Electronic apparatus for managing data encryption key

The electronic device addresses the challenge of managing data encryption keys by generating and managing keys through multiple encryption devices, ensuring key integrity and availability even in failure scenarios.

WO2025127307A1PCT designated stage expired Publication Date: 2025-06-19SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/011611
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-26
Filing Date
2024-08-06
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Existing systems for managing data encryption keys face challenges in ensuring the integrity and availability of encryption keys, particularly when failures occur in key decryption systems or when encryption key data is damaged or lost.

Method used

An electronic device is designed to generate and manage data encryption keys by transmitting these keys to multiple key encryption devices for encryption and storage, allowing for the recovery of damaged or lost encryption key data through redundant systems.

Benefits of technology

The solution ensures the electronic device can obtain a normal data encryption key for decrypting encrypted data even if failures occur in key decryption systems or if encryption key data is damaged or lost, thereby maintaining system operation and data integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024011611_19062025_PF_FP_ABST
    Figure KR2024011611_19062025_PF_FP_ABST
Patent Text Reader

Abstract

An electronic apparatus: generates a data encryption key (DEK); transmits a first DEK encryption request message including the DEK to a first DEK encryption apparatus; transmits a second DEK encryption request message including the DEK to a second DEK encryption apparatus; receives, from the first DEK encryption apparatus, a first DEK encryption response message including a first encrypted DEK (EDEK) generated by encrypting the DEK by using a first KEK, and identification information of the first KEK; receives, from the second DEK encryption apparatus, a second DEK encryption response message including a second EDEK generated by encrypting the DEK by using a second KEK, and identification information of the second KEK; stores the first EDEK, identification information of the DEK, and the identification information of the first KEK in a first storage area of a memory corresponding to the first DEK encryption apparatus; and stores the second EDEK, the identification information of the DEK, and the identification information of the second KEK in a second storage area of the memory corresponding to the second DEK encryption apparatus.
Need to check novelty before this filing date? Find Prior Art

Description

Electronic device for managing data encryption keys

[0001] Embodiments of the present disclosure relate to an electronic device for managing keys used to encrypt and decrypt data.

[0002] A data management system can encrypt data using envelope encryption. For example, a first electronic device (e.g., a key management system (KMS)) can generate a data encryption key (DEK) and encrypt data using the DEK in response to a request from a client device. The first electronic device can return the encrypted data to the client device along with identification information of the DEK used to encrypt the data. The first electronic device can request the generation of a key encryption key (KEK) from a second electronic device (e.g., a cloud service provider (CSP)). In response to the request, the second electronic device can generate a key encryption key (KEK) and convert the identification information of the KEK to the first electronic device. The first electronic device can request the second electronic device to encrypt the DEK by transmitting the DEK to the second electronic device along with the identification information of the KEK. In response to the request, the second electronic device may encrypt (or, in other words, wrap) the DEK using a KEK corresponding to the identification information of the KEK received from the first electronic device. The second electronic device may return the encrypted DEK (EDEK) to the first electronic device together with the identification information of the KEK used to encrypt the DEK. The first electronic device may store the EDEK received from the second electronic device in a storage in association with the identification information of the KEK used to encrypt the DEK and the identification information of the DEK.

[0003] The above information is provided as background information to aid in understanding the present disclosure. No claim or determination is made as to whether any of the above is applicable as prior art related to the present disclosure.

[0004] A data management system can decrypt encrypted data using envelope encryption. For example, a client device can request a DEK from a first electronic device by transmitting identification information of the DEK to the first electronic device. In response to the request, the first electronic device can request the second electronic device to decrypt the EDEK by obtaining an EDEK and KEK identification information related to the identification information of the DEK received from the client device from a storage and transmitting them to the second electronic device. In response to the request, the second electronic device can decrypt the EDEK using a KEK corresponding to the KEK identification information received from the first electronic device and return the DEK obtained through the decryption process to the first electronic device. The client device can receive the DEK through the first electronic device and decrypt the encrypted data using the received DEK.

[0005] If the EDEK managed by the first electronic device is damaged or lost, or if a system failure occurs in the second electronic device and the second electronic device does not respond to the request of the first electronic device, the first electronic device may not be able to obtain an intact DEK, and as a result, encrypted data may not be decrypted, which may cause a failure in system operation (e.g., application execution) on the client device.

[0006] Various embodiments may provide an electronic device capable of obtaining a normal DEK for decrypting encrypted data.

[0007] Various embodiments may provide an electronic device that can obtain a normal DEK even if a failure occurs in a system for decrypting the EDEK or the EDEK is damaged or lost.

[0008] Various embodiments may provide an electronic device capable of recovering a damaged EDEK.

[0009] The technical problems to be achieved in the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned can be clearly understood by a person having ordinary skill in the technical field to which the present invention belongs from the description below.

[0010] According to one embodiment, an electronic device includes a communication circuit; at least one processor; and a memory storing instructions. The instructions, when executed by the processor, may cause the electronic device to generate a data encryption key (DEK), transmit a first DEK encryption request message including the DEK to a first DEK encryption device through the communication circuit, and transmit a second DEK encryption request message including the DEK to a second DEK encryption device through the communication circuit. The instructions, when executed by the processor, may cause the electronic device to receive a first encrypted DEK (EDEK) generated by encrypting the DEK using a first KEK and a first DEK encryption response message including identification information of the first KEK from the first DEK encryption device, and receive a second DEK encryption response message including a second EDEK generated by encrypting the DEK using a second KEK and identification information of the second KEK from the second DEK encryption device. The instructions, when executed by the processor, may cause the electronic device to store the first EDEK, identification information of the DEK, and identification information of the first KEK in a first storage area of ​​the memory corresponding to the first DEK encryption device and to store the second EDEK, identification information of the DEK, and identification information of the second KEK in a second storage area of ​​the memory corresponding to the second DEK encryption device.

[0011] The instructions, when executed by the processor, may cause the electronic device to receive a DEK lookup request message from a client device via the communication circuit, the DEK lookup request message including identification information of the DEK, and, based on the reception of the DEK lookup request message, transmit a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device via the communication circuit. The instructions, when executed by the processor, may cause the electronic device to transmit a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device via the communication circuit, and transmit the first DEK received from the first DEK encryption device or the second DEK received from the second DEK encryption device to the client device via the communication circuit.

[0012] The instructions, when executed by the processor, may cause the electronic device to receive a DEK lookup request message from a client device via the communication circuit, wherein the DEK lookup request message includes identification information of the DEK, and, based on the reception of the DEK lookup request message, transmit a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device via the communication circuit. The instructions, when executed by the processor, may cause the electronic device to transmit a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device via the communication circuit, and, based on a mismatch between the first DEK received from the first DEK encryption device and the second DEK received from the second DEK encryption device, transmit a warning message to the client device.

[0013] The instructions, when executed by the processor, may cause the electronic device to transmit, to the first DEK encryption device through the communication circuit, a first EDEK decryption request message including identification information of the first EDEK and the first KEK, and to transmit, to the second DEK encryption device through the communication circuit, a second EDEK decryption request message including identification information of the second EDEK and the second KEK. The instructions, when executed by the processor, may cause the electronic device to decrypt encrypted data stored in the memory with the first DEK and the second DEK, and to compare sample data stored in the memory with the first DEK-based decryption data and the second DEK-based decryption data, based on a mismatch between the first DEK received from the first DEK encryption device and the second DEK received from the second DEK encryption device. The instructions, when executed by the processor, may cause the electronic device to transmit a third DEK encryption request message including the first DEK to the second DEK encryption device, based on the first DEK-based decryption data being identical to the sample data and the second DEK-based decryption data not matching the sample data, receive a third DEK encryption response message including a third EDEK from the second DEK encryption device, and store the third EDEK in the second storage area instead of the second EDEK.

[0014] The instructions, when executed by the processor, may cause the electronic device to transmit a third DEK encryption request message including the DEK to a third DEK encryption device through the communication circuit, and to receive a third EDEK generated by encrypting the DEK using a third KEK and a third DEK encryption response message including identification information of the third KEK from the third DEK encryption device. The instructions, when executed by the processor, may cause the electronic device to store the third EDEK, the identification information of the DEK, and the identification information of the third KEK in a third storage area of ​​the memory corresponding to the third DEK encryption device. The instructions, when executed by the processor, may cause the electronic device to transmit a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device through the communication circuit, a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device through the communication circuit, and a third EDEK decryption request message including identification information of the third EDEK and the third KEK to the third DEK encryption device through the communication circuit, based on receiving a DEK inquiry request message including identification information of the DEK from a client device through the communication circuit or a predetermined EDEK check time has arrived.The instructions, when executed by the processor, may cause the electronic device to transmit a fourth DEK encryption request message including the first DEK or the second DEK to the third DEK encryption device, based on a first DEK received from the first DEK encryption device and a second DEK received from the second DEK encryption device matching and a third DEK received from the third DEK encryption device not matching the first DEK and the second DEK, receive a fourth DEK encryption response message including a fourth EDEK from the third DEK encryption device, and store the fourth EDEK in the third storage area instead of the third EDEK.

