Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

68 results about "Keystore" patented technology

A Java KeyStore (JKS) is a repository of security certificates – either authorization certificates or public key certificates – plus corresponding private keys, used for instance in SSL encryption. In IBM WebSphere Application Server and Oracle WebLogic Server, a file with extension jks serves as a keystore.

Controlling access to cryptographic resources using double encryption

A system for controlling access to cryptographic resources is disclosed. The system may receive a request to transfer cryptographic resources between users, including a user identifier and a first cryptographic signature. The system may verify the signature and retrieve an encrypted private key from a key vault using the user identifier. A command to sign the request may be transmitted over a private network to a signature device, which may generate a second cryptographic signature using the decrypted private key. The system may receive the second signature, generate a blockchain operation based on the request and signature, and transmit the operation to a blockchain node for commitment. The system may also handle new account generation, storing encrypted keys in jurisdiction-specific databases, and validating blockchain operations against request parameters.
Owner:CITIBANK N A

A method and device for implementing high-speed operation of an algorithm based on a multi-level field cache

The application discloses a method and device for realizing high-speed operation of an algorithm based on a multi-level field cache, which comprises the following steps: a configuration management CPU sends algorithm parameters to an FPGA chip and saves the algorithm parameters in a RAM; a service processing CPU creates a handle and sends the handle to the configuration management CPU; the configuration management CPU generates a key number according to the handle; the configuration management CPU sends a key library to the FPGA chip; the service processing CPU sends a to-be-operated message to the FPGA chip; an algorithm scheduling module performs fragmentation judgment, and performs subsequent processing according to a sequence judgment result; a password operation module takes the received key, an initialization vector or an intermediate chain variable and the to-be-operated message as input, performs password operation, and outputs a calculation result and an operated intermediate chain variable; whether the to-be-operated message is the last data fragment is judged according to a tail fragment identifier, and subsequent processing is performed according to a tail fragment judgment result. The application can reduce the communication interface and CPU access times, realize high-speed operation of a password algorithm, and improve the overall performance of a password service system.
Owner:JIANGSU NEW QUALITY INFORMATION TECH CO LTD

Internet of Things communication encryption system for CPU card management

The invention discloses an internet-of-things communication encryption system for CPU card management, and relates to the technical field of internet-of-things encryption, the internet-of-things communication encryption system comprises an initialization module, a card issuing module, a card reading module and a platform end, a distributed key library is constructed, and according to an authority control mechanism of an alliance chain of the distributed key library, the card issuing module and the card reading module are encrypted. The platform secret key, the manufacturer secret key, the tenant secret key and the project secret key are stored in an isolated mode and are only authorized to be used by the corresponding platform, the manufacturer, the tenant and the project, and under the condition that permission of the opposite side is not obtained, the secret keys cannot be called in an unauthorized mode. The design of segmented keys is adopted, so that a platform, a manufacturer, a tenant and a project respectively hold independent key segments, the problem caused by leakage of a single key is reduced to the minimum, even if an attacker gets one key, the attacker cannot read data of a CPU card, and the data of the CPU card cannot be read by the attacker. Even if an attacker cracks the platform key, the attacker cannot communicate with the initialization device, the card issuing device and the card reading device.
Owner:SHENZHEN QINLIN TECH

Digital identity encryption authentication method

The invention relates to the technical field of digital identity authentication, and discloses a digital identity encryption authentication method, which comprises the following steps of: acquiring a user identity information feature data set, and generating a master key library through multi-dimensional encryption preprocessing; extracting fragment verification features of each master key library to determine an authentication rule; and constructing a multi-level authentication chain and a verification node, and obtaining a node authentication state through bidirectional verification. In an effective authentication state, the master key library is subjected to association authentication according to permission levels; and in the invalid authentication state, identifying the abnormal verification node, calculating the authentication offset of the master key library under the abnormal verification node, and reconstructing the path of the abnormal verification node based on the authentication offset until the authentication is completed. Wherein the generation of the master key library relates to encryption, confusion and format standardization of various types of data; fragment verification feature extraction comprises key fragment sorting and the like; the authentication rule is determined based on the dynamic feature priority; and exception processing is combined with historical tracing and offset calculation. According to the method, the authentication security and the dynamic adaptability are improved.
Owner:YIQIBANG (ANHUI) DIGITAL TECHNOLOGY CO LTD

