发明名称 Use of Indirect Data Keys for Encrypted Tape Cartridges
摘要 A method, system and program are provided for enabling selective access to multiple users' encrypted data in a single storage cartridge. A unique, derived key is generated for each user's data by performing cryptographic operations on a combination of a common base key and metadata related to the data to be encrypted (e.g. its total block count). The base data key is wrapped with one or more encryption keys to form one or more encryption encapsulated data keys (EEDKs). The base key and the derived key are wrapped to create a session encrypted data key (SEDK), which along with the EEDKs, are conveyed to the tape drive, where the SEDK is decrypted. The EEDKs are then stored in one or more places on the storage cartridge. The base key and the derived key are used to encrypt a predetermined user's data, with the derived key stored on the cartridge with the encrypted data. The encrypted data may be subsequently decrypted by retrieving the EEDK and decrypting it with a decryption key to extract the base data key. The extracted base data key can then be used with other information to calculate the derived key. Once calculated, the derived key is used to decrypt its associated encrypted data.
申请公布号 US2008273697(A1) 申请公布日期 2008.11.06
申请号 US20070742837 申请日期 2007.05.01
申请人 发明人 GRECO PAUL M.;HALEVI SHAI;JAQUETTE GLEN A.
分类号 H04L9/14;H04L9/10 主分类号 H04L9/14
代理机构 代理人
主权项
地址