[0015] According to embodiments of the present disclosure, an electronic device can obtain a normal DEK for decrypting encrypted data. The electronic device can obtain a normal DEK even if a system for decrypting the EDEK fails or the EDEK is damaged or lost. The electronic device can recover a damaged EDEK. In addition, various other benefits, directly or indirectly identified through this document, may be provided.

[0016] FIG. 1 is a block diagram of an electronic device within a network environment according to various embodiments.

[0017] Figure 2 is a block diagram of a data management system according to one embodiment.

[0018] FIG. 3 is a block diagram of a DEK encryption device according to one embodiment.

[0019] FIG. 4 is a flowchart illustrating operations for generating and storing an EDEK in an electronic device according to one embodiment.

[0020] FIG. 5 is a flowchart illustrating operations for responding to a DEK inquiry request in an electronic device according to one embodiment.

[0021] FIG. 6 is a flowchart illustrating operations for repairing a defective EDEK in an electronic device according to one embodiment.

[0022] FIG. 7 is a flowchart illustrating operations for repairing a defective EDEK in an electronic device according to one embodiment.

[0023] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings so that those skilled in the art can easily implement the present disclosure. However, the present disclosure may be implemented in various different forms and is not limited to the embodiments described herein. In connection with the description of the drawings, the same or similar reference numerals may be used for identical or similar components. Furthermore, in the drawings and related descriptions, descriptions of well-known functions and configurations may be omitted for clarity and conciseness.

[0024] FIG. 1 is a block diagram of an electronic device (101) within a network environment (100) according to various embodiments. Referring to FIG. 1, in the network environment (100), the electronic device (101) may communicate with an electronic device (102) via a first network (198) (e.g., a short-range wireless communication network), or may communicate with at least one of an electronic device (104) or a server (108) via a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with the electronic device (104) via the server (108). According to one embodiment, the electronic device (101) may include a processor (120), a memory (130), an input module (150), an audio output module (155), a display module (160), an audio module (170), a sensor module (176), an interface (177), a connection terminal (178), a haptic module (179), a camera module (180), a power management module (188), a battery (189), a communication module (190), a subscriber identification module (196), or an antenna module (197). In some embodiments, the electronic device (101) may omit at least one of these components (e.g., the connection terminal (178)), or may have one or more other components added. In some embodiments, some of these components (e.g., the sensor module (176), the camera module (180), or the antenna module (197)) may be integrated into one component (e.g., the display module (160)).

[0025] The processor (120) may, for example, execute software (e.g., a program (140)) to control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) and perform various data processing or calculations. According to one embodiment, as at least a part of the data processing or calculations, the processor (120) may store commands or data received from other components (e.g., a sensor module (176) or a communication module (190)) in a volatile memory (132), process the commands or data stored in the volatile memory (132), and store result data in a non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or a secondary processor (123) (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor)) that can operate independently or together therewith. For example, if the electronic device (101) includes a main processor (121) and a secondary processor (123), the secondary processor (123) may be configured to use less power than the main processor (121) or to be specialized for a specified function. The secondary processor (123) may be implemented separately from the main processor (121) or as a part thereof.

[0026] The auxiliary processor (123) may control at least a portion of functions or states associated with at least one component (e.g., a display module (160), a sensor module (176), or a communication module (190)) of the electronic device (101), for example, on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. In one embodiment, the auxiliary processor (123) (e.g., an image signal processor or a communication processor) may be implemented as a part of another functionally related component (e.g., a camera module (180) or a communication module (190)). In one embodiment, the auxiliary processor (123) (e.g., a neural network processing unit) may include a hardware structure specialized for processing artificial intelligence models. The artificial intelligence models may be generated through machine learning. This learning can be performed, for example, on the electronic device (101) itself where the artificial intelligence model is executed, or can be performed through a separate server (e.g., server (108)). The learning algorithm can include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model can include multiple artificial neural network layers.The artificial neural network may be one of a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to, or alternatively to, a hardware structure, an artificial intelligence model may include a software structure.

[0027] The memory (130) can store various data used by at least one component (e.g., processor (120) or sensor module (176)) of the electronic device (101). The data can include, for example, software (e.g., program (140)) and input data or output data for commands related thereto. The memory (130) can include volatile memory (132) or non-volatile memory (134).

[0028] The program (140) may be stored as software in the memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).

[0029] The input module (150) can receive commands or data to be used in a component of the electronic device (101) (e.g., a processor (120)) from an external source (e.g., a user) of the electronic device (101). The input module (150) can include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).

[0030] The audio output module (155) can output audio signals to the outside of the electronic device (101). The audio output module (155) can include, for example, a speaker or a receiver. The speaker can be used for general purposes, such as multimedia playback or recording playback. The receiver can be used to receive incoming calls. In one embodiment, the receiver can be implemented separately from the speaker or as part of the speaker.

[0031] The display module (160) can visually provide information to an external party (e.g., a user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling the device. In one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of a force generated by the touch.

[0032] The audio module (170) can convert sound into an electrical signal, or vice versa, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150), output sound through the sound output module (155), or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphone) directly or wirelessly connected to the electronic device (101).

[0033] The sensor module (176) can detect the operating status (e.g., power or temperature) of the electronic device (101) or the external environmental status (e.g., user status) and generate an electrical signal or data value corresponding to the detected status. According to one embodiment, the sensor module (176) can include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0034] The interface (177) may support one or more designated protocols that may be used to directly or wirelessly connect the electronic device (101) with an external electronic device (e.g., the electronic device (102)). In one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.

[0035] The connection terminal (178) may include a connector through which the electronic device (101) may be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0036] A haptic module (179) can convert electrical signals into mechanical stimuli (e.g., vibration or movement) or electrical stimuli that a user can perceive through tactile or kinesthetic sensations. In one embodiment, the haptic module (179) can include, for example, a motor, a piezoelectric element, or an electrical stimulation device.

[0037] The camera module (180) can capture still images and videos. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.

[0038] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented, for example, as at least a part of a power management integrated circuit (PMIC).

[0039] A battery (189) may power at least one component of the electronic device (101). In one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0040] The communication module (190) may support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may operate independently from the processor (120) (e.g., application processor) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module (194) (e.g., a local area network (LAN) communication module, or a power line communication module). Among these communication modules, the corresponding communication module can communicate with an external electronic device (104) via a first network (198) (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network (199) (e.g., a long-range communication network such as a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules can be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can verify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) by using subscriber information (e.g., an international mobile subscriber identity (IMSI)) stored in the subscriber identification module (196).

[0041] The wireless communication module (192) can support 5G networks and next-generation communication technologies following the 4G network, such as NR access technology (new radio access technology). The NR access technology can support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimization of terminal power and connection of multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency (URLLC (ultra-reliable and low-latency communications)). The wireless communication module (192) can support, for example, a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate. The wireless communication module (192) can support various technologies for securing performance in a high-frequency band, such as beamforming, massive multiple-input and multiple-output (MIMO), full dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), an external electronic device (e.g., the electronic device (104)), or a network system (e.g., the second network (199)). According to one embodiment, the wireless communication module (192) can support a peak data rate (e.g., 20 Gbps or more) for eMBB realization, a loss coverage (e.g., 164 dB or less) for mMTC realization, or a U-plane latency (e.g., 0.5 ms or less for downlink (DL) and uplink (UL), or 1 ms or less for round trip) for URLLC realization.

[0042] The antenna module (197) can transmit or receive signals or power to or from an external device (e.g., an external electronic device). In one embodiment, the antenna module (197) may include an antenna including a radiator formed of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). In one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as the first network (198) or the second network (199), may be selected from the plurality of antennas by, for example, the communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device through the selected at least one antenna. In some embodiments, in addition to the radiator, another component (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as a part of the antenna module (197).

[0043] According to various embodiments, the antenna module (197) may form a mmWave antenna module. According to one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent a first side (e.g., a bottom side) of the printed circuit board and capable of supporting a designated high-frequency band (e.g., a mmWave band), and a plurality of antennas (e.g., an array antenna) disposed on or adjacent a second side (e.g., a top side or a side side) of the printed circuit board and capable of transmitting or receiving signals in the designated high-frequency band.