Payload level encryption

In some implementations, a system may configure a set of compliance requirements for a secure communication service. The system may configure a key rotation component and a key fallback component. The system may store a key, generated by the key rotation component, using a key store. The system may periodically update, using the key rotation component, the key in the key store in accordance with the set of compliance requirements. The system may maintain, in connection with periodically updating the key, at least one fallback key using the key fallback component. The system may receive a request for a communication using the key. The system may determine whether the key is a valid current key or a valid fallback key. The system may communicate using the key based on determining whether the key is the valid current key or the valid fallback key.
Owner:CAPITAL ONE SERVICES LLC

Controlling access to cryptographic resources using offline storage

A system for controlling access to cryptographic resources is disclosed. The system may receive a request to transfer cryptographic resources between users, including a user identifier and a first cryptographic signature. The system may verify the signature and retrieve an encrypted private key from a key vault using the user identifier. A command to sign the request may be transmitted over a private network to a signature device, which may generate a second cryptographic signature using the decrypted private key. The system may receive the second signature, generate a blockchain operation based on the request and signature, and transmit the operation to a blockchain node for commitment. The system may also handle new account generation, storing encrypted keys in jurisdiction-specific databases, and validating blockchain operations against request parameters.
Owner:CITIBANK N A

Identity verification method and device for space mobile equipment, electronic equipment and storage medium

The invention provides a space mobile equipment identity verification method and device, electronic equipment and a storage medium, and relates to the technical field of information security. The invention discloses a space mobile device identity verification method, which comprises the following steps: acquiring a motion track of a target space mobile device; decoding the motion track by using a preset decoding algorithm to obtain a to-be-verified key; and matching the to-be-verified key with an identity key pre-stored in a key library, and obtaining an identity verification result of the target space mobile device according to a matching result. According to the technical scheme provided by the embodiment of the invention, the motion track of the target space mobile device is captured, the key information embedded in the track is identified and decoded by using the preset decoding algorithm to obtain the to-be-verified key, and the to-be-verified key is compared with the pre-stored identity key to realize identity verification. The method does not need to depend on network connection or hardware equipment support, is not easy to crack, and is good in anti-interference capability and safety performance.
Owner:GUANGDONG-HONG KONG-MACAO GREATER BAY AREA DIGITAL ECONOMY RESEARCH INSTITUTE (INTERNATIONAL ADVANCED TECHNOLOGY APPLICATION PROMOTION CENTER (SHENZHEN)

Quantum encryption communication data protection method, gateway, and system

The present application provides a quantum encryption communication data protection method in a public-private integrated network communication system. A key management platform is used to generate, in real time, a session key actually used for operation, and the session key is encrypted using a key pre-filled in a preset key library of two parties participating in a call as a protection key, and a key ciphertext is generated and issued to both parties in the call, so as to implement transcoding from a private network talkback terminal to a gateway side, and perform encrypted transmission of corresponding data from the gateway side to a public network talkback terminal, as well as support reverse data transmission from the public network talkback terminal to the private network talkback terminal. The present application further provides a public-private integrated network gateway and a public-private integrated network communication system. The present application has the advantages of: improving security relative to directly using a preset shared key library, solving the problem of repeated use of a key in a talkback handheld terminal, and implementing one-time key negotiation and one-time key functionality.
Owner:CHINA TELECOM QUANTUM TECH CO LTD

Method and apparatus for dynamic encryption of communication channels

The application relates to the technical field of network communication, and discloses a communication channel dynamic encryption method and device, which comprises the following steps: collecting communication scene related information and security state related information to obtain an evaluation result; selecting a corresponding encryption scheme based on the evaluation result to establish an encryption link; transmitting an updated key library by using the encryption link to complete seamless updating of the key library; and binding the encryption scheme and session information and optimizing session parameters based on the encryption link and the updated key library to obtain encrypted transmission of communication data. The communication channel dynamic encryption method and device are characterized in that, through three-dimensional evaluation of data sensitivity, network security level and historical interaction security record and dynamic adaptation of the encryption scheme, high-sensitivity data, dangerous network environment and other scenes can be subjected to high-intensity encryption with high pertinence, low-sensitivity data and safe network environment can be subjected to moderate encryption strength, transmission efficiency caused by excessive encryption is avoided, and security risks caused by insufficient encryption strength are reduced.
Owner:CHONGQING COLLEGE OF ELECTRONICS ENG

