- 专利标题: Authenticating key-value data pairs for protecting node related data
-
申请号: US17889782申请日: 2022-08-17
-
公开(公告)号: US12120097B2公开(公告)日: 2024-10-15
- 发明人: Martin Schmatz , Navaneeth Rameshan , Patricia M. Sagmeister
- 申请人: International Business Machines Corporation
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理机构: Zilka-Kotab, P.C.
- 主分类号: H04L9/40
- IPC分类号: H04L9/40 ; H04L9/06 ; H04L9/08 ; H04L9/32
摘要:
A computer-implemented method according to one embodiment includes using a first symmetric key to encrypt a second symmetric key. The first symmetric key is securely loaded inside a hardware security module (HSM) by a key management service before the encryption of the second symmetric key, and a cloud provider only has access to encrypted bits of the first symmetric key. Key data of a key-value-pair of the second symmetric key is used as additional authenticated data (AAD) for the encryption of the second symmetric key. The second symmetric key is used to encrypt value data of the key-value-pair. The method further includes storing the encrypted second symmetric key, the AAD used in the encryption of the second symmetric key, and tag bits created during the encryption of the second symmetric key, to thereafter use for verifying node related data.
公开/授权文献
信息查询