[0044] At least some of the above components can be interconnected and exchange signals (e.g., commands or data) with each other via a communication method between peripheral devices (e.g., a bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)).

[0045] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) via a server (108) connected to a second network (199). Each of the external electronic devices (102 or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations executed in the electronic device (101) may be executed in one or more of the external electronic devices (102, 104, or 108). For example, when the electronic device (101) is to perform a certain function or service automatically or in response to a request from a user or another device, the electronic device (101) may, instead of or in addition to executing the function or service itself, request one or more external electronic devices to perform the function or at least a part of the service. One or more external electronic devices that receive the request may execute at least a portion of the requested function or service, or an additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may process the result as is or additionally and provide it as at least a portion of a response to the request. For this purpose, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used, for example. The electronic device (101) may provide an ultra-low latency service by using distributed computing or mobile edge computing, for example. In another embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server utilizing machine learning and / or a neural network. According to one embodiment, the external electronic device (104) or the server (108) may be included in the second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.

[0046] FIG. 2 is a block diagram of a data management system according to one embodiment. Referring to FIG. 2, the data management system may include a DEK management device (201), a client device (202), and a plurality of DEK encryption devices (203). The DEK management device (201) (e.g., the server (108) of FIG. 1) may include a first communication circuit (277), a first memory (288), and a first processor (299). The above components of the DEK management device (201) may be operatively, functionally, and / or electrically connected to each other. The first communication circuit (277), the first memory (288), and the first processor (299) may be implemented substantially identically to the communication module (190), the memory (130), and the processor (120) of FIG. 1, respectively, and thus may perform the same functions. The first memory (288) can store a program for DEK management (e.g., DEK generation, response to a DEK request from a client, recovery of a forged / modified EDEK). The first memory (288) can include volatile memory and non-volatile memory. A program (e.g., program (140) of FIG. 1) can be stored as instructions in the non-volatile memory and loaded into the volatile memory to be executed by the first processor (299). The program, when executed by the first processor (299), can cause the DEK management device (201) to perform given operations for DEK management. According to one embodiment, the program can include a DEK generation module (231), an EDEK storage module (233), a DEK provision module (235), and an EDEK recovery module (237).

[0047] The DEK generation module (231) can generate a DEK (data encryption key) used to encrypt data and decrypt the encrypted data. In addition, the DEK generation module (231) can generate an ID (identification) as identification information for identifying the generated DEK. For example, the DEK generation module (231) can receive a data encryption request message including data from a client device (202) (e.g., the electronic device (101) or the electronic device (104) of FIG. 1) through the first communication circuit (277). In response to the data encryption request, the DEK generation module (231) can generate a DEK and its ID. The DEK generation module (231) can reply to the client device (202) through the first communication circuit (277) a data encryption response message including encrypted data and a DEK ID using the generated DEK.

[0048] The EDEK storage module (233) can transmit a DEK encryption request message including the generated DEK to the DEK encryption devices (203) via the first communication circuit (277). The DEK generation module (231) can receive a DEK encryption response message including an encrypted DEK (hereinafter, EDEK) and the ID of the KEK used to encrypt the DEK from the DEK encryption devices (203) via the first communication circuit (277). The EDEK storage module (233) can store the EDEK and the KEK ID in the first memory (288).

[0049] The first memory (288) may include an EDEK storage (250) for storing EDEKs received from the DEK encryption devices (203). The EDEK storage module (233) may store the KEK ID and EDEK received from the DEK encryption devices (203) together with the corresponding DEK ID in the EDEK storage (250). According to one embodiment, the EDEK storage (250) may include storage areas corresponding to the DEK encryption devices (203), respectively. For example, referring to Table 1 below, the EDEK storage (250) may include a first storage area (251) for storing a KEK ID and EDEK received from a first DEK encryption device (221), a second storage area (252) for storing a KEK ID and EDEK received from a second DEK encryption device (222), and a third storage area (253) for storing a KEK ID and EDEK received from a third DEK encryption device (223).

[0050] First storage area (251) Second storage area (252) Third storage area (253) DEK IDKEK IDEDEKDEK IDKEK IDEDEKDEK IDKEK IDEDEK12A1KEK_A1(DEK_12)12B1KEK_B1(DEK_12)12C1KEK_C1(DEK_12)34A2KEK_A2(DEK_34)34B2KEK_B2(DEK_34)34C2KEK_C2(DEK_34)

[0051] The client device (202) may request a DEK from the DEK management device (201) to decrypt encrypted data in relation to a service (e.g., application execution). The DEK provision module (235) may receive a DEK inquiry request message including a DEK ID from the client device (202) via the first communication circuit (277). In response to the DEK inquiry request, the DEK provision module (235) may obtain the corresponding EDEK from the EDEK storage (250) and transmit an EDEK decryption request message including the obtained EDEK to the DEK encryption devices (203). The DEK provision module (235) may receive EDEK decryption response messages including the DEK from the DEK encryption devices (203). The DEK provision module (235) may transmit a DEK inquiry response message including the DEK to the client device (202) via the first communication circuit (277).

[0052] For example, referring to Table 1, if the ID of the DEK requested by the client device (202) is “12”, the DEK provision module (235) may obtain the KEK ID “A1” and EDEK “KEK_A1 (DEK_12)” corresponding to the DEK ID “12” from the first storage area (251) and transmit a first EDEK decryption request message including the obtained KEK ID and EDEK to the first DEK encryption device (221). The DEK provision module (235) may obtain the KEK ID “B1” and EDEK “KEK_B1 (DEK_12)” corresponding to the DEK ID “12” from the second storage area (252) and transmit a second EDEK decryption request message including the obtained KEK ID and EDEK to the second DEK encryption device (222). The DEK provision module (235) can obtain the KEK ID “C1” and EDEK “KEK_C1 (DEK_12)” corresponding to the DEK ID “12” from the third storage area (253) and transmit a third EDEK decryption request message including the obtained KEK ID and EDEK to the third DEK encryption device (223). EDEK decryption response messages including DEK_12 can be received from the DEK encryption devices (221, 222, 223). A DEK inquiry response message including DEK_12 can be transmitted to the client device (202) via the first communication circuit (277).

[0053] According to one embodiment, the DEK provision module (235) can obtain the DEK from the fastest arriving EDEK decryption response message and reply to the client device (202). This embodiment can be implemented in a data management system that requires a quick response to a request from the client device (202).

[0054] According to one embodiment, the DEK provision module (235) may transmit a DEK query response message including a DEK to the client device (202) via the first communication circuit (277) when EDEK decryption response messages are returned from all of the DEK encryption devices (203) and the DEKs obtained from the EDEK decryption response messages are all identical. This embodiment may be implemented in a data management system that requires high reliability of a response to a request from the client device (202). If the obtained DEKs do not match, the DEK provision module (235) may transmit a warning message indicating that the DEK is not reliable to the client device (202) via the first communication circuit (277).

[0055] The EDEK recovery module (237) can recover EDEKs that are found to have defects (e.g., forgery or alteration) among the EDEKs stored in the EDEK storage (250).

[0056] According to one embodiment, the DEK encryption devices (203) may be three or more as illustrated in FIG. 2. In response to a DEK inquiry request from a client device (202), the DEK provision module (235) may obtain DEKs from three or more DEK encryption devices (203). One of the three or more obtained DEKs may not match other DEKs. The EDEK recovery module (237) may determine that other DEKs that match each other are normal. The EDEK recovery module (237) may determine that the corresponding EDEK of one DEK that does not match other DEKs is defective. The EDEK recovery module (237) may recover the defective EDEK using a DEK that is determined to be normal among those obtained from the DEK encryption devices (203). The EDEK recovery module (237) can store the recovered EDEK in the EDEK storage (250) instead of the defective EDEK.

[0057] Referring to Table 1 for an example of the above embodiment, if the ID of the DEK requested for inquiry by the client device (202) is '34', the DEKs obtained from the first DEK encryption device (221) and the second DEK encryption device (222) may be the same as "DEK_34", whereas the DEK obtained from the third DEK encryption device (223) may not be "DEK_34". In such a case, the EDEK recovery module (237) may determine that the "KEK_C2 (DEK1_34)" stored in the third storage area (253) is defective. The EDEK recovery module (237) may transmit a DEK encryption request message including the obtained "DEK_34" to the third DEK encryption device (223). In response to the DEK encryption request, the EDEK recovery module (237) may receive a DEK encryption response message including the ID of the KEK used to encrypt the EDEK and DEK_34 from the third DEK encryption device (223). For example, as shown in Table 2 below, the EDEK recovery module (237) may receive “KEK_C3 (DEK_34)” encrypted using the KEK ID “C3” and “C3” from the third DEK encryption device (223) and store them in the third storage area (253) corresponding to the DEK ID “34”.

