Encryption for Message Queues

A topic-based encryption policy system in message queuing systems ensures secure data transmission by encrypting at the producer end and decrypting at the consumer end, addressing vulnerabilities in existing systems and maintaining confidentiality.

JP7811910B2Active Publication Date: 2026-02-06INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2022543533
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-02-05
Filing Date
2021-01-10
Publication Date
2026-02-06
Estimated Expiration
2041-01-10

AI Technical Summary

Technical Problem

Existing message queuing systems lack end-to-end encryption and secure key management, making them vulnerable to sysadmin attacks and unauthorized access to sensitive data.

Method used

Implement a topic-based encryption policy system that manages encryption keys independently of the message producer and consumer, ensuring encryption at the producer end and decryption at the consumer end, with logging and authentication to maintain confidentiality and integrity.

Benefits of technology

Ensures secure storage and transmission of sensitive data by preventing unauthorized access and maintaining encryption throughout the message exchange process, even when administrators have read permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007811910000001
    Figure 0007811910000001
  • Figure 0007811910000002
    Figure 0007811910000002
  • Figure 0007811910000003
    Figure 0007811910000003
Patent Text Reader

Abstract

Targeted topic-based encryption on publish-subscribe message queues. Topic-based encryption, driven by encryption policies for both storing and receiving messages, ensures confidentiality of the specific topic associated with stored encrypted messages, with activity tracking and logging. Authentication of both publishers and consumers ensures confidentiality of encryption and decryption keys.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates generally to message queuing systems, and more particularly to processing messages within a message queuing system in a secure manner. [Background technology]

[0002] Managing the exchange of messages and information within businesses, between businesses, business-to-consumer, and consumer-to-consumer is one of the core skills of information technology. Messaging systems have been widely used for decades to store, transfer, and distribute data as messages. More recently, messaging systems such as Kafka are also considered a form of database. Concurrent with this development, such messaging systems are increasingly instantiated in cloud computing systems. (Note: The term "KAFKA" may be subject to trademark rights in various jurisdictions around the world and is used here only with reference to products or services appropriately named by the mark to the extent such trademark rights may exist.)

[0003] A secure key management and data transmission system is known that includes a transition system, a data consumer network device, a user network device, and a data transmission network, wherein the transmission management system is configured to receive user-specific data from the user network device via the data transmission network and receive a request for a service corresponding to processing the user-specific data according to a proprietary process provided by the data consumer network device.

[0004] Additionally, a system for propagating a network configuration policy is known that uses a publish / subscribe messaging system, wherein during operation, the system receives one or more messages including a first representation of the configuration policy from a policy server through the publish / subscribe messaging system. Summary of the Invention

[0005] In one aspect of the present invention, methods, computer program products, and systems include: (i) determining, by referencing a topic-based encryption policy, that a first topic associated with a first message requires a first encryption level; (ii) providing a first entity (e.g., a user system) with an encryption key for encrypting the first message according to the first encryption level to generate a first encrypted message; (iii) storing the first encrypted message within a message queuing system according to the first topic; (iv) receiving a request from a second entity (e.g., a consumer system) for the first message associated with the first topic, including the first encrypted message; (v) identifying a decryption key corresponding to the first encrypted message associated with the first topic according to the topic-based encryption policy for the first topic; and (vi) sending the first encrypted message to the second entity (e.g., the consumer system) for decryption by the second entity (e.g., the consumer system) using the decryption key. In one aspect of the invention, before step (i), the computer-implemented method includes receiving a request from a first entity to determine whether a first topic requires encryption for storage within the message queuing system. In any one aspect of the invention, the computer-implemented method may further include recording in a logging system the providing of the encryption key to the first entity for generating the first encrypted message and the sending of the decryption key for the first encrypted message to the second entity. In any aspect of the invention, the computer-implemented method may further include, in response to an update to the topic-based encryption policy, logging the update in the logging system. In one optional aspect of the present invention, the message authentication code may include a keyed-hash message authentication code (HMAC). In any aspect of the invention, the computer-implemented method may further include establishing a subscription account for the second entity, including assigning authenticating credentials to the second entity, and receiving the request when the second entity subscribes to the first topic via the subscription account. In one optional aspect of the present invention, the decryption key may be assigned to the first topic by the topic-based encryption policy.

[0006] According to another aspect of the present invention, a computer-implemented method for targeted, policy-based encryption in a publish / subscribe message queuing system may be provided. The method may include receiving, by the message queuing system, an encrypted message, where the message is encrypted by referencing an encryption policy system and a key management system that stores topic-associated encryption keys; storing the received topic-associated encrypted message; and sending the encrypted message based on a subscription to the topic.

[0007] According to yet another aspect of the present invention, there may be provided a system for targeted policy-based encryption in a publish-subscribe message queue, the system may include a message queuing system adapted to receive encrypted messages, the messages being encrypted by reference to an encryption policy system and a key management system that stores topic-related encryption keys, means for storing the received topic-related encrypted messages, and means for sending the encrypted messages based on subscriptions to the topics.