Resource transfer information processing method and related device

The invention provides a resource transfer information processing method and a related device. The method is performed by a first processing node. The method comprises the following steps: identifying a receiver of resource transfer information as a second processing node, and generating receiver information according to the second processing node; obtaining a target multi-party symmetric key from a first multi-party symmetric key library of the first processing node; generating a target multi-party symmetric key identifier for the target multi-party symmetric key; encrypting the resource transfer information by using the target multi-party symmetric key to obtain encrypted resource transfer information; and binding and recording the encrypted resource transfer information, the receiver information and the target multi-party symmetric key identifier to the block chain. According to the resource transfer method and device, the resources can be effectively transferred under the conditions that normal operation of the block chain is not influenced and details of the data are not exposed, and privacy and security in the resource transfer process are improved under the condition that continuous detection of a third party is not influenced.
Owner:BEIJING NATIONAL FINANCIAL TECHNOLOGY RISK MONITORING CENTER CO LTD

Assembly line optimization method, device and equipment for SM4 encrypted circuit and medium

The invention relates to the technical field of digital integrated circuit design, in particular to an SM4 encrypted circuit assembly line optimization method and device, equipment and a medium. The method comprises the following steps: acquiring the total number of rounds of encryption operation; based on the total number of rounds of encryption operation, the target SM4 encryption circuit is divided into a plurality of encryption assembly lines, and each encryption assembly line comprises at least one round of encryption operation; the method comprises the steps of obtaining a sub-key corresponding to each encryption operation round from a preset multi-round key library, dividing an encryption assembly line corresponding to each encryption operation round into a plurality of sub-assembly line stages, and controlling the plurality of sub-assembly line stages to execute corresponding encryption operations based on the sub-key corresponding to each encryption operation round. Therefore, by optimizing the pipeline architecture design, the subkey generation mechanism and the task scheduling strategy, the problem of performance reduction caused by data dependence in a hardware pipeline is solved, and the performance and the resource utilization rate of the SM4 hardware accelerator are improved.
Owner:CHERY AUTOMOBILE CO LTD

Autonomously booting system with encryption of the entire data storage and method for this

Encryption system with an application-specific integrated circuit (ASIC) which has a permanent memory for the non-volatile storage of the operating system (OS) of a processor and software modules for encrypting the data memory of the processor and which has a hardware-implemented encryption algorithm, characterized in that a security module (SM) is integrated in the ASIC for autonomous booting of the operating system (OS), consisting of: - a symmetric cryptosystem (SK) for processing symmetric keys, - an asymmetric cryptosystem (AK) for the use of public and private keys, - a module for generating cryptographic hash functions (KH), - a module for the secure exchange of keys using hardware-implemented key exchange protocols (SP), - a key storage (SS) for the secure storage of root keys (WS), which are protected by appropriate measures in the physical structures of the ASIC and - a key management system (SMS) for the secure introduction of authenticated-encrypted key packets, and that the security module (SM) communicates with a central processing unit (CPU) via a communication interface (CS1), and that the central processing unit (CPU) communicates with at least one internal storage (IS) and one external storage (ES), as well as with at least one internal persistent storage (IP) and one external persistent storage (EP), such that the operating system (OS) is loaded by a second-stage bootloader (SSB) stored in the external persistent storage (EP), and then the operating system (OS) loads the applications, the second-stage bootloader (SSB) itself being decrypted and loaded by a first-stage bootloader (FSB) stored in the internal persistent storage (IP), and a public key (PUBOS) to verify the operating system (OS).and a symmetric key (KOS) to decrypt the operating system (OS), and that the contents of the internal memory (IS) and the external memory (ES) are decrypted by the security module (SM) during read accesses by the central management unit (CMU) or other modules integrated on the ASIC, and re-encrypted during write accesses by the same.
Owner:IAD GESELLSCHAFT FUER INFORMATIK AUTOMATISIERUNG & DATENVERARBEITUNG MBH

Systems and methods for providing containerized applications with updated secret values