[0058] First storage area (251) Second storage area (252) Third storage area (253) DEK IDKEK IDEDEKDEK IDKEK IDEDEKDEK IDKEK IDEDEK12A1KEK_A1(DEK_12)12B1KEK_B1(DEK_12)12C1KEK_C1(DEK_12)34A2KEK_A2(DEK_34)34B2KEK_B2(DEK_34)34C3KEK_C3(DEK_34)

[0059] According to one embodiment, there may be three or more DEK encryption devices (203) as illustrated in FIG. 2. The EDEK recovery module (237) may check, at set intervals, whether the EDEKs stored in the EDEK storage (250) have defects (e.g., forgery or alteration). The EDEK recovery module (237) may recover a defective EDEK and store the recovered EDEK in the EDEK storage (250) instead of the defective EDEK.

[0060] Referring to Table 1 for an example of the above embodiment, when the inspection time of the EDEK corresponding to DEK ID “34” arrives according to a set cycle, the EDEK recovery module (237) may obtain the KEK ID “A2” and the EDEK “KEK_A2 (DEK_34)” from the first storage area (251) and transmit a first EDEK decryption request message including the obtained KEK ID and EDEK to the first DEK encryption device (221). The EDEK recovery module (237) may obtain the KEK ID “B2” and the EDEK “KEK_B2 (DEK_34)” from the second storage area (252) and transmit a second EDEK decryption request message including the obtained KEK ID and EDEK to the second DEK encryption device (222). The EDEK recovery module (237) may obtain the KEK ID “C2” and the EDEK “KEK_C2 (DEK_34)” from the third storage area (253) and transmit a third EDEK decryption request message including the obtained KEK ID and EDEK to the third DEK encryption device (223). As a response to the EDEK decryption request, the EDEK recovery module (237) may receive DEKs from the DEK encryption devices (203). The DEKs obtained from the first DEK encryption device (221) and the second DEK encryption device (222) may be the same as “DEK_34”, while the DEK obtained from the third DEK encryption device (223) may not be “DEK_34”. In such a case, the EDEK recovery module (237) may determine that the “KEK_C2 (DEK1_34)” stored in the third storage area (253) is defective. The EDEK recovery module (237) may transmit a DEK encryption request message including the acquired “DEK_34” to the third DEK encryption device (223).In response to the DEK encryption request, the EDEK recovery module (237) may receive a DEK encryption response message including the ID of the KEK used to encrypt the EDEK and DEK_34 from the third DEK encryption device (223). For example, as shown in Table 2 above, the EDEK recovery module (237) may receive “KEK_C3 (DEK_34)” encrypted using the KEK ID “C3” and “C3” from the third DEK encryption device (223) and store them in the third storage area (253) corresponding to the DEK ID “34”.

[0061] According to one embodiment, there may be two or more DEK encryption devices (203). Sample data (in other words, first data) used to check for defects in the EDEK and encrypted data (in other words, second data) generated by encrypting the sample data using the DEK may be stored in the EDEK storage (250). For example, as shown in Table 3 below, the DEK generation module (231) may generate encrypted data by encrypting the sample data using the generated DEK when generating the DEK. The DEK generation module (231) may store the encrypted data in the fourth storage area (254) of the EDEK storage (250) in association with the corresponding DEK ID and sample data. The EDEK recovery module (237) may obtain a DEK from a plurality of DEK encryption devices in response to a DEK inquiry request from a client device (202) or at a set cycle. The EDEK recovery module (237) may verify that the obtained plurality of DEKs are not identical to each other. Accordingly, the EDEK recovery module (237) can decrypt the encrypted data stored in the fourth storage area (254) with multiple DEKs. The EDEK recovery module (237) can compare each decrypted data with sample data. The EDEK recovery module (237) can determine that the DEK corresponding to the decrypted data that is identical to the sample data is normal, and determine that the EDEK corresponding to the decrypted data that does not match the sample data is defective. The EDEK recovery module (237) can recover a defective EDEK using a DEK that is determined to be normal among those obtained from the DEK encryption devices (203). The EDEK recovery module (237) can store the recovered EDEK in the EDEK storage (250) instead of the defective EDEK.

[0062] 4th storage area (254) DEK ID sample data encrypted data 12abcdDEK-12(abcd)34efghDEK-34(efgh)

[0063] Referring to Tables 2 and 3 for an example of the above embodiment, among the EDEKs stored in the EDEK storage (250), the target of inspection may be the EDEK corresponding to DEK ID “34”. The EDEK recovery module (237) can obtain the DEK corresponding to DEK ID “34” (hereinafter, the first DEK) from the first DEK encryption device (221). The EDEK recovery module (237) can obtain the DEK corresponding to DEK ID “34” (hereinafter, the third DEK) from the third DEK encryption device (223). The EDEK recovery module (237) can decrypt “DEK-34(efgh)” with the first DEK and the third DEK based on the fact that the first DEK and the third DEK are not identical. The EDEK recovery module (237) can compare each decrypted data with “efgh”. As a result of the comparison, the EDEK recovery module (237) can confirm that the first DEK-based decryption data is identical to “efgh” and the third DEK-based decryption data does not match “efgh”. Accordingly, the EDEK recovery module (237) can determine that the first DEK is normal and that the “KEK_C2 (DEK_34)” corresponding to the third DEK is defective. The EDEK recovery module (237) can transmit a DEK encryption request message including the first DEK determined to be normal to the third DEK encryption device (223). In response to the DEK encryption request, the EDEK recovery module (237) can receive a DEK encryption response message including the ID of the KEK used to encrypt the EDEK and DEK_34 from the third DEK encryption device (223). For example, as shown in Table 2 above, the EDEK recovery module (237) can receive encrypted “KEK_C3 (DEK_34)” using KEK ID “C3” and ‘C3’ from the third DEK encryption device (223) and store them in the third storage area (253) corresponding to the DEK ID “34”.

[0064] Table 3 illustrates, but is not limited to, the sample data being different for each DEK. For example, the EDEK recovery module (237) can use a single sample data for EDEK integrity verification.

[0065] According to one embodiment, at least one storage area in the EDEK storage (250) may be provided in an external device (e.g., a cloud server). Accordingly, the DEK management device (201) can access the EDEK storage of the external device via the first communication circuit (277) to read and write data.

[0066] FIG. 3 is a block diagram of a DEK encryption device (301) according to one embodiment. Referring to FIG. 3, the DEK encryption device (301) may include a second communication circuit (377), a second memory (388), and a second processor (399). The components of the DEK encryption device (301) may be operatively, functionally, and / or electrically connected to each other. The second communication circuit (377), the second memory (388), and the second processor (399) may be implemented substantially identically to the communication module (190), the memory (130), and the processor (120) of FIG. 1, respectively, and thus may perform the same functions. The second memory (388) may store a program for responding to a request from the DEK management device (201) (e.g., generating a KEK, encrypting a DEK, decrypting an EDEK). The second memory (388) may include volatile memory and non-volatile memory. A program (e.g., program (140) of FIG. 1) may be stored as instructions in the non-volatile memory and loaded into the volatile memory to be executed by the second processor (399). When executed by the second processor (399), the program may cause the DEK encryption device (301) to perform given operations in response to a request from the DEK management device (201). According to one embodiment, the program may include a KEK generation module (331), a DEK encryption module (333), and an EDEK decryption module (335).

[0067] The KEK generation module (331) can generate a KEK (key encryption key) used to encrypt a DEK (data encryption key) and decrypt the encrypted DEK. The KEK generation module (331) can generate an ID (identification) as identification information for identifying the generated KEK. The KEK generation module (331) can store the KEK and the corresponding ID in the KEK storage (340) of the second memory (388) (e.g., see Table 4 below).

[0068] KEK IDKEKA1KEK_A1A2KEK_A2

[0069] The DEK encryption module (333) can receive a DEK encryption request message from a DEK management device (201) (e.g., an EDEK storage module (233) or an EDEK recovery module (237)). The DEK encryption module (333) can obtain a DEK from the DEK encryption request message, encrypt the obtained DEK using one of the KEKs stored in the KEK storage (340), include the EDEK together with the ID of the corresponding KEK in a DEK encryption response message, and transmit the DEK encryption response message to the DEK management device (201).