[0008] Furthermore, another embodiment may take the form of an associated computer program accessible from a computer usable or computer readable medium providing program code for use by or in connection with a computer or any instruction execution system. In this description, a computer usable or computer readable medium may be any apparatus that may include means for storing, communicating, propagating, or transporting a program for use by or in connection with an instruction execution system, apparatus, or device. Yet another embodiment is a computer-implemented method, the computer-implemented method comprising: receiving a request from a first entity to determine whether a first topic requires encryption for storage in a message queuing system, the first topic being associated with a first message; determining, by the first entity, that the first topic requires a first encryption level by referencing a topic-based encryption policy; encrypting, by the first entity, the first message according to the first encryption level to generate an encrypted message; storing the encrypted message within a message queuing system according to the first topic; receiving a subscription for messages associated with the first topic from a second entity, the subscription including the first message; identifying, by the second entity, a decryption key corresponding to the encrypted message according to the topic-based encryption policy for the first topic; decrypting the encrypted message with the decryption key by the second entity to recover the first message; Including, wherein the encrypted message includes a message authentication code, the message authentication code ensuring the integrity of the signer of the first encrypted message and the integrity of the first encrypted message. A computer-implemented method is provided. In any aspect of the invention, the computer-implemented method may further include receiving the first message associated with the first topic from the first entity. In one optional aspect of the present invention, the message queuing system is a Kafka system. In any aspect of the invention, identifying the decryption key may include referencing the topic-based encryption policy to determine whether a subscription for messages associated with the first topic includes encrypted messages. In one optional aspect of the invention, a subscription for the message may include the encrypted message only if the message authentication code is provided by the second entity.

[0009] It should be noted that embodiments of the present invention are described with reference to different subject matters. Specifically, some embodiments are described with reference to method-type claims, while other embodiments are described with reference to apparatus-type claims. However, from the above and following description, those skilled in the art will infer that, unless otherwise specified, any combination of features belonging to a certain type of subject matter, as well as any combination between features relating to different subject matters, specifically between features of method-type claims and features of apparatus-type claims, is also considered to be disclosed within this document.

[0010] The above-defined aspects, as well as other aspects of the present invention, will be apparent from and will be elucidated with reference to the example embodiments described hereinafter, to which the present invention is not limited.

[0011] Some embodiments of the present invention will now be described, by way of example only, with reference to the following drawings, in which: [Brief explanation of the drawings]

[0012] [Figure 1] 1 is a flowchart of a first embodiment method for targeted policy-based encryption in publish-subscribe message queues. [Figure 2] 2 is a schematic diagram of a first embodiment system supporting the first embodiment method of FIG. 1; [Figure 3] 3 is a flowchart of activities for implementing at least a portion of the method of the first embodiment using the system of the first embodiment of FIG. 2. [Figure 4] 1 is a schematic diagram of a machine logic (e.g., software) portion of a first embodiment system for targeted policy-based encryption in publish / subscribe message queues. [Figure 5] 10 is a flowchart of a second embodiment method for targeted policy-based encryption in publish-subscribe message queues. [Figure 6] 1 is a schematic diagram of a computing system according to the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0013] Targeted topic-based encryption on publish-subscribe message queues. Topic-based encryption, driven by encryption policies for both storing and receiving messages, uses activity tracking and logging to ensure confidentiality for a given topic associated with a stored encrypted message. Authentication of both publishers and consumers ensures that encryption and decryption keys are used confidentially.

[0014] When messaging systems move highly sensitive data, such as personal or financial data, encryption of the data at the messaging server may often be required due to regulatory requirements, privacy policies, and / or best practices.

[0015] Some messaging systems store all data intended to be transmitted through the messaging server. For this and other reasons, these messaging systems resemble databases. This type of messaging system increases the need for encrypted storage, as the complete set of sensitive information may reside and be stored on the messaging server. If not encrypted, the entire sensitive data may be exposed to unauthorized access.

[0016] Some messaging systems may support native encryption of data stored on the messaging server. However, even if a messaging system supports encrypted storage on the server, the original producer of the data does not necessarily control the means of encryption, especially the encryption keys.

[0017] Encryption-at-rest is often addressed with disk or file system encryption on messaging servers. While this approach may prevent exposure if the disk is lost or stolen, it typically does not prevent access to decrypted data when a user has read and write permissions to all files on the messaging server. Thus, the file system will decrypt data for such users because they have read permissions. To prevent this, known as a "sysadmin attack," best security practices dictate that sensitive data be encrypted at the database or application level, with the corresponding decryption keys inaccessible to system administrators.

[0018] In the context of this description, the following conventions, terms or expressions, or combinations thereof, may be used:

[0019] The term "policy-based encryption" may indicate that a repository of rules may be available, for example, in an encryption policy database. By referencing the encryption policy database and flagging the encryption requirement for messages on specific topics in a message queue, the encryption policy database may inform the requestor that messages on the selected topics are or must be encrypted. Note also that "encrypting a message" can refer to the process of making a message unreadable as plain text; a message may only be understandable after it is decrypted.

[0020] It should also be noted that the term "encryption" may be understood broadly, i.e., to include other cryptographic operations such as digital signatures and MACs that provide message integrity and non-repudiation properties.

[0021] The term "message queue" (or messaging queue) can refer to a data storage organization that facilitates inter-process communication or communication between threads within the same process. It can use a queue for messages, such as a predefined sequence of messages. In this way, an asynchronous communication protocol can be established. This means that the sender and receiver of a message do not need to interact with the message queue at the same time. A message placed on a queue by the sender is stored on the queue and can be received and / or retrieved by the receiver. There can be several different commercially available message queuing systems from various companies or as larger open-source implementations. Sometimes, a message queuing system can also be referred to as a message broker.

