The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 10, 2019

Filed:

Nov. 09, 2016
Applicant:

Sap SE, Walldorf, DE;

Inventors:

Meinolf Block, Heidelberg, DE;

Christoph Hohner, Mannheim, DE;

Martin Schindewolf, Walldorf, DE;

Sascha Zorn, Schwetzingen, DE;

Assignee:

SAP SE, Walldorf, DE;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/00 (2006.01); G06F 12/14 (2006.01); H04L 9/08 (2006.01); G06F 21/62 (2013.01); H04L 9/32 (2006.01);
U.S. Cl.
CPC ...
H04L 9/0894 (2013.01); G06F 21/6227 (2013.01); H04L 9/0891 (2013.01); H04L 9/3226 (2013.01); H04L 9/3236 (2013.01);
Abstract

Embodiments manage access to cryptography keys for database data, within a secure key store of a local key server owned by a new (security) operating system (OS) user separate from an original default OS user. Existing principles governing distinct OS user access privileges engrained within the OS itself, are leveraged to preclude the default OS user from accessing files of the new security OS user. Embodiments thus segregate the right to read secure cryptography keys of a secure key store, from the right to administer database installation on the OS level. While the original default OS user retains access to the encrypted data, the new security OS user now owns the cryptography key necessary to decrypt that database data. Thus, the default OS user is denied enough information to unlock the database data, enhancing its security. Embodiments are particularly useful for promoting data security in cloud setups and multi-tenant databases.


Find Patent Forward Citations

Loading…