[0070] The EDEK decryption module (335) can receive an EDEK decryption request message from the DEK management device (201) (e.g., the DEK provision module (235) or the EDEK recovery module (237)). The EDEK decryption module (335) can obtain an EDEK and a KEK ID from the EDEK decryption request message, obtain a KEK of the obtained ID from a KEK storage (340), decrypt the EDEK using the obtained KEK to obtain a DEK, and transmit an EDEK decryption response message including the obtained DEK to the DEK management device (201).

[0071] According to one embodiment, at least one of the DEK encryption devices (203) of FIG. 2 may have the above configurations of the DEK encryption device (301).

[0072] According to one embodiment, a DEK encryption device (301) may be configured in a DEK management device (201) (e.g., server (108) of FIG. 1). For example, a KEK generation module (331), a DEK encryption module (333), an EDEK decryption module (335), and a KEK storage (340) may be stored in a first memory (288) and executed by a first processor (299).

[0073] FIG. 4 is a flowchart illustrating operations for generating and storing an EDEK in an electronic device according to one embodiment. When instructions (e.g., modules (231, 233) of FIG. 2) stored in a memory of an electronic device (e.g., DEK management device (201)) are executed by a processor of the electronic device, the operations of FIG. 4 may be performed by the electronic device.

[0074] In operation 410, the electronic device may generate a DEK used to encrypt data. For example, the electronic device may generate the DEK in response to a data encryption request from an external device (e.g., a client device (202)).

[0075] At operation 420, the electronic device may transmit a DEK encryption request message including the DEK generated at operation 410 to a plurality of DEK encryption devices.

[0076] In operation 430, the electronic device can receive a DEK encryption response message including identification information of the KEK used to encrypt the EDEK and the DEK generated by encrypting the DEK generated in operation 410 using the KEK from a plurality of DEK encryption devices.

[0077] As an example of operations 420 and 430, the electronic device may transmit a first DEK encryption request message including the DEK generated in operation 410 to a first DEK encryption device (221), and transmit a second DEK encryption request message including the DEK generated in operation 410 to a second DEK encryption device (222). The electronic device may receive a first DEK encryption response message including a first EDEK generated by encrypting the DEK generated in operation 410 using the first KEK and identification information of the first KEK from the first DEK encryption device (221). The electronic device may receive a second DEK encryption response message including a second EDEK generated by encrypting the DEK generated in operation 410 using the second KEK and identification information of the second KEK from the second DEK encryption device (222). The electronic device may additionally transmit the DEK generated in operation 410 to another DEK encryption device. For example, the electronic device may transmit a third DEK encryption request message including the DEK generated in operation 410 to the third DEK encryption device (223). The electronic device may receive a third DEK encryption response message including a third EDEK generated by encrypting the DEK generated in operation 410 using the third KEK and identification information of the third KEK from the third DEK encryption device (223).

[0078] In operation 440, the electronic device can obtain KEK identification information and EDEK from each of the multiple DEK encryption response messages, and store the obtained KEK identification information and EDEK in memory in a manner differentiated by DEK encryption device.

[0079] As an example of operation 440, the electronic device may store the identification information of the DEK generated in operation 410 and the identification information of the first KEK received from the first DEK encryption device (221) and the first EDEK in a first storage area (e.g., the first storage area (251) of FIG. 2) corresponding to the first DEK encryption device (221). The electronic device may store the identification information of the DEK generated in operation 410 and the identification information of the second KEK received from the second DEK encryption device (222) and the second EDEK in a second storage area (e.g., the second storage area (252) of FIG. 2) corresponding to the second DEK encryption device (222). The electronic device may additionally receive a DEK encryption response message from another DEK encryption device. For example, the electronic device may store the identification information of the DEK generated in operation 410 and the identification information of the third KEK received from the third DEK encryption device (223) and the third EDEK in a third storage area corresponding to the third DEK encryption device (223) (e.g., the third storage area (253) of FIG. 3).

[0080] FIG. 5 is a flowchart illustrating operations for responding to a DEK inquiry request in an electronic device according to one embodiment. When instructions (e.g., the DEK provision module (235) of FIG. 2) stored in a memory of an electronic device (e.g., the DEK management device (201)) are executed by a processor of the electronic device, the operations of FIG. 4 may be performed by the electronic device.

[0081] In operation 510, the electronic device may receive a DEK lookup request message including identification information of the DEK from an external device (e.g., the client device (202) of FIG. 2).

[0082] In operation 520, the electronic device may, in response to the DEK lookup request, transmit an EDEK decryption request message including the EDEK and KEK identification information corresponding to the DEK identification information received in operation 510 to a plurality of DEK encryption devices.

[0083] In operation 530, the electronic device may receive an EDEK decryption response message from a plurality of DEK encryption devices, the EDEK decryption response message including a DEK corresponding to the DEK identification information received in operation 510.

[0084] As an example of operations 520 and 530, the electronic device may obtain the identification information of the first KEK and the first EDEK corresponding to the DEK identification information received in operation 510 from a first storage area (e.g., the first storage area (251) of FIG. 2), and transmit a first EDEK decryption request message including the obtained identification information of the first KEK and the first EDEK to the first EDK encryption device (221). The electronic device may obtain the identification information of the second KEK and the second EDEK corresponding to the DEK identification information received in operation 510 from a second storage area (e.g., the second storage area (252) of FIG. 2), and transmit a second EDEK decryption request message including the obtained identification information of the second KEK and the second EDEK to the second EDK encryption device (222). The electronic device may receive a first EDEK decryption response message including a first DEK corresponding to the DEK identification information received in operation 510 from the first EDK encryption device (221). The electronic device may receive a second EDEK decryption response message including a second DEK corresponding to the DEK identification information received in operation 510 from the second EDK encryption device (222). The electronic device may additionally transmit an EDEK decryption request message to another DEK encryption device. For example, the electronic device may obtain identification information of a third KEK corresponding to the DEK identification information received in operation 510 and a third EDEK from a third storage area (e.g., the third storage area (253) of FIG. 2), and transmit a third EDEK decryption request message including the obtained identification information of the third KEK and the third EDEK to the third EDK encryption device (223). The electronic device may receive a third EDEK decryption response message including a third DEK corresponding to the DEK identification information received in operation 510 from the third EDK encryption device (223).

[0085] In operation 540, the electronic device may transmit a DEK query response message including a DEK received from a DEK encryption device to an external device that has requested the query. For example, the electronic device may obtain the DEK from the fastest arriving EDEK decryption response message and reply to the external device that has requested the query. As another example, the electronic device may reply to the external device that has requested the DEK query if EDEK decryption response messages are replied from all of the plurality of encryption devices and all DEKs obtained from the EDEK decryption response messages are identical. If even one of the obtained DEKs is not identical, the electronic device may send a warning message to the external device that has requested the query.

[0086] FIG. 6 is a flowchart illustrating operations for recovering a defective EDEK in an electronic device, according to one embodiment. When instructions (e.g., EDEK recovery modules (237) of FIG. 2) stored in a memory of an electronic device (e.g., DEK management device (201)) are executed by a processor of the electronic device, the operations of FIG. 6 may be performed by the electronic device.

[0087] In operation 610 (e.g., operation 530), the electronic device may receive a DEK from three or more DEK encryption devices.

[0088] In operation 620, the electronic device can verify that at least two out of three or more received DEKs match, except for one.

[0089] In operation 630, the electronic device may determine that two or more DEKs that match each other are normal DEKs and determine that the corresponding EDEK of one DEK that does not match the other DEKs is defective.

[0090] At operation 640, the electronic device may transmit a DEK encryption request message containing a normal DEK to the DEK encryption device that transmitted the DEK corresponding to the EDEK determined to be defective.

[0091] At operation 650, the electronic device may receive a DEK encryption response message including an EDEK from a DEK encryption device.

[0092] At operation 660, the electronic device may store the received EDEK in memory instead of the EDEK determined to be defective.