[0022] Thus, message queuing may enable messaging patterns in which the sender of a message, referred to herein as a publisher or message producer, does not program the message to be sent directly to a specific receiver, referred to herein as a message consumer. In the context of this description, the terms "producer" and "consumer" may refer to a human user operating a computer or a computer program that operates according to program instructions to generate, encrypt, subscribe, receive, and / or decrypt messages in a message queuing system. Instead, published messages may be categorized into different classes or topics without the knowledge of any subscriber. A subscriber may express interest in one or more of these message classes and receive only messages of interest to the subscriber, such as a particular topic of interest, without any knowledge of which message producer generated the message.

[0023] The term "encrypted message" may refer to data that is not present in clear text but is encoded by a cryptographic key. Various methods for encryption are known. The proposed concept may be independent of the encryption method chosen. An encrypted message is readable only in clear text after decryption.

[0024] The term "cryptographic policy system" may refer to a policy database or repository of information defining the cryptographic operations and associated key material to be applied to messages, e.g., sent to a given topic in a message queuing system. Specifically, for each topic to be protected against unauthorized access, there may be a record detailing at least some of the following information: (i) message server address, (ii) topic name, (iii) topic identifier, (iv) encryption algorithm, (v) encryption / decryption steps, (vi) cipher suite (e.g., respective application programming interface), (vii) key management service, (viii) service address, (ix) key identifier, and / or (x) optional initialization information for encryption / decryption.

[0025] The term "key management system" may refer specifically to a storage system for encryption and decryption key pairs for asymmetric encryption or symmetric encryption / decryption of messages. A key management system may provide specific encryption keys based on selected rules of an encryption policy system (for message senders) or based on selected topics (for message consumers).

[0026] The term "subscription" may refer to a expressed interest in messages of a specified class or topic. A message consumer with a subscription may receive messages stored in a message queue by the topic or class.

[0027] The term "topic" may refer to a theme or headline for multiple messages. Topics may be organized according to various rules, for example, regarding the same or similar content, regarding a particular time frame, and / or regarding authors.

[0028] The term "Kafka" (or the Kafka system), particularly version 0.9.0 and above, may refer to a well-known open source stream processing software platform owned by the Apache Software Foundation. Kafka aims to provide a unified, high-throughput, low-latency platform for processing real-time data feeds. Kafka may also be used as a message queuing system, organizing received messages into topics and storing them in relational databases. In addition to the Kafka system, the proposed method and related systems may be implemented with other message queuing systems. (Note: The terms "KAFKA," "APACHE," and "APACHE SOFTWARE FOUNDATION" may be subject to trademark rights in various jurisdictions worldwide and are used herein only with respect to products or services appropriately named by the marks to the extent such trademark rights may exist.)

[0029] The term "message producer" may refer to the originator (or originator operated system) of a message. The originator may also be referred to as a publisher.

[0030] The term "message consumer" may refer to the recipient of a message. Note that the terms "(message) producer" and "(message) consumer" may relate to the Kafka system.

[0031] Some embodiments of the present invention recognize the following facts, potential problems, and / or potential areas for improvement with respect to the current state of the art: (i) traditional systems for propagating network configuration policies do not enable end-to-end encryption of topic-related messages in message broker systems, and therefore sysadmin attacks may still be unavoidable, and therefore there may be a need to overcome these shortcomings in traditional message queuing systems, particularly with regard to protecting data within the message queuing system; (ii) end-to-end data protection from producer to consumer can be guaranteed without decrypting messages sent from the producer to the message queuing system. (iii) the message queuing system, encryption policy system, and associated key management system or service, or combination thereof, may enable inherent control of security aspects of topic-related messages in a publish / subscribe environment; (iv) administrators of the message queuing server may be excluded from accessing encrypted messages on specified topics in the message queuing system's database pursuant to an encryption policy system that may exclude administrators from read permissions for topics in the database;(v) control is not simply delegated to the message producer, but is controlled by an encryption policy system that may define rules for message producers and message recipients independently, in such a way that the message producer may simply request an encryption key from a key management system or service that is related to, but not necessarily identical to, the encryption policy system, and the message may then be encrypted at the message producer's end before sending the message to the message queuing system (e.g., depending on permissions, the message may then only be decrypted at the consumer's end, so that the message never remains unencrypted from the message producer to the message recipient); (vi) messages may be stored within the message queuing system as topic-related messages, and therefore there may be topics that require encryption in the message queuing system's database and other topics that may not require any encryption; and / or (vii) the message producer or encryption database system key user may define rules for the message producer and message recipient independently, in such a way that the message producer may simply request an encryption key from a key management system or service that is related to, but not necessarily identical to, the encryption policy system, and the message may then be encrypted at the message producer's end before sending the message to the message queuing system (e.g., depending on permissions, the message may then only be decrypted at the consumer's end, so that the message never remains unencrypted from the message producer to the message recipient); user) or both may remain in full control of the encryption / decryption process, so that encryption is not delegated to the operator of a message queuing system (for example, the operator of a standard message queuing system like Kafka can be used and at the same time ensure the encryption of messages in the topic);

[0032] In the following, a detailed description of the figures is provided. All illustrations are schematic. First, a block diagram of one embodiment of the inventive computer-implemented method for targeted policy-based encryption on publish-subscribe messaging queues is provided. Later, other embodiments, as well as an embodiment of a system for targeted policy-based encryption on publish-subscribe messaging queues, are described.

[0033] FIG. 1 is a flowchart of a first embodiment method 100 for targeted policy-based encryption in publish-subscribe message queues, specifically targeted at the topic level. The message queue may be implemented using the Kafka system or another now known or to be developed messaging system. The method includes receiving 102 an encrypted message by the message queuing system, whereby the message has been encrypted specifically by a message producer or associated message generating system by reference to an encryption policy system and a key management system that stores topic-related encryption keys. Alternatively, the policy-based encryption may be targeted at the class level.

