Skip to content
PatentBrief
Get alertsTop ↑

Inspecting Encrypted Cloud Disks While Bypassing Provider Rules

This patent describes a method to inspect encrypted data disks in cloud environments for cybersecurity threats by re-encrypting a copy of the disk with a new key, allowing security tools to access it without violating cloud provider restrictions.

Granted 2026ActiveExpires 2044

Original patent title: “Techniques for circumventing provider-imposed limitations in snapshot inspection of disks for cybersecurity”

Plain-English explanation by SahiLast reviewed · October 6, 2026

This patent describes a method to inspect encrypted data disks in cloud environments for cybersecurity threats by re-encrypting a copy of the disk with a new key, allowing security tools to access it without violating cloud provider restrictions. Granted in 2026.

Coverage

What does this patent actually cover?

This system helps cybersecurity teams inspect encrypted disks in cloud computing environments, even when cloud providers limit direct access. First, it detects an encrypted disk that uses a 'first key' from a Key Management System (KMS). Then, it creates a 'second key' in the KMS, specifically granting access to the inspection tools. The system generates a snapshot of the original encrypted disk, then creates a new data volume from this snapshot. Crucially, this new volume is re-encrypted using the 'second key'. Finally, another snapshot is taken of this re-encrypted volume, and an 'inspectable disk' is generated from it, allowing cybersecurity tools to begin scanning for threats.

The gap

What does this patent NOT cover?

  • Does not cover inspecting unencrypted disks in a cloud environment, as the method specifically starts with 'detecting an encrypted disk'.
  • Does not cover inspection methods that do not involve generating a snapshot of the disk, as 'generating a snapshot' is a core step.
  • Does not cover scenarios where cloud providers already offer direct, unrestricted access to encrypted disk contents for cybersecurity inspection.
  • Does not cover inspection without re-encrypting the volume with a new key that grants access to the inspection environment.
  • Does not cover inspecting data that is not stored on a disk or volume, such as data in memory or network traffic.

These exclusions are unique to PatentBrief — derived from the actual claim language, not patent-office boilerplate.

Key facts

Patent numberUS 12739106
StatusActive
FieldSoftware & Internet
Filed2024
Granted2026
Times cited0
LitigationNone on record
Value · $17K–$54KMinimal

What made this novel

The noveltynoveltyThe requirement that an invention be different from anything publicly known before its priority date.Read more → lies in the multi-step re-encryption process: taking a snapshot of an encrypted disk, creating a new volume, re-encrypting that volume with a *different* key accessible to the inspection system, and then creating an inspectable disk. This allows security tools to access the data without needing the original encryption key or direct access to the original encrypted disk.

Techniques for circumventing p…(Primary claim)cloud computingcybersecuritysoftwaretelecommunications

Schematic visualization of the patent's claim structure. Hand-drawn diagrams in progress for each landmark patent.

Where you've seen this

Real-world examples

01

Cloud security posture management (CSPM) platforms

02

Cloud workload protection platforms (CWPP)

03

Endpoint detection and response (EDR) solutions for cloud instances

04

Cloud compliance and auditing tools

Why it matters

The bigger picture

In cloud computing, data is often encrypted for security and compliance, but this can make it hard for cybersecurity tools to scan for threats. This patent provides a technique to overcome these limitations, enabling thorough security inspections without compromising the original encryption or violating cloud provider policies. This capability is vital for organizations needing to maintain strong security postures and comply with regulations like HIPAA or GDPR while operating in the cloud.

Filed

December 20, 2024

Granted

September 15, 2026

Market context

Who's building on this

Companies in this space

Major cloud providers like Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP) are continuously enhancing their security offerings, including methods for inspecting encrypted data. Cybersecurity firms such as Palo Alto Networks, CrowdStrike, and Zscaler are also developing solutions that integrate deeply with cloud environments to provide advanced threat detection and compliance for encrypted workloads.

Market impact

This type of technology addresses a critical challenge in cloud security, enabling organizations to adopt cloud services more confidently while meeting stringent security and compliance requirements. It helps to bridge the gap between strong data encryption and the need for continuous threat monitoring, potentially reducing the risk of data breaches and regulatory fines. The ability to inspect encrypted disks without direct access to the original keys empowers a new generation of cloud-native security tools.

Claim 1 — Plain English

What this patent covers

This system helps cybersecurity teams inspect encrypted disks in cloud computing environments, even when cloud providers limit direct access. First, it detects an encrypted disk that uses a 'first key' from a Key Management System (KMS). Then, it creates a 'second key' in the KMS, specifically granting access to the inspection tools. The system generates a snapshot of the original encrypted disk, then creates a new data volume from this snapshot. Crucially, this new volume is re-encrypted using the 'second key'. Finally, another snapshot is taken of this re-encrypted volume, and an 'inspectable disk' is generated from it, allowing cybersecurity tools to begin scanning for threats.

The clever bit

The novelty lies in the multi-step re-encryption process: taking a snapshot of an encrypted disk, creating a new volume, re-encrypting that volume with a *different* key accessible to the inspection system, and then creating an inspectable disk. This allows security tools to access the data without needing the original encryption key or direct access to the original encrypted disk.

