The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jan. 05, 2021

Filed:

Mar. 20, 2018
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Jason K. Resch, Chicago, IL (US);

Hugo M. Krawczyk, Tarrytown, NY (US);

Mark D. Seaborn, Algonquin, IL (US);

Nataraj Nagaratnam, Cary, NC (US);

Erlander Lo, Leander, TX (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/00 (2006.01); H04L 29/06 (2006.01); H04L 9/08 (2006.01); H04L 9/32 (2006.01); H04L 9/06 (2006.01);
U.S. Cl.
CPC ...
H04L 63/06 (2013.01); H04L 9/0656 (2013.01); H04L 9/0869 (2013.01); H04L 9/0877 (2013.01); H04L 9/3247 (2013.01); H04L 9/3271 (2013.01);
Abstract

A computing device includes an interface configured to interface and communicate with a communication system, a memory that stores operational instructions, and processing circuitry operably coupled to the interface and to the memory that is configured to execute the operational instructions to perform various operations. The computing device generates a sub-key identifier based on a data ID, which is based on unique ID value(s) associated with an encrypted data object, and a requester secret. The computing device processes the sub-key identifier in accordance with an Oblivious Pseudorandom Function (OPRF) blinding operation to generate a blinded input and an Oblivious Key Access Request (OKAR). The computing device transmits the OKAR to another computing device (e.g., Key Management System (KMS) service) and receives a blinded sub-key therefrom. The computing device processes the blinded sub-key in accordance with an OPRF unblinding operation to generate the key and accesses secure data thereby.


Find Patent Forward Citations

Loading…