A method and system for providing containerized applications with updated secret values has been developed. An update to a secret from a first secret value to a second secret value is detected at a secrets vault. A configuration map associated with the secret is identified. The configuration map includes a first non-secret that is associated with the first secret value. A second non-secret that is associated with the second secret value is generated. The first non-secret is replaced with the second non-secret in the configuration map. The replacement of the first non-secret with the second non-secret in the configuration map results is an event. A reloader issues a restart signal to a containerized application associated with the secret in response to the event. The secret at the containerized application is updated from the first secret value to the second secret value during a restart process.
Owner:SALESFORCE INC

Digital identity encryption authentication method

This invention relates to the field of digital identity authentication technology and discloses a digital identity encryption authentication method. The method includes the following steps: acquiring a user identity information feature dataset and generating a master key library through multi-dimensional encryption preprocessing; extracting fragmented verification features from each master key library to determine authentication rules; constructing a multi-level authentication chain and verification nodes, and obtaining the node authentication status through bidirectional verification. In a valid authentication state, the master key library is associated with authentication according to permission levels; in an invalid authentication state, abnormal verification nodes are identified, the authentication offset of their respective master key libraries is calculated, and the abnormal verification node paths are reconstructed based on this until authentication is completed. The master key library generation involves multiple types of data encryption, obfuscation, and format standardization; fragmented verification feature extraction includes key fragment sorting; authentication rule determination is based on dynamic feature priority; and anomaly handling combines historical tracing and offset calculation. This method improves authentication security and dynamic adaptability.
Owner:YIQIBANG (ANHUI) DIGITAL TECHNOLOGY CO LTD

Credential revocation leveraging private keys on keystores read by provisioned devices

The disclosed technology teaches a method for revocation of user credentials for controlling user access to a private permissioned blockchain data structure or decentralized personal ledger, comprising an administrative logic configured to de-configure user private keys from keystores of respective users. The administrative logic further comprises a revocation logic configured to receive a unique identifier linked to a keystore of a particular user in response to the keystore, and the revocation logic is further configured to revoke access of the keystore based on the unique identifier.
Owner:LEDGERDOMAIN INC

Secure secrets for encryption consistency

Providing secure secrets for encryption consistency enables rotating security measures (e.g., encryption access keys in users' certificate) for encrypted data at rest, without either needing to retain any prior certificates or requiring decryption and re-encryption. This provides enhanced security over some prior art methods (old keys may be discarded) and enhanced speed over the other prior art methods (no decryption / re-encryption needed). Examples generate a primary encryption key, which is retained on a secure remote computing node, such as in a key vault, and is not shared outside the key vault. Access to the primary encryption key is restricted to users who possess the current encryption access key, which is rotated on some trigger event. The remote node receives incoming messages to encrypt or decrypt files and performs the encryption / decryption using the primary - but only if a message contains the current encryption access key. Rotating the encryption access key preserves security.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Supply chain integrated collaborative management system based on cloud platform

The invention discloses a supply chain integrated collaborative management system based on a cloud platform, which belongs to the technical field of supply chain management, and comprises a supply application platform processor, a multi-tenant key library management service, a digital twinning collaborative optimization module, a federal learning decision engine, an intelligent contract execution layer and an application interface layer, the problems of data splitting, low cooperation efficiency, low demand prediction precision and rigid logistics planning in the prior art are solved, and a distributed data warehouse, multi-dimensional supplier matching, a hierarchical demand prediction model and a block chain traceability technology are integrated. Breakthrough is realized through three major innovation mechanisms: firstly, a cross-subject real-time collaborative environment is constructed by adopting a digital twinning technology, and the problem of poor collaboration of links of a traditional supply chain is solved; secondly, data fusion is carried out by using federal learning, and the data value mining capability is improved on the premise of protecting data privacy; and thirdly, an intelligent contract is introduced to realize automatic disposal of abnormal events, and timeliness and toughness of supply chain risk response are enhanced.
Owner:SHANGLUO TIANSHOU ZHIXING TECHNOLOGY CO LTD

Auditable master secrets and key vault

Systems and techniques are provided for generating cryptographic keys. For instance, a process may include generating a plurality of master keys based on a plurality of generated random numbers, a second number, and a nonce number; storing a master key, of the plurality of master keys, along with a generated random number of the plurality of generated random numbers, the second number, and the nonce number used to generate the master key in a one-time programmable memory; generating public key-private key pairs for the plurality of master keys; transmitting public keys of the plurality of public key-private key pairs for audit; destroying an audited master key, along with the generated random number, second number, and the nonce number used to generate the audited master key, based on the audit; and storing a non-audited public key-private key pair corresponding to the master key that were not destroyed based on the audit.
Owner:QUALCOMM INC

