-
公开(公告)号:US20250125955A1
公开(公告)日:2025-04-17
申请号:US18925554
申请日:2024-10-24
Applicant: Seagate Technology LLC
Inventor: Hamza Jeljeli , Kian Beng Lim , Saravanan Nagarajan
IPC: H04L9/08
Abstract: A method of rotating a set of keys, having a media encryption key (MEK) and a current media encryption key encryption key (MEKEK) encrypted and stored in a self-encrypting drive (SED) having data encrypted with the MEK (MEK (data)), includes decrypting the stored MEK and the current MEKEK. A new MEK (MEK′) and a new MEKEK (MEKEK′) are generated. The MEKEK′ is encrypted to replace the current encrypted MEKEK. A concatenation of the MEK and the MEK′ is encrypted with MEKEK′. The encrypted data MEK (data) is re-encrypted with MEK′.
-
公开(公告)号:US20220286282A1
公开(公告)日:2022-09-08
申请号:US17189927
申请日:2021-03-02
Applicant: Seagate Technology LLC
Inventor: Hamza Jeljeli , Kian Beng Lim , Saravanan Nagarajan
IPC: H04L9/08
Abstract: A method of rotating a set of keys, having a media encryption key (MEK) and a current media encryption key encryption key (MEKEK) encrypted and stored in a self-encrypting drive (SED) having data encrypted with the MEK (MEK(data)), includes decrypting the stored MEK and the current MEKEK. A new MEK (MEK′) and a new MEKEK (MEKEK′) are generated. The MEKEK′ is encrypted to replace the current encrypted MEKEK. A concatenation of the MEK and the MEK′ is encrypted with MEKEK′. The encrypted data MEK(data) is re-encrypted with MEK′.
-
公开(公告)号:US20220263654A1
公开(公告)日:2022-08-18
申请号:US17177780
申请日:2021-02-17
Applicant: Seagate Technology LLC
Inventor: Foo Yee Yeo , Saravanan Nagarajan , Vipin Singh Sehrawat , Kian Beng Lim
Abstract: A method includes receiving, in a data storage device, a request from a client computer for a portion of ciphertext stored in the data storage device, and providing, by a controller of the data storage device, the portion of the ciphertext to the client computer. The method also includes receiving, in the data storage device, an update token generated by the client computer from the portion of the ciphertext. The method further includes performing, by the controller of the data storage device, re-encryption of the ciphertext using the update token.
-
公开(公告)号:US20210390532A1
公开(公告)日:2021-12-16
申请号:US16898977
申请日:2020-06-11
Applicant: Seagate Technology LLC
Inventor: Varun Reddy Boddu , Kian Beng Lim , Hamza JelJeli , Vipin Kumar Verma
Abstract: Tokenized assets with associated value are transferred from a designated server to a mobile device. The associated value is removed from the designated server. The tokenized assets are transferred to a first trusted electronic device. The first trusted electronic device is associated with the mobile device. At least a portion of the tokenized assets are transferred to a second trusted electronic device such that the portion of the tokenized assets are only stored on the second trusted electronic device after the transfer. The second electronic device is associated with a second mobile device. The transfer occurs at a time when both the mobile device and the electronic device are offline.
-
公开(公告)号:US11245527B2
公开(公告)日:2022-02-08
申请号:US16669307
申请日:2019-10-30
Applicant: Seagate Technology LLC
Inventor: Vincent Uy , Nino Wicaksono , Saravanan Nagarajan , Kwong Heng Alphonsus John Kwok , Kian Beng Lim
Abstract: Secure distribution of data objects using a unique quantum-safe cryptographic key provided to a user requesting the data object that has been authenticated using a zero-knowledge authentication. A user may access the system by way of the zero-knowledge authentication to request access to a data object of a data library. The system may generate and associate a unique quantum-safe cryptographic key for the instance of the data library to be provided to the authenticated user. The data object is encrypted using the unique quantum-safe cryptographic key. The encrypted data object and the unique quantum-safe cryptographic key are provided to the authenticated user. Other instances of the data object may also be encrypted with other unique quantum-safe cryptographic keys. In turn, access to a unique quantum-safe cryptographic key may not be useful in decrypting other instances of the data object, and other data objects may not be decrypted using a given unique key for a given data object instance.
-
公开(公告)号:US20210132826A1
公开(公告)日:2021-05-06
申请号:US16676068
申请日:2019-11-06
Applicant: Seagate Technology LLC
Inventor: Kwong Heng Alphonsus John Kwok , Kian Beng Lim , Wei Siong Teo , Vincent Uy , Nino Wicaksono
Abstract: Apparatus and method for local authentication of a collection of processing devices, such as but not limited to storage devices (e.g., SSDs, etc.). In some embodiments, each of the processing devices stores an internal token value as a unique ID value associated with the corresponding processing device. A host controller circuit performs a local authentication of the collection by accessing a distributed ledger as a data structure in a memory that lists the internal token values of the respective processing devices. The distributed ledger may take the form of a blockchain. The processing devices may each further store an external token value as the internal token value of a selected one of the other processing devices in the collection. A newly added device may be initially authenticated using a remote server. Once authenticated, the device is added to the collection and thereafter authenticated locally.
-
公开(公告)号:US12166873B2
公开(公告)日:2024-12-10
申请号:US17189927
申请日:2021-03-02
Applicant: Seagate Technology LLC
Inventor: Hamza Jeljeli , Kian Beng Lim , Saravanan Nagarajan
IPC: H04L9/08
Abstract: A method of rotating a set of keys, having a media encryption key (MEK) and a current media encryption key encryption key (MEKEK) encrypted and stored in a self-encrypting drive (SED) having data encrypted with the MEK (MEK(data)), includes decrypting the stored MEK and the current MEKEK. A new MEK (MEK′) and a new MEKEK (MEKEK′) are generated. The MEKEK′ is encrypted to replace the current encrypted MEKEK. A concatenation of the MEK and the MEK′ is encrypted with MEKEK′. The encrypted data MEK(data) is re-encrypted with MEK′.
-
公开(公告)号:US11711212B2
公开(公告)日:2023-07-25
申请号:US17177780
申请日:2021-02-17
Applicant: Seagate Technology LLC
Inventor: Foo Yee Yeo , Saravanan Nagarajan , Vipin Singh Sehrawat , Kian Beng Lim
CPC classification number: H04L9/0891 , H04L9/0618 , H04L9/0894 , H04L9/3213
Abstract: A method includes receiving, in a data storage device, a request from a client computer for a portion of ciphertext stored in the data storage device, and providing, by a controller of the data storage device, the portion of the ciphertext to the client computer. The method also includes receiving, in the data storage device, an update token generated by the client computer from the portion of the ciphertext. The method further includes performing, by the controller of the data storage device, re-encryption of the ciphertext using the update token.
-
公开(公告)号:US11526874B2
公开(公告)日:2022-12-13
申请号:US16898977
申请日:2020-06-11
Applicant: Seagate Technology LLC
Inventor: Varun Reddy Boddu , Kian Beng Lim , Hamza JelJeli , Vipin Singh Sehrawat
Abstract: Tokenized assets with associated value are transferred from a designated server to a mobile device. The associated value is removed from the designated server. The tokenized assets are transferred to a first trusted electronic device. The first trusted electronic device is associated with the mobile device. At least a portion of the tokenized assets are transferred to a second trusted electronic device such that the portion of the tokenized assets are only stored on the second trusted electronic device after the transfer. The second electronic device is associated with a second mobile device. The transfer occurs at a time when both the mobile device and the electronic device are offline.
-
-
-
-
-
-
-
-