[0093] As an example of the operations described above in FIG. 6, the electronic device may receive a first EDEK decryption response message including a first DEK corresponding to the DEK identification information received in operation 510 from a first EDK encryption device (e.g., the first EDK encryption device (221) of FIG. 2). The electronic device may receive a second EDEK decryption response message including a second DEK corresponding to the DEK identification information received in operation 510 from a second EDK encryption device (e.g., the second EDK encryption device (222)). The electronic device may receive a third EDEK decryption response message including a third DEK corresponding to the DEK identification information received in operation 510 from a third EDK encryption device (e.g., the third EDK encryption device (223)). The electronic device may verify that the second DEK and the third DEK match each other and that the first DEK does not match another DEK. Based on the verification result, the electronic device may determine the second DEK and the third DEK as normal and determine the first EDEK corresponding to the first DEK as a defective EDEK. The electronic device may transmit a DEK encryption request message including the second DEK or the third DEK to the first EDK encryption device. The electronic device may receive a DEK encryption response message including the fourth EDEK from the first EDK encryption device. Instead of the first EDEK, the electronic device may store the fourth EDEK in a storage area corresponding to the first EDK encryption device (221) (e.g., the first storage area (251) of FIG. 2).

[0094] As another example of the operations described above in FIG. 6, when a designated time for checking whether there is a defect (e.g., forgery or tampering) in the EDEKs stored in the EDEK storage (250) has passed, the electronic device may obtain the ID of the first KEK and the corresponding first EDEK from the first storage area (e.g., the first storage area (251) of FIG. 2) and transmit the ID and the corresponding first EDEK to the first DEK encryption device (e.g., the first DEK encryption device (221)) by including them in a first EDEK decryption request message. The electronic device may obtain the ID of the second KEK and the corresponding second EDEK from the second storage area (e.g., the second storage area (252) of FIG. 2) by including them in a second EDEK decryption request message and transmit the ID and the corresponding second EDEK to the second DEK encryption device (e.g., the second DEK encryption device (222)). The electronic device can obtain the ID of the third KEK and the corresponding third EDEK from the third storage area (e.g., the third storage area (253) of FIG. 2), include the ID of the third KEK and the corresponding third EDEK in the third EDEK decryption request message, and transmit the same to the third DEK encryption device (e.g., the second DEK encryption device (222)). The electronic device can receive a first EDEK decryption response message including the first DEK from the first EDK encryption device. The electronic device can receive a second EDEK decryption response message including the second DEK from the second EDK encryption device. The electronic device can receive a third EDEK decryption response message including the third DEK from the third EDK encryption device. The electronic device can verify that the second DEK and the third DEK match each other and that the first DEK does not match any other DEK. Based on the verification results, the electronic device may determine that the second DEK and the third DEK are normal and determine that the first EDEK corresponding to the first DEK is defective. The electronic device may transmit a DEK encryption request message including the second DEK or the third DEK to the first EDK encryption device.The electronic device may receive a DEK encryption response message including a fourth EDEK from the first EDK encryption device. The electronic device may store the fourth EDEK in the first storage area instead of the first EDEK.

[0095] FIG. 7 is a flowchart illustrating operations for recovering a defective EDEK in an electronic device, according to one embodiment. When instructions (e.g., EDEK recovery modules (237) of FIG. 2) stored in a memory of an electronic device (e.g., DEK management device (201)) are executed by a processor of the electronic device, the operations of FIG. 7 may be performed by the electronic device.

[0096] In operation 710, the electronic device can determine that the first DEK received from the first DEK encryption device (e.g., the first DEK encryption device (221) of FIG. 2) and the second DEK received from the second DEK encryption device (e.g., the second DEK encryption device (222) of FIG. 2) do not match. The first DEK and the second DEK may be received based on a DEK inquiry request from an external device (e.g., the client device (202) of FIG. 2) or a set EDEK check cycle.

[0097] In operation 720, the electronic device may obtain encrypted data and sample data from a memory (e.g., the fourth storage area (254) of FIG. 2) and decrypt the obtained encrypted data using the first DEK and the second DEK. The electronic device may compare sample data corresponding to the obtained encrypted data with the first DEK-based decrypted data and the second DEK-based decrypted data.

[0098] At operation 730, the electronic device may determine that the first DEK is normal based on the first DEK-based decryption data being identical to the sample data. The electronic device may determine that the EDEK corresponding to the second DEK is defective based on the third DEK-based decryption data not being identical to the sample data.

[0099] At operation 740, the electronic device may transmit a DEK encryption request message including the first DEK to a second DEK encryption device.

[0100] In operation 750, the electronic device may receive a DEK encryption response message including an EDEK from a second DEK encryption device. The electronic device may store the received EDEK in memory instead of the EDEK determined to be defective.

[0101] According to one embodiment, an electronic device (e.g., a DEK management device (201) of FIG. 2) includes a communication circuit; at least one processor; and a memory storing instructions. The instructions, when executed by the processor, may cause the electronic device to generate a data encryption key (DEK), transmit a first DEK encryption request message including the DEK to a first DEK encryption device through the communication circuit, and transmit a second DEK encryption request message including the DEK to a second DEK encryption device through the communication circuit. The instructions, when executed by the processor, may cause the electronic device to receive, from the first DEK encryption device, a first DEK encryption response message including a first EDEK (encrypted DEK) generated by encrypting the DEK using a first KEK and identification information of the first KEK, and to receive, from the second DEK encryption device, a second DEK encryption response message including a second EDEK generated by encrypting the DEK using a second KEK and identification information of the second KEK. The instructions, when executed by the processor, may cause the electronic device to store the first EDEK, the identification information of the DEK, and the identification information of the first KEK in a first storage area of ​​the memory corresponding to the first DEK encryption device, and to store the second EDEK, the identification information of the DEK, and the identification information of the second KEK in a second storage area of ​​the memory corresponding to the second DEK encryption device.

[0102] The instructions, when executed by the processor, may cause the electronic device to receive a DEK lookup request message including identification information of the DEK from a client device via the communication circuit. The instructions, when executed by the processor, may cause the electronic device to transmit, based on the reception of the DEK lookup request message, a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device via the communication circuit, and a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device via the communication circuit. The instructions, when executed by the processor, may cause the electronic device to transmit, to the client device via the communication circuit, the first DEK received from the first DEK encryption device or the second DEK received from the second DEK encryption device.

[0103] The above instructions, when executed by the processor, may cause the electronic device to transmit, through the communication circuit, whichever comes first between the first DEK and the second DEK, to the client device.

[0104] The instructions, when executed by the processor, may cause the electronic device to transmit the first DEK or the second DEK to the client device based on whether the first DEK and the second DEK match.

[0105] The instructions, when executed by the processor, may cause the electronic device to receive a DEK lookup request message including identification information of the DEK from a client device through the communication circuit, and, based on the reception of the DEK lookup request message, transmit a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device through the communication circuit, and transmit a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device through the communication circuit. The instructions, when executed by the processor, may cause the electronic device to transmit a warning message to the client device based on a mismatch between the first DEK received from the first DEK encryption device and the second DEK received from the second DEK encryption device.

[0106] The instructions, when executed by the processor, may cause the electronic device to transmit, to the first DEK encryption device through the communication circuit, a first EDEK decryption request message including identification information of the first EDEK and the first KEK, and to transmit, to the second DEK encryption device through the communication circuit, a second EDEK decryption request message including identification information of the second EDEK and the second KEK. The instructions, when executed by the processor, may cause the electronic device to decrypt encrypted data stored in the memory with the first DEK and the second DEK, and to compare sample data stored in the memory with the first DEK-based decryption data and the second DEK-based decryption data, based on a mismatch between the first DEK received from the first DEK encryption device and the second DEK received from the second DEK encryption device. The instructions, when executed by the processor, may cause the electronic device to transmit a third DEK encryption request message including the first DEK to the second DEK encryption device based on the first DEK-based decryption data being identical to the sample data and the second DEK-based decryption data not being identical to the sample data. The instructions, when executed by the processor, may cause the electronic device to receive a third DEK encryption response message including a third EDEK from the second DEK encryption device and to store the third EDEK in the second storage area instead of the second EDEK.

[0107] The instructions, when executed by the processor, may cause the electronic device to transmit a third DEK encryption request message including the DEK to a third DEK encryption device through the communication circuit, and to receive a third EDEK generated by encrypting the DEK using a third KEK and a third DEK encryption response message including identification information of the third KEK from the third DEK encryption device. The instructions, when executed by the processor, may cause the electronic device to store the third EDEK, the identification information of the DEK, and the identification information of the third KEK in a third storage area of ​​the memory corresponding to the third DEK encryption device. The instructions, when executed by the processor, may cause the electronic device to transmit a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device through the communication circuit, a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device through the communication circuit, and a third EDEK decryption request message including identification information of the third EDEK and the third KEK to the third DEK encryption device through the communication circuit, based on receiving a DEK inquiry request message including identification information of the DEK from a client device through the communication circuit or a predetermined EDEK check time has arrived.The instructions, when executed by the processor, may cause the electronic device to transmit a fourth DEK encryption request message including the first DEK or the second DEK to the third DEK encryption device based on a first DEK received from the first DEK encryption device and a second DEK received from the second DEK encryption device matching and a third DEK received from the third DEK encryption device not matching the first DEK and the second DEK. The instructions, when executed by the processor, may cause the electronic device to receive a fourth DEK encryption response message including a fourth EDEK from the third DEK encryption device and to store the fourth EDEK in the third storage area instead of the third EDEK.