Industrial encryption communication method and system fusing national secret algorithm and dynamic key mechanism

The invention relates to the technical field of secure network communication, and discloses an industrial encryption communication method and system fusing a national cryptographic algorithm and a dynamic key mechanism, and the method comprises the steps: a transmitting end obtains a network layer data packet, analyzes a specific field of an IP head of the network layer data packet, and obtains a current timestamp; based on the specific field and the timestamp, a dynamic key sequence number is calculated through a preset key sequence number generation algorithm; extracting a corresponding encryption key and an initialization vector from a pre-stored key library which is the same as the receiving end according to the serial number; and encrypting the data load by using the CTR working mode of the SM4 algorithm, adding a timestamp to the head of the encrypted load, and sending the encrypted load. And the receiving end extracts the timestamp to perform timeliness verification, and calculates the same key sequence number based on the same field and the timestamp to complete decryption. The method realizes a one-time pad dynamic key mechanism, has the advantages of high encryption strength, good compatibility and the like, and is particularly suitable for an industrial control communication environment with high requirements on real-time performance and reliability.
Owner:DONGFANG ELECTRIC (CHENGDU) INNOVATION RES CO LTD +1

Key library generation method and device, equipment and storage medium

The invention discloses a key library generation method and device, equipment and a storage medium. In the scheme, a mode of presetting a key library and statically configuring is not adopted, the key library is automatically created through the initial strategy file and the attribute value of each attribute variable, and the triple information of each key in the key library is automatically generated; a corresponding secret key can be directly obtained and processed based on the triple information; if an encryption algorithm or a hardware cipher machine needs to be replaced, a new key library and a configuration file do not need to be manually regenerated, only the attribute value of the attribute variable needs to be changed, the new key library and the triple information can be automatically created, the key library management mode greatly simplifies the generation process of the key library, the downtime is reduced, and the key library management efficiency is improved. And the error probability is reduced, so that efficient and safe management of the key library is realized.
Owner:SHANDONG CVICSE MIDDLEWARE CO LTD

Character encryption method, electronic equipment and computer readable medium

The invention discloses a character encryption method, electronic equipment and a computer readable medium, and the method comprises the steps: determining a switched target key group and a switched target key from a pre-constructed key library under the condition of meeting a key switching condition; packaging according to the target key group, the target key and the original character to obtain an encrypted character conforming to a preset data structure; a locally stored character mapping table is updated according to the character mapping relation, so that the gateway converts a plaintext cue word sent by the user equipment into a ciphertext cue word based on the updated character mapping table; and inputting the ciphertext cue word into a natural language processing system obtained by encryption based on the character mapping relationship, and obtaining an output ciphertext response, so that the gateway performs character decryption on the ciphertext response to obtain a plaintext response and sends the plaintext response to the user equipment. Data security can be improved, computing resources are saved, reasoning delay is reduced, and natural language processing efficiency and user experience are improved.
Owner:CLP (TIANJIN) NETWORK INFORMATION SECURITY CO LTD

Access audit framework

Key vault access security migration is provided, including a computing device receiving key vault information. The key vault information is received from at least one entity operating a user computing device via an initialized release pipeline. Further, at least some of the key vault information is processed to determine a first access security model, including permissions to a cryptographic object for access to a respective technical resource. Data discovery determines cryptographic object permission and the computing device determines a role assignment that includes a security principal, at least one of a plurality of permissions, and the respective technical resource. Further, the computing device migrates access to the key vault for the entity from the first access security model to the second access security model. Access to the key is enabled as a function of the second access security model.
Owner:MORGAN STANLEY SERVICES GROUP INC

Equipment security authentication method and equipment security authentication system

The invention discloses an equipment security authentication method and system. The device security authentication method is applied to a first terminal, and the method comprises the following steps: in response to a login request, calling a first quantum key device of the first terminal to generate first verification information, and sending the first verification information to a quantum cryptography service platform; login is completed according to the encrypted target key library, and the first terminal and the second terminal are both bound with the encrypted target key library. Thus, the dual-quantum key device of the first terminal and the dual-quantum key device of the second terminal cooperatively participate in identity authentication, and the validity verification of the quantum cryptography service platform is combined, so that a dual-hardware security guarantee is constructed, and the problem that a single identity authentication mode is easy to steal or pretend is effectively solved; the identity authentication security of new equipment login is improved to a certain extent, and the requirement that multiple pieces of equipment of a user safely use the same application is met.
Owner:中电信量子信息科技集团有限公司

