Invention Grant
US08504844B2 System, method, and computer-readable medium for cryptographic key rotation in a database system 有权
用于数据库系统中加密密钥旋转的系统,方法和计算机可读介质

  • Patent Title: System, method, and computer-readable medium for cryptographic key rotation in a database system
  • Patent Title (中): 用于数据库系统中加密密钥旋转的系统,方法和计算机可读介质
  • Application No.: US12339179
    Application Date: 2008-12-19
  • Publication No.: US08504844B2
    Publication Date: 2013-08-06
  • Inventor: James Browning
  • Applicant: James Browning
  • Applicant Address: US OH Dayton
  • Assignee: Teradata US, Inc.
  • Current Assignee: Teradata US, Inc.
  • Current Assignee Address: US OH Dayton
  • Agent Steve McDonald; Randy L. Campbell, Jr.
  • Main IPC: G06F21/00
  • IPC: G06F21/00
System, method, and computer-readable medium for cryptographic key rotation in a database system
Abstract:
A system, method, and computer-readable medium that facilitate key rotation without disrupting database access are provided. Generation identifiers that specify a particular encryption key are stored in association with cipher text of encrypted columns in database tables. When data is to be read from an encrypted column, the cipher text is read along with the associated generation identifier. An encryption key corresponding to the generation identifier is then read to decrypt the cipher text. When data is to be written to the encrypted column, a most recent encryption key is retrieved from the key repository to encrypt the data. The cipher text is then written to the encrypted column in association with the generation identifier of the key used to encrypt the data. Advantageously, the key rotation may be performed without requiring that the table or database to be taken offline or otherwise unavailable during key rotation.
Information query
Patent Agency Ranking
0/0