[0034] The method 100 also includes storing (104) the received topic-related encrypted messages and sending (106) the encrypted messages based on subscriptions to the topics to which the messages pertain, particularly in a publish / subscribe manner, upon request of message consumers. Alternatively, the concept of a message class is a basis for organizing messages and for subscriptions. In this disclosure, the term class includes characteristics that may not be immediately understood as a topic, such as a message's urgency, classified status, level of insightfulness, etc.

[0035] FIG. 2 is a schematic diagram of a first embodiment system 200 supporting the first embodiment method of FIG. 1. A message producer 202 consults an encryption policy in an encryption policy system 210 to determine whether a message on a particular topic must be encrypted. The message producer 202 receives an encryption key for the message from a key management system 212, either in parallel or on demand, and the key management system grants access via an access control module 213. In this example, the message producer may interact with the key management system using a key management API (application programming interface) 214. The key management system and encryption policy system log key access transactions and policy changes to a logging system 216 via access control modules 211 and 213. The records may include received requests, acceptances, denials, corresponding timestamps, permission levels, topics sought, or keys provided, or a combination thereof. The key management system may also manage access control to specific topics for producers and consumers. The message (not shown) is then encrypted by the encryption interface 203 of the message producer 204 in a particular encryption format and sent to a message broker 204 for storing the message in encrypted format in a file system 206 as a specified topic or class. In some embodiments of the invention, the file system 206 is in the form of a Kafka cluster. In some embodiments of the invention, encryption and decryption are performed at the broker level, e.g., within the broker 204, such that key access is consolidated at the broker. In a publish / subscribe mode, the broker 204 sends encrypted messages to consumers 208 on topics subscribed to by the consumers. In response to receiving the messages, the consumers 208 check with the encryption policy system 210 to determine whether messages on the subscribed topics are encrypted.If encrypted, the consumer receives a decryption key for said encryption key upon request, and the request is made using the subscribed topic as input parameters to the key management system 212. Note that the encryption / decryption can be symmetric (the encryption key and the encryption key are the same) or asymmetric (e.g., the encryption key and the decryption key are different, as in a public key infrastructure). The encryption / decryption mechanism may conform to the AES-256 Advanced Security Standard, or the keys may be compatible with any other suitable encryption standard. In some embodiments of the present invention, the broker is a message queuing system. In some embodiments of the present invention, the key management system acts as a key management service.

[0036] Upon receiving the decryption key, the message consumer decrypts the received message (not shown) using the decryption interface 209 of the message consumer 208 and the received decryption key (not shown).

[0037] FIG. 3 is a flowchart of a process 300 including activities for implementing at least a portion of the method of the first embodiment using the system of the first embodiment of FIG. 2. In initial step 302, a message producer, or simply producer, prepares a message assigned a subscribed topic for sending to the file system 206 via the broker 204. Prior to sending, the producer queries the encryption policy system 210 (304) using the subscribed topic as an input variable. In this example, it is determined that the subscribed topic requires encryption according to the encryption policy system or database. The producer then requests the encryption key referenced in the encryption policy from the key management system 212. Assuming that the access control policy at the key management service grants access to the key for the producer, i.e., the producer is permitted to send messages for the specified topic to the file system, the key is returned by the key management service in the request response to the producer.

[0038] At the same time, the producer's key request is recorded in an audit trail within the logging system 216.

[0039] Next, at 306, the producer encrypts the outgoing message body using a key retrieved from the key management system, and the message is sent to the file system 206 under the specified topic via the broker 204. The broker receives the message (308) and stores the message in encrypted form within the targeted topic in the file system.

[0040] The broker then receives (310) a request from the consumer for a message on the specified topic. The consumer request is stored in a message logging system, such as logging system 216. The logging system is associated with key management system 212 by access control module 213 and with encryption policy system 210 by access control module 211 as a single system, so that policies and access are tracked within the same system. Alternatively, separate logging systems may be associated with the two systems. The broker responds to the request by sending the message received from the producer in step 308. In step 314, the consumer receives the message assigned the specified topic in encrypted form.

[0041] The consumer then checks or queries the encryption policy database system (316) to determine whether messages on the topic are encrypted. attitudeThe consumer determines whether the message is decrypted and, if so, requests the key management system for the key needed to decrypt the message. After the consumer receives the decryption key from the key management system (318), the consumer system decrypts the received message. Upfront, the key management system or encryption policy system verifies that the consumer is authorized to receive the decryption key according to the access control policy. Note that the requesting consumer may be barred from their respective audit service, activity tracker, logging system, and / or ordered trail. Finally, the consumer decrypts the message using the key received from the key management system.

[0042] For completeness, Figure 4 is a schematic diagram of a machine logic (e.g., software) portion 400 of a first embodiment system for targeted policy-based encryption in publish / subscribe message queues. The machine logic portion comprises a message queuing system 402 adapted to receive encrypted messages, where the messages are encrypted by reference to an encryption policy system 404 and a key management system 406 that stores topic-related encryption keys. Additionally, the messages may be encrypted by a producer's encryption system, such as encryption system 410.

[0043] The machine logic portion may also comprise means for storing received topic-related encrypted messages in database 408, i.e., one group of messages may be stored under or associated with one topic and another group may be stored within or associated with another topic. Database 408 may be linked to message queuing system 402 or may be a physical part of message queuing system 402.

