WO2010132251A3

Protection of encryption keys in a database

Abstract

System, method, computer program product embodiments and combinations and sub- combinations thereof for protection of encryption keys in a database are described herein. An embodiment includes a master key and a dual master key, both of which are used to encrypt encryption keys in a database. To access encrypted data, the master key and dual master key must be supplied to a database server by two separate entities, thus requiring dual control of the master and dual master keys. Furthermore, passwords for the master and dual master keys must be supplied separately and independently, thus requiring split knowledge to access the master and dual master keys. In another embodiment, a master key and a key encryption key derived from a user password is used for dual control. An embodiment also includes supplying the secrets for the master key and dual master key through server-private files.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

Every citation, both waysCites: the store holds 6 of 7

Citations
DocumentRelationOfficeCategoryCited during
US2002071566A1CitesUnited States of AmericaYInternational search
US2002071566A1CitesUnited States of AmericaYInternational search
US2006053112A1CitesUnited States of AmericaAInternational search
US2006053112A1CitesUnited States of AmericaAInternational search
US2008077806A1CitesUnited States of AmericaAInternational search
US2008077806A1CitesUnited States of AmericaAInternational search
W. F. EHRSAM ET AL: "A cryptographic key management scheme for implementing the Data Encryption Standard", IBM SYSTEM JOURNAL, vol. 17, no. 2, 1978, pages 106 - 125, XP008164549Non-patentInternational search
See also references of EP 2430789A4Non-patentInternational search