-
公开(公告)号:US20240323010A1
公开(公告)日:2024-09-26
申请号:US18188674
申请日:2023-03-23
Applicant: Google LLC
Inventor: Marcel Catalin Rosu , Timothy Matthew Dierks
CPC classification number: H04L9/0877 , H04L9/0825 , H04L9/3263
Abstract: Provided are computer systems and methods that enable the remote control of a hardware security module (HSM) device. In particular, aspects of the present disclosure enable HSM device management to be split into two components: physical management, which can be handled by a cloud provider or other IT service provider; and logical management, which can be performed by the HSM end user. Thus, a user computing system can be enabled to remotely control a HSM device that is installed in a server computing system that is remotely located from the user computing system.
-
公开(公告)号:US11611558B2
公开(公告)日:2023-03-21
申请号:US16683025
申请日:2019-11-13
Applicant: Google LLC
Inventor: Il-Sung Lee , Sidharth Durgesh Telang , Jimmy C. Chau , Timothy Matthew Dierks , Ariel Joseph Feldman , Hunter James Freyer , Netanel Keidar , Gregory David Laun , Tianyuan Liu , Pedro Henrique Ribeiro Morais e Silva , Aditya Sinha , Xioalan Zhang
Abstract: A method for integrating third-party encryption managers with cloud services includes receiving, at data processing hardware, an operation request requesting a cryptographic operation on data comprising an encryption operation or a decryption operation. When the operation is an encryption operation, the method includes transmitting a data encryption key associated with the data to a remote entity. The remote entity encrypts the data encryption key with a key encryption key and transmits the encrypted data encryption key to the data processing hardware. When the operation is a decryption operation, the method includes transmitting the encrypted data encryption key to the remote entity which causes the remote entity to decrypt the encrypted data encryption key with the key encryption key and transmit the decrypted data encryption key and transmit to the data processing hardware.
-
公开(公告)号:US20210144141A1
公开(公告)日:2021-05-13
申请号:US16683025
申请日:2019-11-13
Applicant: Google LLC
Inventor: Il-Sung Lee , Sidharth Durgesh Telang , Jimmy C. Chau , Timothy Matthew Dierks , Ariel Joseph Feldman , Hunter James Freyer , Netanel Keidar , Gregory David Laun , Tianyuan Liu , Pedro Henrique Ribeiro Morais e Silva , Aditya Sinha , Xioalan Zhang
Abstract: A method for integrating third-party encryption managers with cloud services includes receiving, at data processing hardware, an operation request requesting a cryptographic operation on data comprising an encryption operation or a decryption operation. When the operation is an encryption operation, the method includes transmitting a data encryption key associated with the data to a remote entity. The remote entity encrypts the data encryption key with a key encryption key and transmits the encrypted data encryption key to the data processing hardware. When the operation is a decryption operation, the method includes transmitting the encrypted data encryption key to the remote entity which causes the remote entity to decrypt the encrypted data encryption key with the key encryption key and transmit the decrypted data encryption key and transmit to the data processing hardware.
-
公开(公告)号:US20240177115A1
公开(公告)日:2024-05-30
申请号:US18059239
申请日:2022-11-28
Applicant: Google LLC
Inventor: Christopher William Johnson , Jason Edward Callaway , Anthony Michael Carnevale , Timothy Matthew Dierks , Omkhar Arasaratnam
CPC classification number: G06Q10/103 , H04L63/20
Abstract: A method for implementing software-defined community clouds includes receiving, from a first requestor, a first access request requesting access to a first project of a plurality of projects. Each project includes project data governed by a compliance regime that enforces compliance requirements. The method includes, for each compliance requirement, determining that the first access request satisfies the compliance requirement. The method includes, based on determining that the first access request satisfies compliance requirements, granting the first requestor access to the first project. The method includes receiving, from a second requestor, a second access request requesting access to a second project and determining that the second access request fails to satisfy one of the one of the compliance requirements. The method also includes, based on determining that the second access request fails to satisfy one of the compliance requirements, denying the second requestor access to the second project.
-
公开(公告)号:US20230231850A1
公开(公告)日:2023-07-20
申请号:US18186733
申请日:2023-03-20
Applicant: Google LLC
Inventor: ll-Sung Lee , Sidharth Durgesh Telang , Jimmy C. Chau , Timothy Matthew Dierks , Ariel Joseph Feldman , Hunter James Freyer , Gregory David Laun , Tianyuan Liu , Pedro Henrique Ribeiro Morais E Silva , Aditya Sinha , Xioalan Zhang , Netanel Keidar
CPC classification number: H04L63/0884 , H04L9/0822 , H04L9/0891 , H04L63/083 , H04L63/06 , H04L63/20
Abstract: A method for integrating third-party encryption managers with cloud services includes receiving, at data processing hardware, an operation request requesting a cryptographic operation on data comprising an encryption operation or a decryption operation. When the operation is an encryption operation, the method includes transmitting a data encryption key associated with the data to a remote entity. The remote entity encrypts the data encryption key with a key encryption key and transmits the encrypted data encryption key to the data processing hardware. When the operation is a decryption operation, the method includes transmitting the encrypted data encryption key to the remote entity which causes the remote entity to decrypt the encrypted data encryption key with the key encryption key and transmit the decrypted data encryption key and transmit to the data processing hardware.
-
-
-
-