CENTRALLY ROTATING PRIVATE/PUBLIC ENCRYPTION KEYS IN A LARGE SCALE SYSTEM

    公开(公告)号:US20230179413A1

    公开(公告)日:2023-06-08

    申请号:US17457386

    申请日:2021-12-02

    CPC classification number: H04L9/0891 H04L9/0894 H04L9/14

    Abstract: A system and method for rotating private encryption keys for tenants of a database system has been developed. First, three separate public-private encryption keys are generated for a tenant of the database system. The three separate private encryption keys for the tenant are then stored in cloud-based storage. A defined cadence is created to rotate the private encryption keys for the tenant. The three separate private encryption keys for the tenant are defined as a a past private key, a present private key and a future private key. Next, the public encryption key is stored for the tenant in a global tenant directory. The present private key and the public encryption key are retrieved to encrypt and decrypt data from the tenant. The three separate private encryption keys are rotated at the defined cadence, where the past private key is discarded, the present private key becomes a new past private key, the future private key becomes a new present private key, and a new future private key is generated. The new past private key, the new present private key and the new future private key for the tenant are then stored in cloud-based storage.

    BULK DATA EXTRACTION SYSTEM
    15.
    发明申请

    公开(公告)号:US20190238918A1

    公开(公告)日:2019-08-01

    申请号:US15885065

    申请日:2018-01-31

    Abstract: Techniques are disclosed relating to bulk data extraction systems. In some embodiments, a streaming server system may receive a first request, from a data storage system, that is sent prior to initiation of a bulk data extraction for a first group of users. In response to the first request, the streaming server system may receive, from the data storage system, a first notification message that includes a particular event identifier for a most recent data event generated at the data storage system. The streaming server system may receive, from the data storage system, those messages associated with the bulk data extraction for the first group. Subsequent to completion of the bulk data extraction, the streaming server system may send, to the data storage system, a request to subscribe to notification messages for data events associated with the first group.

Patent Agency Ranking