UPDATEABLE ENCRYPTION IN SELF ENCRYPTING DRIVES

    公开(公告)号:US20250125955A1

    公开(公告)日:2025-04-17

    申请号:US18925554

    申请日:2024-10-24

    Abstract: A method of rotating a set of keys, having a media encryption key (MEK) and a current media encryption key encryption key (MEKEK) encrypted and stored in a self-encrypting drive (SED) having data encrypted with the MEK (MEK (data)), includes decrypting the stored MEK and the current MEKEK. A new MEK (MEK′) and a new MEKEK (MEKEK′) are generated. The MEKEK′ is encrypted to replace the current encrypted MEKEK. A concatenation of the MEK and the MEK′ is encrypted with MEKEK′. The encrypted data MEK (data) is re-encrypted with MEK′.

    UPDATEABLE ENCRYPTION IN SELF ENCRYPTING DRIVES

    公开(公告)号:US20220286282A1

    公开(公告)日:2022-09-08

    申请号:US17189927

    申请日:2021-03-02

    Abstract: A method of rotating a set of keys, having a media encryption key (MEK) and a current media encryption key encryption key (MEKEK) encrypted and stored in a self-encrypting drive (SED) having data encrypted with the MEK (MEK(data)), includes decrypting the stored MEK and the current MEKEK. A new MEK (MEK′) and a new MEKEK (MEKEK′) are generated. The MEKEK′ is encrypted to replace the current encrypted MEKEK. A concatenation of the MEK and the MEK′ is encrypted with MEKEK′. The encrypted data MEK(data) is re-encrypted with MEK′.

    POST-QUANTUM SECURE KEY-ROTATION FOR STORAGE DEVICES

    公开(公告)号:US20220263654A1

    公开(公告)日:2022-08-18

    申请号:US17177780

    申请日:2021-02-17

    Abstract: A method includes receiving, in a data storage device, a request from a client computer for a portion of ciphertext stored in the data storage device, and providing, by a controller of the data storage device, the portion of the ciphertext to the client computer. The method also includes receiving, in the data storage device, an update token generated by the client computer from the portion of the ciphertext. The method further includes performing, by the controller of the data storage device, re-encryption of the ciphertext using the update token.

    OFFLINE VALUE TRANSFER USING ASYMMETRIC CRYPTOGRAPHY

    公开(公告)号:US20210390532A1

    公开(公告)日:2021-12-16

    申请号:US16898977

    申请日:2020-06-11

    Abstract: Tokenized assets with associated value are transferred from a designated server to a mobile device. The associated value is removed from the designated server. The tokenized assets are transferred to a first trusted electronic device. The first trusted electronic device is associated with the mobile device. At least a portion of the tokenized assets are transferred to a second trusted electronic device such that the portion of the tokenized assets are only stored on the second trusted electronic device after the transfer. The second electronic device is associated with a second mobile device. The transfer occurs at a time when both the mobile device and the electronic device are offline.

    Secure distribution networks
    5.
    发明授权

    公开(公告)号:US11245527B2

    公开(公告)日:2022-02-08

    申请号:US16669307

    申请日:2019-10-30

    Abstract: Secure distribution of data objects using a unique quantum-safe cryptographic key provided to a user requesting the data object that has been authenticated using a zero-knowledge authentication. A user may access the system by way of the zero-knowledge authentication to request access to a data object of a data library. The system may generate and associate a unique quantum-safe cryptographic key for the instance of the data library to be provided to the authenticated user. The data object is encrypted using the unique quantum-safe cryptographic key. The encrypted data object and the unique quantum-safe cryptographic key are provided to the authenticated user. Other instances of the data object may also be encrypted with other unique quantum-safe cryptographic keys. In turn, access to a unique quantum-safe cryptographic key may not be useful in decrypting other instances of the data object, and other data objects may not be decrypted using a given unique key for a given data object instance.

    SECURING A COLLECTION OF DEVICES USING A DISTRIBUTED LEDGER

    公开(公告)号:US20210132826A1

    公开(公告)日:2021-05-06

    申请号:US16676068

    申请日:2019-11-06

    Abstract: Apparatus and method for local authentication of a collection of processing devices, such as but not limited to storage devices (e.g., SSDs, etc.). In some embodiments, each of the processing devices stores an internal token value as a unique ID value associated with the corresponding processing device. A host controller circuit performs a local authentication of the collection by accessing a distributed ledger as a data structure in a memory that lists the internal token values of the respective processing devices. The distributed ledger may take the form of a blockchain. The processing devices may each further store an external token value as the internal token value of a selected one of the other processing devices in the collection. A newly added device may be initially authenticated using a remote server. Once authenticated, the device is added to the collection and thereafter authenticated locally.

    Updateable encryption in self encrypting drives

    公开(公告)号:US12166873B2

    公开(公告)日:2024-12-10

    申请号:US17189927

    申请日:2021-03-02

    Abstract: A method of rotating a set of keys, having a media encryption key (MEK) and a current media encryption key encryption key (MEKEK) encrypted and stored in a self-encrypting drive (SED) having data encrypted with the MEK (MEK(data)), includes decrypting the stored MEK and the current MEKEK. A new MEK (MEK′) and a new MEKEK (MEKEK′) are generated. The MEKEK′ is encrypted to replace the current encrypted MEKEK. A concatenation of the MEK and the MEK′ is encrypted with MEKEK′. The encrypted data MEK(data) is re-encrypted with MEK′.

    Offline value transfer using asymmetric cryptography

    公开(公告)号:US11526874B2

    公开(公告)日:2022-12-13

    申请号:US16898977

    申请日:2020-06-11

    Abstract: Tokenized assets with associated value are transferred from a designated server to a mobile device. The associated value is removed from the designated server. The tokenized assets are transferred to a first trusted electronic device. The first trusted electronic device is associated with the mobile device. At least a portion of the tokenized assets are transferred to a second trusted electronic device such that the portion of the tokenized assets are only stored on the second trusted electronic device after the transfer. The second electronic device is associated with a second mobile device. The transfer occurs at a time when both the mobile device and the electronic device are offline.

Patent Agency Ranking