-
公开(公告)号:US11258592B2
公开(公告)日:2022-02-22
申请号:US16554522
申请日:2019-08-28
Applicant: Amazon Technologies, Inc.
Inventor: Petr Shveykin , Kelvin Yiu , Jakub Wojciak
Abstract: Systems and processes are described for a message service with distributed key caching for server-side encryption. Message requests are received by message handlers of the message service that cache data encryption keys used to encrypt and decrypt messages that are stored to message containers in back end storage. A metadata service obtains the data encryption keys from a key management service, caches the keys locally, and sends the keys to the message handlers upon request, where the keys are cached, again. The key management service may generate the data encryption keys based on a master key (e.g., a client's master key). The message handlers may send both message data encrypted using the data encryption key and an encrypted copy of the data encryption key to be stored together in the data store.
-
公开(公告)号:US20180054302A1
公开(公告)日:2018-02-22
申请号:US15242034
申请日:2016-08-19
Applicant: Amazon Technologies, Inc.
Inventor: Petr Shveykin , Kelvin Yiu , Jakub Wojciak
CPC classification number: H04L9/083 , H04L9/0822 , H04L9/0894 , H04L9/14 , H04L63/0435 , H04L63/064 , H04L63/068
Abstract: Systems and processes are described for a message service with distributed key caching for server-side encryption. Message requests are received by message handlers of the message service that cache data encryption keys used to encrypt and decrypt messages that are stored to message containers in back end storage. A metadata service obtains the data encryption keys from a key management service, caches the keys locally, and sends the keys to the message handlers upon request, where the keys are cached, again. The key management service may generate the data encryption keys based on a master key (e.g., a client's master key). The message handlers may send both message data encrypted using the data encryption key and an encrypted copy of the data encryption key to be stored together in the data store.
-