[0044] Finally, the machine logic portion comprises means for sending encrypted messages to consumers based on their subscriptions to the message's assigned topic. The transmissions may be directed to a message receiver (not shown here) that comprises a decryption system, such as decryption system 412.

[0045] Some embodiments of the present invention may include one or more of the following features, characteristics, or advantages, or a combination thereof: (i) the message queuing system may be a Kafka system, particularly version 0.9.0 or higher, although any other message queuing system may be deployed when implementing various embodiments of the present invention; (ii) the method of the present invention may be independent of the underlying message queuing system; (iii) the method may also include a message producer consulting an encryption policy system before sending a topic-related message, whereby the message producer may determine whether a message related to a particular topic should be encrypted before sending it to the message queuing system; (iv) the method may include a message producer consulting an encryption policy database (e.g., a key management system) when the message producer determines that the encryption policy database contains rules for encrypting topic-related messages, i.e., based on the selected topic, and (v) the key management system and the encryption policy system may be implemented within the same security system (e.g., the key management system may be a service of the encryption policy system, thereby realizing centralized control of security rules and associated keys for encryption and decryption, specifically outside the control of the message queuing system operator); and / or (vi) the key management system and the encryption policy system may be accessible at different locations (e.g., the encryption database system and the key management system may be implemented independently of each other, thus further increasing the security level achieved) (note that different authentication methods may have to be used to access the encryption database system and the key management system).

[0046] Some embodiments of the present invention may include one or more of the following features, characteristics, or advantages, or a combination thereof: (i) an operation in which, when a message is received by a message consumer, specifically a message sent from a message queuing system, a message consumer may be enabled to distinguish between encrypted and unencrypted messages from a message queuing system and a message receiver may not be enabled to process them separately, and the operation in which, when a message is received by a message consumer, a message consumer may refer to an encryption policy system to determine whether the received message is encrypted; (ii) a message consumer may be enabled to distinguish between encrypted and unencrypted messages from a message queuing system and a message receiver may process them separately, and a message consumer may refer to an encryption policy system to determine whether the received message is encrypted; (iii) a message consumer may be enabled to distinguish between encrypted and unencrypted messages from a message queuing system and a message receiver may process them separately; (iv) a message consumer may be enabled to determine whether a message is encrypted if a decryption key should be associated with the encryption key with which the message was encrypted, and the key may be stored by a topic, and the message receiver may request the decryption key by referencing the topic, and the message receiver may then use the received decryption key to decrypt the received message; (iii) an operation of receiving a decryption key by a message consumer, specifically from a key management system, upon determining that the message is to be encrypted, specifically after an associated request; (iv) an operation of recording access to the encryption policy system; (v) an operation of recording access to the key management system, such that a secure audit trail may be established for the encryption policy system as well as for the key management system, and all accesses, key retrievals, and modifications may be traceable at any time, including to unauthorized users or attempts to access the system; (vi) whether a message sent to a message consumer is decrypted (e.g., made readable by a specific identifiable user), and all accesses, key retrievals, and modifications may be tracked; (vii) an encrypted message received by a message queuing system may be digitally signed;and / or (viii) the encrypted message received by the message queuing system includes a message authentication code, specifically a keyed-hash message authentication code (HMAC), to ensure the integrity of the signer of the encrypted message as well as the integrity of the message (e.g., it can be proven that no bits have been altered on the path from the message producer to the message consumer), and a subscription for the message can include the first encrypted message only when the message authentication code is provided by the second entity;

[0047] FIG. 5 shows a flow chart 600 illustrating a second method in accordance with the present invention.

[0048] The process begins in step S602, where the key management system determines a first encryption level. The encryption level refers to the type and / or degree of encryption. The encryption levels are provided in a topic-based list according to an encryption policy. Messages are encrypted according to the message's associated topic.

[0049] Processing continues at step S604, where the key management system provides encryption keys to users who wish to store messages within the file system of a message queuing system such as Kafka. In some embodiments of the invention, key access is controlled such that users must be authenticated before the keys are provided.

[0050] The process continues to step S606, where the key management system stores the encrypted message. A user encrypts a message associated with a given topic and provides the encrypted message to a broker for storage in the file system of the message queuing system.

[0051] Processing continues at step S608, where the key management system receives a request for an encrypted message. A consumer may subscribe to the message queuing system and select several topics of interest. When messages associated with the subscribed topics are stored, the consumer may request the messages. In some embodiments of the invention, the consumer receives notification of messages on a particular topic and submits the request after the notification. Alternatively, a request is generated automatically for each consumer subscribed to a particular topic.

[0052] The process continues at step S610, where the key management system identifies a decryption key corresponding to the encrypted message. The decryption keys are stored according to topic, such that a decryption key can be identified for a given message on a particular topic via an encryption policy system. Identifying the decryption key may include referencing the topic-based encryption policy to determine whether a subscription for messages associated with the first topic includes the first encrypted message.

[0053] Processing ends at step S612, where the key management system sends the encrypted message and the corresponding decryption key to the consumer. In some embodiments of the present invention, the decryption key is sent to the consumer when the encrypted message is sent to the consumer and it is determined that a decryption key is needed. Alternatively, the consumer receives the encrypted message and requests the decryption key to decrypt the message.

[0054] Embodiments of the present invention can be implemented in conjunction with virtually any type of computer platform suitable for storing and / or executing program code. Figure 6 shows, by way of example, a computing system 500 suitable for executing program code relating to the proposed method.

