Invention Grant
- Patent Title: Key encryption key (KEK) rotation for multi-tenant (MT) system
-
Application No.: US17031720Application Date: 2020-09-24
-
Publication No.: US11374749B2Publication Date: 2022-06-28
- Inventor: Amit Agarwal , Rohit Koul , Srikant Krishnapuram Tirumalai , Jie Wang , Xinnong Wang
- Applicant: Oracle International Corporation
- Applicant Address: US CA Redwood Shores
- Assignee: Oracle International Corporation
- Current Assignee: Oracle International Corporation
- Current Assignee Address: US CA Redwood Shores
- Agency: Trellis IP Law Group, PC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/08

Abstract:
An example method facilitates enabling Key Encryption Key (KEK) rotation for a running multi-tenant system without requiring system downtime or interruption. The example method facilitates decrypting a set of one or more DEKs using a preexisting KEK; using a new KEK to re-encode the DEKs using the new KEK, all while simultaneously enabling servicing of tenant requests. This is enabled in part, by strategic caching of tenant DEKs in a secure local memory, wherein the cached tenant DEKs are maintained in the clear and are readily accessible to running processes that are using the DEKs to decrypt and access tenant data, irrespective of the state of a background process used to implement the KEK rotation to the new KEK.
Public/Granted literature
- US20210014056A1 KEY ENCRYPTION KEY (KEK) ROTATION FOR MULTI-TENANT (MT) SYSTEM Public/Granted day:2021-01-14
Information query