发明名称 SYSTEM, METHOD, AND COMPUTER-READABLE MEDIUM FOR CRYPTOGRAPHIC KEY ROTATION IN A DATABASE SYSTEM
摘要 A system, method, and computer-readable medium that facilitate key rotation without disrupting database access are provided. Generation identifiers that specify a particular encryption key are stored in association with cipher text of encrypted columns in database tables. When data is to be read from an encrypted column, the cipher text is read along with the associated generation identifier. An encryption key corresponding to the generation identifier is then read to decrypt the cipher text. When data is to be written to the encrypted column, a most recent encryption key is retrieved from the key repository to encrypt the data. The cipher text is then written to the encrypted column in association with the generation identifier of the key used to encrypt the data. Advantageously, the key rotation may be performed without requiring that the table or database to be taken offline or otherwise unavailable during key rotation.
申请公布号 US2010161995(A1) 申请公布日期 2010.06.24
申请号 US20080339179 申请日期 2008.12.19
申请人 BROWNING JAMES 发明人 BROWNING JAMES
分类号 G06F21/00;G06F17/30;H04L9/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址
您可能感兴趣的专利