-
公开(公告)号:US11533168B2
公开(公告)日:2022-12-20
申请号:US16723466
申请日:2019-12-20
Applicant: SAP SE
Inventor: Martin Schindewolf , Meinolf Block , Christoph Höhner , Sascha Zorn
Abstract: The system described herein provides for storing the databases and encryption keys for decrypting the data in the databases into two separate partitions. In an embodiment, the first partition includes the databases while the second partition includes a configuration database and a payload database. The payload database stores a data encryption key for decrypting the data stored in the databases. The payload database is encrypted and may be decrypted using a body encryption key. The body encryption key itself is encrypted twice. In the first instance a key encryption key is generated and in the second instance a second access key is generated. The key encryption key or the second access key may be used to decrypt the body encryption key. The second access key is stored in a secure location, to be retrieved in situations when the key encryption key is inaccessible.