[0055] Computing system 500 is merely one example of a suitable computer system, and whether computer system 500 may be implemented and / or computer system 500 may perform any of the aforementioned functions does not suggest any limitation as to the scope of use or functionality of the embodiments of the invention described herein. There are components in computer system 500 that are operable with numerous other general-purpose or special-purpose computing system environments or configurations. Examples of well-known computing systems, environments, or configurations, or combinations thereof, that may be suitable for use with computer system / server 500 include, but are not limited to, personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and distributed cloud computing environments that include any of the above systems or devices. The computer system / server 500 may be described in the general context of computer system-executable instructions, such as program modules, being executed by the computer system 500. Generally, program modules may include routines, programs, objects, components, logic, data structures, etc. that perform particular tasks or implement particular abstract data types. The computer system / server 500 may be practiced in a distributed cloud computing environment where tasks are performed by remote processing devices that are linked through a communications network. In a distributed cloud computing environment, program modules may be located in both local and remote computer system storage media, including memory storage devices.

[0056] As shown in the figure, computer system / server 500 is illustrated in the form of a general-purpose computing device. Components of computer system / server 500 may include, but are not limited to, one or more processors or processing units 502, a system memory 504, and a bus 506 that couples various system components, including the system memory 504, to the processor 502. Bus 506 is a communications fabric that may represent any one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus using any of a variety of bus architectures. By way of example and not limitation, such architectures include an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MCA) bus, an Enhanced ISA (EISA) bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnects (PCI) bus. Computer system / server 500 typically includes a variety of computer system-readable media. Such media may be any available media that is accessible by computer system / server 500 and includes both volatile and non-volatile media, removable and non-removable media.

[0057] The system memory 504 may include computer-system-readable media in the form of volatile memory, such as random access memory (RAM) 508 and / or cache memory 510. The computer system / server 500 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 512 may be provided for reading from and writing to a non-removable, non-volatile magnetic medium (not shown, typically referred to as a "hard drive"). Although not shown, a magnetic disk drive may be provided for reading from and writing to a removable, non-volatile magnetic disk (e.g., a "floppy disk"), and an optical disk drive may be provided for reading from and writing to a removable, non-volatile optical disk, such as a CD-ROM, DVD-ROM, or other optical medium. In such cases, each may be connected to the bus 506 by one or more data media interfaces. As further illustrated and described below, memory 504 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of embodiments of the present invention.

[0058] By way of example and not limitation, a program / utility having a set (at least one) of program modules 516, as well as an operating system, one or more application programs, other program modules, and program data, may be stored in memory 504. Each of the operating system, one or more application programs, other program modules, and program data, or some combination thereof, may include an implementation of a networking environment. The program modules 516 generally implement the functions and / or methods of embodiments of the present invention as described herein.

[0059] The computer system / server 500 may also communicate with one or more external devices 518, such as a keyboard, pointing device, display 520, one or more devices that allow a user to interact with the computer system / server 500, or any device that allows the computer system / server 500 to communicate with one or more other computing devices (e.g., a network card, modem, etc.), or a combination thereof. Such communication may occur via an input / output (I / O) interface 514. Additionally, the computer system / server 500 may communicate with one or more networks, such as a local area network (LAN), a general wide area network (WAN), or a public network (e.g., the Internet), or a combination thereof, via a network adapter 522. As shown, the network adapter 522 may communicate with other components of the computer system / server 500 via a bus 506. It should be understood that other hardware and / or software components, not shown, may be used with the computer system / server 500. Examples include, but are not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, data archive storage systems, and the like.

[0060] Additionally, at least a portion of the system 400 for targeted policy-based encryption on publish-subscribe messaging queues may be connected to a bus system 506. The complete system 400 may require multiple different computing systems 500 for different portions of the system, such as a message producer system, a message recipient system, a database system, a core message queuing system, a key management system, and an encryption policy system.

[0061] While the description of various embodiments of the present invention has been presented for illustrative purposes, the description is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terms used herein are chosen to best explain the principles of the embodiments, practical applications or technical improvements over technology found in the market, or to enable those skilled in the art to understand the embodiments disclosed herein.

[0062] The present invention may be embodied as a system, method, and / or computer program product, which may include one or more computer-readable storage media having computer-readable program instructions for causing a processor to implement aspects of the present invention.

[0063] The medium may be an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system for a propagation medium. Examples of computer-readable media may include semiconductor or solid-state memory, magnetic tape, removable computer diskettes, random access memory (RAM), read-only memory (ROM), rigid magnetic disks, and optical disks. Current examples of optical disks include compact disk-read-only memory (CD-ROM), compact disk-read / write (CD-R / W), DVD, and Blu-Ray disk.

[0064] A computer-readable storage medium may be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium may be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the above. A non-exhaustive list of more specific examples of computer-readable storage media includes: portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disk (DVD), memory sticks, floppy disks, punch cards, or mechanically encoded devices such as ridge structures in grooves with instructions recorded thereon, and any suitable combination of the above. As used herein, computer-readable storage media should not be construed as signals that are transitory in nature, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses through fiber optic cable), or electrical signals transmitted through wires.

[0065] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to each computing / processing device or to an external computer or storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network may include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface within each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the respective computing / processing device.

[0066] Computer-readable program instructions for carrying out operations of the present invention may be either source code or object code written in any combination of one or more programming languages, including assembler instructions, instruction set architecture (ISA) instructions, machine language instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk®, C++, and traditional procedural programming languages ​​such as the “C” programming language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, electronic circuitry including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) may execute computer readable program instructions to personalize the electronic circuitry by utilizing state information of the computer readable program instructions to implement aspects of the present invention.