What it does not cover

  • Does not cover inspecting unencrypted disks in a cloud environment, as the method specifically starts with 'detecting an encrypted disk'.
  • Does not cover inspection methods that do not involve generating a snapshot of the disk, as 'generating a snapshot' is a core step.
  • Does not cover scenarios where cloud providers already offer direct, unrestricted access to encrypted disk contents for cybersecurity inspection.
  • Does not cover inspection without re-encrypting the volume with a new key that grants access to the inspection environment.
  • Does not cover inspecting data that is not stored on a disk or volume, such as data in memory or network traffic.

Patent timeline

Filing

Application submitted to the patent office

Grant

Patent officially issued

PatentBrief Score

Impact Score

Early stage

Citation count

0/40

No citations yet

Claim breadth

0/20

Narrow claimsclaimsThe numbered statements at the end of a patent that legally define what the inventor owns.Read more →

Recency

20/20

Granted within 5 years

Assignee scale

0/20

Independent or smaller assigneeassigneeThe entity that owns the patent — usually the inventor's employer or a company.Read more →

PatentBrief Impact Score — based on citation count, claim breadth, recency, and assignee scale. Not a legal assessment.

Heuristic Value Estimate

What this patent might be worth

Minimal

$17K – $54K

Midpoint $34K · 18.2 yr remaining · industry ×1.4

Adjust inputs →

Heuristic only — blends forward/backward citation counts, claim scope, time remaining, litigation history, and CPC-derived industry baseline. Real valuations need a professional appraisal.

Claim text not yet imported for this patent

Claim text not yet imported for this patent.

Concepts involved

ClaimPrior artNon-obviousnessNoveltySpecificationAssigneePatent term

Cite this patent

(2026). Inspecting Encrypted Cloud Disks While Bypassing Provider Rules (U.S. Patent No. 12,739,106). U.S. Patent and Trademark Office. https://patentbrief.org/patent/us/12739106/techniques-for-circumventing-provider-imposed-limitations-in-snapshot

Auto-generated from the patent record. Double-check author order and the issue date against the official USPTO document before submitting.

Embed

Add this patent to your site

Drop this plain-English patent card into any blog post or article — free, no signup. It always links back to the full breakdown here.

<div data-patentlens-widget data-patent-number="US12739106"></div>
<script src="https://patentbrief.org/embed.js" async></script>

Stay in the loop

Get a weekly digest of new patents.

One email per week. No spam. Unsubscribe anytime.

Keep exploring

Related patents you should know

US 4683195 · 1987

How to Make Billions of Copies of a DNA Segment

This patent describes the Polymerase Chain Reaction (PCR), a method to rapidly create many copies of a specific piece of DNA or RNA, enabling its detection and analysis.

Cetus Corp

US 8697359 · 2014

How to Edit Genes in Human Cells Using an Engineered CRISPR System

This patent describes an engineered CRISPR-Cas9 system for precisely cutting DNA in eukaryotic cells to change how genes work, opening the door for gene editing in complex organisms.

Massachusetts Institute of Technology

US 7657849 · 2010

How the iPhone's Slide-to-Unlock Gesture Works

Apple's 2010 patent describes unlocking a device by dragging a specific graphical image across the touchscreen along a predefined path, a gesture that became iconic with the original iPhone.

Apple Inc

US 4733665 · 1988

How Doctors Implant a Permanent Stent Using a Balloon

This patent describes the method for placing a permanent, expandable wire mesh tube inside a blood vessel or other body tube using a balloon-tipped catheter to widen it and keep it open.

Expandable Grafts Partnership

US 4965188 · 1990

How to Make Many Copies of a DNA Piece with Heat

This patent describes the Polymerase Chain Reaction (PCR) method, a technique to make millions of copies of a specific DNA segment using a heat-resistant enzyme and repeated temperature changes.

Cetus Corp

US 4235871 · 1980

How to Encapsulate Active Materials in Lipid Bubbles Efficiently

This patent describes a method for trapping biologically active substances inside tiny, multi-layered fat bubbles called liposomes, using a specific water-in-oil emulsion and gel-forming process to improve how much material gets captured.

Individual

More to explore

More in Software & Internet

Browse all Software & Internet

New to patents?

What is a patent?How to read a patentAnatomy of a claimHow strong is this patent?What the citations meanWhat it doesn't coverSoftware PatentsPatent glossary
Explore the landscape:cloud computing patents →cybersecurity patents →software patents →

Common Questions

Frequently Asked Questions

What does Inspecting Encrypted Cloud Disks While Bypassing Provider Rules cover?

This patent describes a method to inspect encrypted data disks in cloud environments for cybersecurity threats by re-encrypting a copy of the disk with a new key, allowing security tools to access it without violating cloud provider restrictions.

When does this patent expire?

This patent is expected to expire on September 15, 2046, when the invention enters the public domain.

What problem does this patent solve?

In cloud computing, data is often encrypted for security and compliance, but this can make it hard for cybersecurity tools to scan for threats. This patent provides a technique to overcome these limitations, enabling thorough security inspections without compromising the original encryption or violating cloud provider policies. This capability is vital for organizations needing to maintain strong security postures and comply with regulations like HIPAA or GDPR while operating in the cloud.

What does this patent NOT cover?

Does not cover inspecting unencrypted disks in a cloud environment, as the method specifically starts with 'detecting an encrypted disk'.

Patent monitoring

Get notified when new matching patents are published

Get notified when this company files a new patent. Weekly digest · Confirm via email · Unsubscribe anytime.

Last reviewed: October 6, 2026 · PatentBrief is not a law firm and this is not legal advice.