Invention Grant
- Patent Title: Long term encrypted storage and key management
- Patent Title (中): 长期加密存储和密钥管理
-
Application No.: US14575676Application Date: 2014-12-18
-
Publication No.: US09455963B1Publication Date: 2016-09-27
- Inventor: Gregory Branchek Roth , Eric Jason Brandwine
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US NV Reno
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US NV Reno
- Agency: Hogan Lovells US LP
- Main IPC: H04L9/32
- IPC: H04L9/32 ; H04L29/06 ; G06F1/26 ; G08B29/00

Abstract:
An encryption key not accessible outside a data storage device can be used to encrypt data stored in that device. The received data may have been encrypted under an external key, such as a key associated with a customer of a data storage service. Upon receiving the data encrypted under the external key, the data can be decrypted using a copy of the external key and then re-encrypted, inside the data storage device, using the internal key. If the external key is to be rotated, the stored data does not need to be modified as the data can be decrypted using the internal key and then re-encrypted using the new external key in response to an authorized request for the data after the change to the new external key. Such an approach provides near instant key rotation while not having to re-encrypt data under the new key unless requested.
Information query