[0108] According to one embodiment, a method of operating an electronic device (e.g., a DEK management device (201) of FIG. 2) is provided. The method may include: generating a data encryption key (DEK); and transmitting a first DEK encryption request message including the DEK to a first DEK encryption device, and transmitting a second DEK encryption request message including the DEK to a second DEK encryption device. The method may further include receiving, from the first DEK encryption device, a first EDEK (encrypted DEK) generated by encrypting the DEK using a first KEK and a first DEK encryption response message including identification information of the first KEK, and receiving, from the second DEK encryption device, a second EDEK generated by encrypting the DEK using a second KEK and a second DEK encryption response message including identification information of the second KEK. And it may include an operation of storing the first EDEK, identification information of the DEK, and identification information of the first KEK in a first storage area corresponding to the first DEK encryption device, and storing the second EDEK, identification information of the DEK, and identification information of the second KEK in a second storage area corresponding to the second DEK encryption device.

[0109] The method may include: receiving a DEK lookup request message including identification information of the DEK from a client device; transmitting a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device based on the reception of the DEK lookup request message, and transmitting a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device; and transmitting the first DEK received from the first DEK encryption device or the second DEK received from the second DEK encryption device to the client device.

[0110] The operation of transmitting the first DEK or the second DEK to the client device may include an operation of transmitting, to the client device, whichever comes first between the first DEK and the second DEK.

[0111] The operation of transmitting the first DEK or the second DEK to the client device may include an operation of transmitting the first DEK or the second DEK to the client device based on the first DEK and the second DEK matching.

[0112] The method may include the following actions: receiving a DEK lookup request message including identification information of the DEK from a client device; and, based on the reception of the DEK lookup request message, transmitting a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device, and transmitting a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device. The method may include the action of transmitting a warning message to the client device based on a mismatch between the first DEK received from the first DEK encryption device and the second DEK received from the second DEK encryption device.

[0113] The method may include, based on a predetermined EDEK check time, transmitting a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device, and transmitting a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device. The method may include, based on a first DEK received from the first DEK encryption device and a second DEK received from the second DEK encryption device not matching, decrypting encrypted data with the first DEK and the second DEK and comparing sample data with the first DEK-based decryption data and the second DEK-based decryption data. The method may include transmitting a third DEK encryption request message including the first DEK to the second DEK encryption device based on the first DEK-based decryption data being identical to the sample data and the second DEK-based decryption data not matching the sample data; receiving a third DEK encryption response message including a third EDEK from the second DEK encryption device; and storing the third EDEK in the second storage area instead of the second EDEK.

[0114] The method may include: transmitting a third DEK encryption request message including the DEK to a third DEK encryption device; receiving a third DEK encryption response message including a third EDEK generated by encrypting the DEK using a third KEK and identification information of the third KEK from the third DEK encryption device; and storing the third EDEK, the identification information of the DEK, and the identification information of the third KEK in a third storage area of ​​the memory corresponding to the third DEK encryption device. The method may include, based on receiving a DEK inquiry request message including identification information of the DEK from a client device or a predetermined EDEK inspection time having arrived, transmitting a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device, transmitting a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device, and transmitting a third EDEK decryption request message including identification information of the third EDEK and the third KEK to the third DEK encryption device. The method may include transmitting a fourth DEK encryption request message including the first DEK or the second DEK to the third DEK encryption device based on the first DEK received from the first DEK encryption device and the second DEK received from the second DEK encryption device matching and the third DEK received from the third DEK encryption device not matching the first DEK and the second DEK. The method may include receiving a fourth DEK encryption response message including a fourth EDEK from the third DEK encryption device; and storing the fourth EDEK in the third storage area instead of the third EDEK.

[0115] According to one embodiment, a recording medium is provided that stores instructions readable by an electronic device (e.g., a DEK management device (201) of FIG. 2). The instructions, when executed by at least one processor of the electronic device, may cause the electronic device to perform the following operations: generating a data encryption key (DEK); and transmitting a first DEK encryption request message including the DEK to a first DEK encryption device and transmitting a second DEK encryption request message including the DEK to a second DEK encryption device. The instructions, when executed by a processor of the electronic device, may cause the electronic device to perform an operation of receiving, from the first DEK encryption device, a first EDEK (encrypted DEK) generated by encrypting the DEK using a first KEK and a first DEK encryption response message including identification information of the first KEK, and receiving, from the second DEK encryption device, a second EDEK generated by encrypting the DEK using a second KEK and a second DEK encryption response message including identification information of the second KEK. The instructions, when executed by the processor of the electronic device, may cause the electronic device to perform an operation of storing the first EDEK, the identification information of the DEK, and the identification information of the first KEK in a first storage area corresponding to the first DEK encryption device, and storing the second EDEK, the identification information of the DEK, and the identification information of the second KEK in a second storage area corresponding to the second DEK encryption device.

[0116] In the above explanation, the prefixes “first,” “second,” and “third” are only used to distinguish between the same names and do not have any special meaning in themselves, such as importance or order.

[0117] Electronic devices according to the various embodiments disclosed in this document may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to the embodiments of this document are not limited to the aforementioned devices.

[0118] The various embodiments of this document and the terminology used therein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases "A or B", "at least one of A and B", "at least one of A or B", "A, B, or C", "at least one of A, B, and C", and "at least one of A, B, or C" can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as "coupled" or "connected" to another component (e.g., a second component), with or without the terms "functionally" or "communicatively," it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.

[0119] The term "module" used in various embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. In one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0120] Various embodiments of the present document may be implemented as software (e.g., a program (140)) including one or more instructions stored in a storage medium (e.g., an internal memory (136) or an external memory (138)) readable by a machine (e.g., an electronic device (101)). For example, a processor (e.g., a processor (120)) of the machine (e.g., an electronic device (101)) may call at least one instruction among the one or more instructions stored from the storage medium and execute it. This enables the machine to operate to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently or temporarily on the storage medium.

[0121] According to one embodiment, the method according to various embodiments disclosed in this document may be provided as a computer program product. The computer program product may be traded between sellers and buyers as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or may be provided through an application store (e.g., Play Store). TM ) or directly between two user devices (e.g., smart phones), online distribution (e.g., downloading or uploading). In the case of online distribution, at least a portion of the computer program product may be at least temporarily stored or temporarily created in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.

[0122] According to various embodiments, each component (e.g., a module or a program) of the above-described components may include one or more entities, and some of the entities may be separated and placed in other components. According to various embodiments, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to various embodiments, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.

Claims

1. In electronic devices, communication circuit; a processor connected to said communication circuit; and A memory storing instructions executable by the processor, wherein the instructions, when executed by the processor, cause the electronic device to: Generate a DEK (data encryption key), Transmitting a first DEK encryption request message including the DEK to a first DEK encryption device through the communication circuit, and transmitting a second DEK encryption request message including the DEK to a second DEK encryption device through the communication circuit, Receiving a first DEK encryption response message including a first EDEK (encrypted DEK) generated by encrypting the DEK using the first KEK and identification information of the first KEK from the first DEK encryption device, and receiving a second DEK encryption response message including a second EDEK generated by encrypting the DEK using the second KEK and identification information of the second KEK from the second DEK encryption device, An electronic device that stores the identification information of the first EDEK, the DEK, and the identification information of the first KEK in a first storage area of ​​the memory corresponding to the first DEK encryption device, and stores the identification information of the second EDEK, the DEK, and the identification information of the second KEK in a second storage area of ​​the memory corresponding to the second DEK encryption device.

2. In the first paragraph, the instructions, when executed by the processor, cause the electronic device to: Receive a DEK inquiry request message including identification information of the DEK from a client device through the above communication circuit, Based on the reception of the DEK lookup request message, a first EDEK decryption request message including identification information of the first EDEK and the first KEK is transmitted to the first DEK encryption device through the communication circuit, and a second EDEK decryption request message including identification information of the second EDEK and the second KEK is transmitted to the second DEK encryption device through the communication circuit. An electronic device that transmits a first DEK received from the first DEK encryption device or a second DEK received from the second DEK encryption device to the client device through the communication circuit.