Systems, methods, and media for generating and using a multi-signature token for electronic communication validation

Techniques are provided for generating and using a multi-signature token for electronic message validation according to the one or more embodiments as described herein. Specifically, a multi-signature token may be generated that includes at least two digital signatures and information (e.g., user information). Each of the at least two digital signatures may be generated using a private key of at least two key pairs that are maintained on a plurality of keystores that have at least two different implementations (e.g., security protocols). If the at least two digital signatures are valid, the multi-signature token may be determined to be valid and the client request may optionally be performed. If at least one of the at least two digital signatures is invalid, the client request is optionally not performed.
Owner:FMR CORP

A fingerprint module factory testing method, apparatus, and computer-readable storage medium

ActiveCN114048462BSimple test stepserasure implementationDigital data authenticationPasswordSmart device
This invention discloses a fingerprint module factory testing method, device, and computer-readable storage medium. The method includes: creating an initial password verification factor for the device in the fingerprint module's factory testing mode; setting the device's password to a preset keystore based on the initial password verification factor; when the device's password is successfully set, recording a test value of 1 through a corresponding system attribute; verifying the initial password verification factor and the keystore to obtain verification response body parameters; if the verification response body parameters are not empty, obtaining the verification token of the verification response body, and using the verification token to enable fingerprint verification of the device. This provides an efficient fingerprint module factory testing scheme, greatly simplifying the testing steps for fingerprint modules in smart devices, reducing labor and time costs, and improving productivity.
Owner:NUBIA TECHNOLOGY CO LTD

An image encryption and decryption method based on chaos and elliptic curve encryption algorithm

ActiveCN115146296BDigital data protectionImage data processing detailsAlgorithmChaotic synchronization
The present invention discloses an image encryption and decryption method based on chaos and elliptic curve encryption algorithms. This method utilizes the characteristics of chaos and the elliptic curve public key encryption system to perform image encryption operations. The steps include: generating a key using a chaotic sequence; chaotic scrambling of image blocks; chaotic diffusion of the image; transmitting the key using an elliptic curve encryption algorithm; decrypting the key using the elliptic curve encryption algorithm; and restoring image pixels to restore the image. The chaotic sequence utilized is an optical chaotic synchronization sequence based on light injection. The chaotic sequence can be synchronized at the receiving and transmitting ends, and the chaotic sequence is used to generate a key library for image encryption. Each key library is transmitted separately through the synchronized chaotic sequence and the elliptic curve encryption algorithm, providing dual encryption characteristics and improving encryption security.
Owner:HANGZHOU DIANZI UNIV

Methods and systems for team collaboration and document management

A user and business collaboration and document management solution is described. The solution utilizes the InterPlanetary File System (IPFS) or similar distributed and decentralized storage methods, in addition to the Publish / Subscribe (PubSub) message protocol or similar distributed messaging methods. As a fully decentralized and distributed solution, information is shared through cryptographically secure and resilient Web 3.0 mechanisms. The solution provides a number of secure collaboration services. Users can securely add, update, delete, archive and share documents on the IPFS file system. Local directory synchronization automates this task. A localized encryption key and secrets vault is used to protect data encryption keys, authentication credentials, and related secrets.
Owner:TOWNSEND PATRICK A

Secure data erasure framework using individualized encryption key management

There are provided systems and methods for a secure data erasure framework using individualized encryption key management. A service provider, including an electronic transaction processor, may provide data management and secure erasure through individualized encryption keys that may be managed and deleted to render encrypted data unreadable. When a device interacts with a service provider and provides or generates user data, the user data may be stored in accordance with an encryption process that encrypts the data using an encryption key for a corresponding account. Thereafter, the encryption key may be stored by a key store and not replicated elsewhere. When data is needed, the key store may be used by a trusted decryption platform and not shared. As such, when data is required to be erased or deleted, the data may be removed from availability with the service provider by implementing a secure key deletion process.
Owner:PAYPAL INC