[0067] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0068] These computer-readable program instructions may be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that the instructions, executed by the processor of the computer or other programmable data processing apparatus, produce means for implementing the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams, to create a machine. These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer, programmable data processing apparatus, or other device, or combination thereof, to function in a particular way, such that the computer-readable storage medium having the instructions stored thereon comprises an article of manufacture containing instructions that implement aspects of the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams.

[0069] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device such that the instructions, which execute on the computer, other programmable apparatus, or other device, implement the functions / acts specified in one or more blocks of the flowcharts and / or block diagrams, causing the computer, other programmable apparatus, or other device to perform a series of operational steps to create a computer-implemented process.

[0070] The flowcharts and / or block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowcharts or block diagrams may represent a module, segment, or portion of instructions, including one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions described in the blocks may occur in an order other than that described in the figures. For example, two blocks shown in succession may in fact be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending on the functionality involved. It will also be noted that each block in the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, may be implemented by a dedicated hardware-based system that performs the specified function or operation or a combination of dedicated hardware and computer instructions.

[0071] The terminology used in the specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the present invention. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms unless the context clearly dictates otherwise. It will be further understood that as used herein, the terms "comprises" and / or "comprising" specify the presence of stated features, integers, steps, operations, elements, or components, or combinations thereof, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, or groups thereof, or combinations thereof.

[0072] The corresponding structure, material, acts, and equivalents of all means or steps and functional elements in the following claims are intended to include any structure, material, or acts for performing the function as specifically claimed in combination with other claimed elements. The description of the present invention has been presented for purposes of illustration and description and is not intended to be exhaustive or limited to the invention in the form disclosed. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the invention. The embodiments are chosen and described in order to best explain the principles and practical applications of the invention and to enable those skilled in the art to understand the invention in various embodiments with various modifications as suited to the particular uses contemplated.

[0073] Some useful definitions follow:

[0074] The Present Invention: The subject matter described by the term "the present invention" should not be understood as an absolute indication that it is encompassed by the claims as filed or by the claims that may ultimately be issued after patent prosecution; the term "the present invention" is used to help the reader gain a general impression of the disclosures herein that are believed to be new, but as indicated by the use of the term "the present invention," this understanding is tentative and provisional, and is subject to change during patent prosecution as relevant information comes to light and the claims are potentially revised.

[0075] Embodiments: See definition of "present invention" above. A similar caution applies to the term "embodiments."

[0076] and / or: inclusive disjunction, e.g., A, B, "and / or" C means that at least one of A or B or C is true or true.

[0077] User / Subscriber: Includes, but is not necessarily limited to: (i) a single individual human being, (ii) an artificially intelligent entity with sufficient intelligence to act as a user or subscriber, or (iii) a group of related users or subscribers, or any combination thereof.

[0078] Module / Sub-Module: Any set of hardware, firmware, or software, or combination thereof, operable to perform some type of function, whether the modules are (i) in a single local proximity, (ii) distributed over a wide area, (iii) in a single proximity within a larger body of software code, (iv) located within a single body of software code, (v) located within a single storage device, memory, or medium, (vi) mechanically connected, (vii) electrically connected, or (viii) connected in data communication, or any combination thereof.

[0079] Computer: Any device having significant data processing and / or machine-readable instruction capabilities, including, but not limited to, desktop computers, mainframe computers, laptop computers, field programmable gate array (FPGA)-based devices, smart phones, personal digital assistants (PDAs), body-mounted or inserted computers, embedded device-style computers, and application-specific integrated circuit (ASIC)-based devices.

[0080] Some embodiments of the present invention are directed to one or more of the following inventive concepts.

[0081] A computer-implemented method for targeted policy-based encryption in publish-subscribe messaging queues, the method including: (i) receiving an encrypted message by a message queuing system, the message being encrypted by referencing an encryption policy system and a key management system that stores topic-associated encryption keys; (ii) storing the received encrypted message; and (iii) sending the encrypted message based on a subscription to the topic.

[0082] The Kafka system is a message queuing system.

[0083] Targeted policy-based encryption on publish-subscribe messaging queues, including the ability for message producers to consult an encryption policy system before sending topic-related messages.

[0084] Targeted policy-based encryption on publish-subscribe messaging queues, including receiving an encryption key from a key management system if the message producer determines that an encryption policy database contains rules that enforce encryption of topic-related messages and the message producer is authorized to receive the encryption key.

[0085] The key management system and encryption policy system are implemented in the same security system.

[0086] A key management system and encryption policy system that are accessible in different locations.

[0087] Targeted policy-based encryption on publish-subscribe messaging queues involves consulting an encryption policy system when a sent message is received by a message consumer to determine whether the received message should be encrypted.

[0088] Targeted policy-based encryption on publish-subscribe messaging queues includes (i) receiving a decryption key by a message consumer upon determining that a received message is encrypted, and (ii) decrypting the received message.

[0089] Targeted policy-based encryption on publish-subscribe messaging queues, including operations logging access to the encryption policy system.

[0090] Targeted policy-based encryption on publish-subscribe messaging queues, including logging access to the key management system.

[0091] Encrypted messages received by the message queuing system are digitally signed.

[0092] An encrypted message received by the message queuing system includes a message authentication code.

[0093] A computer system for targeted policy-based encryption in a publish-subscribe messaging queue, comprising: (i) a message queuing system adapted to receive encrypted messages, the messages being encrypted by reference to an encryption policy system and a key management system that stores topic-related encryption keys; (ii) means for storing the received encrypted messages; and (iii) means for sending the encrypted messages based on subscriptions to the topics.

