryption key from the second encrypted key, the first encrypted key and the second encrypted key encrypted with a first system key, replacing the first system key by determining a second system key, and encrypting, with the second system key, the first encryption key to generate a replacement first encrypted key and the second encryption key to generate a replacement second encrypted key.

US20260031986A1, drawing sheet 1
Sheet 1 of 8

Term

17.8 yearsto projected expiry

Projected expiry 29 July 2044, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

20 claims: 3 independent, 17 dependent

  1. 1
    A method comprising:generating, by a data platform implemented by a computing system, a first encrypted key and a second encrypted key, wherein the data platform stores one or more encrypted chunks, each encrypted chunk of the one or more encrypted chunks encrypted with a data encryption key derived from a first encryption key of the first encrypted key and key data of encrypted key data, the first encrypted key data encrypted with a second encryption key from the second encrypted key, the first encrypted key and the second encrypted key encrypted with a first system key;replacing, by the data platform, the first system key by determining a second system key;encrypting, by the data platform and with the second system key, the first encryption key to generate a replacement first encrypted key and the second encryption key to generate a replacement second encrypted key;decrypting, by the data platform, the replacement first encrypted key to obtain the first encryption key and the encrypted key data to obtain the key data, wherein the first encryption key and the key data are used derive the data encryption key when decrypting the one or more encrypted chunks;and outputting, by the data platform, data from the one or more encrypted chunks by decrypting the one or more encrypted chunks with the data encryption key.
  2. 9
    Broadest claimClaim Score 39, average(NHIP)A computing system comprising:a memory storing instructions;and processing circuitry that executes the instructions to: generate a first encrypted key and a second encrypted key, wherein the data platform stores one or more encrypted chunks, each encrypted chunk of the one or more encrypted chunks encrypted with a data encryption key derived from a first encryption key of the first encrypted key and key data of encrypted key data, the first encrypted key data encrypted with a second encryption key from the second encrypted key, the first encrypted key and the second encrypted key encrypted with a first system key;replace the first system key by determining a second system key;encrypt, with the second system key, the first encryption key to generate a replacement first encrypted key and the second encryption key to generate a replacement second encrypted key;decrypt the replacement first encrypted key to obtain the first encryption key and the encrypted key data to obtain the key data, wherein the first encryption key and the key data are used derive the data encryption key when decrypting the one or more encrypted chunks;and output data from the one or more encrypted chunks by decrypting the one or more encrypted chunks with the data encryption key.
  3. 17
    A computer-readable storage medium comprising instructions that, when executed, cause processing circuitry of a computing system to:generate a first encrypted key and a second encrypted key, wherein the data platform stores one or more encrypted chunks, each encrypted chunk of the one or more encrypted chunks encrypted with a data encryption key derived from a first encryption key of the first encrypted key and key data of encrypted key data, the first encrypted key data encrypted with a second encryption key from the second encrypted key, the first encrypted key and the second encrypted key encrypted with a first system key;replace the first system key by determining a second system key;encrypt, with the second system key, the first encryption key to generate a replacement first encrypted key and the second encryption key to generate a replacement second encrypted key;decrypt the replacement first encrypted key to obtain the first encryption key and the encrypted key data to obtain the key data, wherein the first encryption key and the key data are used derive the data encryption key when decrypting the one or more encrypted chunks;and output data from the one or more encrypted chunks by decrypting the one or more encrypted chunks with the data encryption key.