3. In the second paragraph, the instructions, when executed by the processor, cause the electronic device to: An electronic device that transmits, to the client device via the communication circuit, whichever of the first DEK and the second DEK comes first.

4. In the second paragraph, the instructions, when executed by the processor, cause the electronic device to: An electronic device that transmits the first DEK or the second DEK to the client device based on whether the first DEK and the second DEK match.

5. In the first paragraph, the instructions, when executed by the processor, cause the electronic device to: Receive a DEK inquiry request message including identification information of the DEK from a client device through the above communication circuit, Based on the reception of the DEK lookup request message, a first EDEK decryption request message including identification information of the first EDEK and the first KEK is transmitted to the first DEK encryption device through the communication circuit, and a second EDEK decryption request message including identification information of the second EDEK and the second KEK is transmitted to the second DEK encryption device through the communication circuit. An electronic device configured to transmit a warning message to the client device based on a mismatch between the first DEK received from the first DEK encryption device and the second DEK received from the second DEK encryption device.

6. In the first paragraph, the instructions, when executed by the processor, cause the electronic device to: Based on the predetermined EDEK inspection time having arrived, a first EDEK decryption request message including identification information of the first EDEK and the first KEK is transmitted to the first DEK encryption device through the communication circuit, and a second EDEK decryption request message including identification information of the second EDEK and the second KEK is transmitted to the second DEK encryption device through the communication circuit. Based on the fact that the first DEK received from the first DEK encryption device and the second DEK received from the second DEK encryption device do not match, the encrypted data stored in the memory is decrypted with the first DEK and the second DEK, and the sample data stored in the memory is compared with the first DEK-based decrypted data and the second DEK-based decrypted data, Based on the fact that the first DEK-based decryption data is identical to the sample data and the second DEK-based decryption data does not match the sample data, a third DEK encryption request message including the first DEK is transmitted to the second DEK encryption device, Receive a third DEK encryption response message including a third EDEK from the second DEK encryption device, An electronic device that stores the third EDEK in the second storage area instead of the second EDEK.

7. In the first paragraph, the instructions, when executed by the processor, cause the electronic device to: Transmitting a third DEK encryption request message including the above DEK to the third DEK encryption device through the communication circuit, Receive a third DEK encryption response message including a third EDEK generated by encrypting the above DEK using a third KEK and identification information of the third KEK from the third DEK encryption device; Store the identification information of the third EDEK, the identification information of the DEK, and the identification information of the third KEK in the third storage area of ​​the memory corresponding to the third DEK encryption device, Upon receipt of a DEK lookup request message containing identification information of the DEK from a client device through the above communication circuit or upon arrival of a predetermined EDEK check time: Transmitting a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device through the communication circuit, transmitting a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device through the communication circuit, and transmitting a third EDEK decryption request message including identification information of the third EDEK and the third KEK to the third DEK encryption device through the communication circuit, Based on the fact that the first DEK received from the first DEK encryption device and the second DEK received from the second DEK encryption device match and the third DEK received from the third DEK encryption device does not match the first DEK and the second DEK, a fourth DEK encryption request message including the first DEK or the second DEK is transmitted to the third DEK encryption device, Receive a 4th DEK encryption response message including a 4th EDEK from the 3rd DEK encryption device, Instead of the above third EDEK, the above fourth EDEK is stored in the above third storage area. Electronic devices.

8. In a method of operating an electronic device, The action of generating a DEK (data encryption key); An operation of transmitting a first DEK encryption request message including the DEK to a first DEK encryption device, and transmitting a second DEK encryption request message including the DEK to a second DEK encryption device; An operation of receiving a first DEK encryption response message including a first EDEK (encrypted DEK) generated by encrypting the DEK using a first KEK and identification information of the first KEK from the first DEK encryption device, and receiving a second DEK encryption response message including a second EDEK generated by encrypting the DEK using a second KEK and identification information of the second KEK from the second DEK encryption device; and A method comprising the steps of storing the first EDEK, identification information of the DEK, and identification information of the first KEK in a first storage area corresponding to the first DEK encryption device, and storing the second EDEK, identification information of the DEK, and identification information of the second KEK in a second storage area corresponding to the second DEK encryption device.

9. In paragraph 8, An action of receiving a DEK lookup request message including identification information of the DEK from a client device; An operation of transmitting a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device, and transmitting a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device based on the reception of the above DEK inquiry request message; and A method further comprising the action of transmitting the first DEK received from the first DEK encryption device or the second DEK received from the second DEK encryption device to the client device.

10. In the 9th paragraph, the operation of transmitting the first DEK or the second DEK to the client device comprises: A method comprising the action of transmitting, to the client device, one of the first DEK and the second DEK, whichever comes first.

11. In the 9th paragraph, the operation of transmitting the first DEK or the second DEK to the client device comprises: A method comprising the action of transmitting the first DEK or the second DEK to the client device based on a match between the first DEK and the second DEK.

12. In paragraph 8, An action of receiving a DEK lookup request message including identification information of the DEK from a client device; An operation of transmitting a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device, and transmitting a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device based on the reception of the above DEK inquiry request message; and A method further comprising the action of transmitting a warning message to the client device based on a mismatch between the first DEK received from the first DEK encryption device and the second DEK received from the second DEK encryption device.

13. In paragraph 8, An operation of transmitting a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device, and transmitting a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device based on a predetermined EDEK check time having arrived; An operation of decrypting encrypted data with the first DEK and the second DEK based on a mismatch between the first DEK received from the first DEK encryption device and the second DEK received from the second DEK encryption device, and comparing sample data with the first DEK-based decrypted data and the second DEK-based decrypted data; An operation of transmitting a third DEK encryption request message including the first DEK to the second DEK encryption device based on the first DEK-based decryption data being identical to the sample data and the second DEK-based decryption data not matching the sample data; An operation of receiving a third DEK encryption response message including a third EDEK from the second DEK encryption device; and A method further comprising the action of storing the third EDEK in the second storage area instead of the second EDEK.

14. In paragraph 8, An action of transmitting a third DEK encryption request message including the above DEK to a third DEK encryption device; An operation of receiving a third DEK encryption response message including a third EDEK generated by encrypting the DEK using a third KEK and identification information of the third KEK from the third DEK encryption device; An operation of storing the identification information of the third EDEK, the identification information of the DEK, and the identification information of the third KEK in a third storage area of ​​the memory corresponding to the third DEK encryption device; Upon receipt of a DEK lookup request message containing identification information of the DEK from a client device or upon arrival of a predetermined EDEK check time: An operation of transmitting a first EDEK decryption request message including identification information of the first EDEK and the first KEK to the first DEK encryption device, transmitting a second EDEK decryption request message including identification information of the second EDEK and the second KEK to the second DEK encryption device, and transmitting a third EDEK decryption request message including identification information of the third EDEK and the third KEK to the third DEK encryption device; An operation of transmitting a fourth DEK encryption request message including the first DEK or the second DEK to the third DEK encryption device based on the first DEK received from the first DEK encryption device and the second DEK received from the second DEK encryption device matching and the third DEK received from the third DEK encryption device not matching the first DEK and the second DEK; An operation of receiving a fourth DEK encryption response message including a fourth EDEK from the third DEK encryption device; and A method further comprising the action of storing the fourth EDEK in the third storage area instead of the third EDEK.

15. A recording medium storing instructions readable by an electronic device, wherein the instructions, when executed by a processor of the electronic device, cause the electronic device to: The action of generating a DEK (data encryption key); An operation of transmitting a first DEK encryption request message including the DEK to a first DEK encryption device, and transmitting a second DEK encryption request message including the DEK to a second DEK encryption device; An operation of receiving a first DEK encryption response message including a first EDEK (encrypted DEK) generated by encrypting the DEK using a first KEK and identification information of the first KEK from the first DEK encryption device, and receiving a second DEK encryption response message including a second EDEK generated by encrypting the DEK using a second KEK and identification information of the second KEK from the second DEK encryption device; and A recording medium that causes an operation to be performed to store the first EDEK, identification information of the DEK, and identification information of the first KEK in a first storage area corresponding to the first DEK encryption device, and to store the second EDEK, identification information of the DEK, and identification information of the second KEK in a second storage area corresponding to the second DEK encryption device.

Citation Information

Patent Citations

  • Method and system for secure delegated access to encrypted data in big data computing clusters

    US10581603B2

  • Key encryption key rotation

    US11057359B2

  • Encryption in a distributed storage system utilizing cluster-wide encryption keys

    US20220407685A1

  • Database encryption key management

    US20230283456A1

  • Secure distribution and update of encryption keys in cluster storage

    WO2022125943A1