[0094] A computer system for targeted policy-based encryption in publish-subscribe messaging queues, the computer system adapted to receive an encryption key from a key management system if the message producer is authorized to receive the encryption key when the message producer determines that an encryption policy database contains rules that enforce encryption of topic-related messages.

Claims

1. A computer-implemented method for a key management system, a cryptographic policy system, and a message queuing system, the computer-implemented method comprising: receiving, by the encryption policy system, a request from a first entity to determine whether a first topic requires encryption for storage in the message queuing system, the first topic being associated with a first message, the first topic indicating a theme or headline for the message; In response to receiving the request, the encryption policy system determines that the first topic requires a first encryption level by referencing a topic-based encryption policy; the key management system providing an encryption key to a first entity for encrypting the first message according to the first encryption level to generate a first encrypted message; the message queuing system storing the first encrypted message according to the first topic; receiving, by the message queuing system, a request from a second entity for the first message associated with the first topic, the first message including the first encrypted message; the message queuing system sending the first encrypted message to the second entity; identifying, by the key management system, a decryption key corresponding to the first encrypted message associated with the first topic according to the topic-based encryption policy, wherein the decryption key is assigned to the first topic by the topic-based encryption policy; the key management system providing the second entity with a decryption key for decrypting the first encrypted message; Including, wherein the first encrypted message stored in the message queuing system includes a message authentication code, the message authentication code ensuring the integrity of the first encrypted message. The computer-implemented method.

2. recording in a logging system the providing of the encryption key to the first entity for generating the first encrypted message and the sending of the decryption key for the first encrypted message to the second entity. The computer-implemented method of claim 1 , further comprising:

3. In response to an update to the topic-based encryption policy, logging the update in the logging system. The computer-implemented method of claim 2 further comprising:

4. 2. The computer-implemented method of claim 1, wherein the message authentication code comprises a keyed-hash message authentication code (HMAC).

5. establishing a subscription account for the second entity, including assigning an authenticating credential to the second entity; the request is received when the second entity subscribes to the first topic via the subscription account; The computer-implemented method of claim 1 , further comprising:

6. The processor receiving, as an encryption policy system, a request from a first entity to determine whether a first topic requires encryption for storage in a message queuing system, the first topic being associated with a first message, the first topic indicating a theme or headline for the message; causing the encryption policy system, in response to receiving the request, to determine that the first topic requires a first encryption level by referencing a topic-based encryption policy; having a first entity provide an encryption key for encrypting the first message according to the first encryption level to generate a first encrypted message as a key management system; storing the first encrypted message according to the first topic as a message queuing system, wherein the first encrypted message is stored within a targeted topic of the first encrypted message; As a message queuing system, the first encrypted message is receiving a request from a second entity for the first message associated with the first topic including: sending the first encrypted message to the second entity as a message queuing system; causing a key management system to identify a decryption key corresponding to the first encrypted message associated with the first topic in accordance with the topic-based encryption policy, wherein the decryption key is stored according to topic and assigned to the first topic by the topic-based encryption policy; providing a second entity with a decryption key for decrypting the first encrypted message as a key management system; 1. A computer program product for implementing topic-based encryption on a publish-subscribe messaging queue by causing the computer program product to execute: wherein the first encrypted message stored in the message queuing system includes a message authentication code, the message authentication code ensuring the integrity of the first encrypted message. The computer program.

7. the processor, recording in a logging system the providing of the encryption key to the first entity for generating the first encrypted message and the sending of the decryption key for the first encrypted message to the second entity.

7. The computer program product of claim 6, further comprising:

8. the processor, In response to an update to the topic-based encryption policy, logging the update in the logging system.

8. The computer program product of claim 7, further comprising:

9. the processor, establishing a subscription account for the second entity, including assigning an authenticating credential to the second entity; the request is received when the second entity subscribes to the first topic via the subscription account; 7. The computer program product of claim 6, further comprising:

10. 1. A computer system comprising: It includes a key management system, an encryption policy system, and a message queuing system. receiving a request from a first entity by an encryption policy system to determine whether a first topic requires encryption for storage in a message queuing system, the first topic being associated with a first message and indicating a theme or headline for the message; an encryption policy system, in response to receiving the request, determining that the first topic requires a first encryption level by referencing a topic-based encryption policy; a key management system providing an encryption key to a first entity for encrypting the first message according to the first encryption level to generate a first encrypted message; a message queuing system storing the first encrypted message within the message queuing system according to the first topic, wherein the first encrypted message is stored within a targeted topic of the first encrypted message; receiving, by a message queuing system, a topic request from a second entity for messages associated with the first topic, including the first encrypted message; a message queuing system sending the first encrypted message to the second entity; a key management system identifying, in accordance with the topic-based encryption policy, a decryption key corresponding to the first encrypted message associated with the first topic, wherein the decryption key is stored according to topic and was assigned to the first topic by the topic-based encryption policy; the key management system providing a decryption key to the second entity for decrypting the first encrypted message; 10. A computer system executing the program instructions to cause the set of processors to perform topic-based encryption on a publish-subscribe messaging queue by: wherein the first encrypted message stored in the message queuing system includes a message authentication code, the message authentication code ensuring the integrity of the first encrypted message. The computer system.

Citation Information

Patent Citations

  • Message processing apparatus and processing method thereof

    US20100067695A1

  • Topic protection policy for publish-subscribe messaging system

    US20140372748A1