Inspecting Encrypted Cloud Disks While Bypassing Provider Rules
This patent describes a method to inspect encrypted data disks in cloud environments for cybersecurity threats by re-encrypting a copy of the disk with a new key, allowing security tools to access it without violating cloud provider restrictions.
Patent Number
US 12739106
Status
Active
Filing Date
December 20, 2024
Grant Date
September 15, 2026
Expiration
~December 2044 (estimated)
Claims
0
Assignee
—
Inventors
—
Citations
0 forward · 0 backward
What it covers
This system helps cybersecurity teams inspect encrypted disks in cloud computing environments, even when cloud providers limit direct access. First, it detects an encrypted disk that uses a 'first key' from a Key Management System (KMS). Then, it creates a 'second key' in the KMS, specifically granting access to the inspection tools. The system generates a snapshot of the original encrypted disk, then creates a new data volume from this snapshot. Crucially, this new volume is re-encrypted using the 'second key'. Finally, another snapshot is taken of this re-encrypted volume, and an 'inspectable disk' is generated from it, allowing cybersecurity tools to begin scanning for threats.
What it doesn't cover
- —Does not cover inspecting unencrypted disks in a cloud environment, as the method specifically starts with 'detecting an encrypted disk'.
- —Does not cover inspection methods that do not involve generating a snapshot of the disk, as 'generating a snapshot' is a core step.
- —Does not cover scenarios where cloud providers already offer direct, unrestricted access to encrypted disk contents for cybersecurity inspection.
- —Does not cover inspection without re-encrypting the volume with a new key that grants access to the inspection environment.
- —Does not cover inspecting data that is not stored on a disk or volume, such as data in memory or network traffic.
The clever bit
The novelty lies in the multi-step re-encryption process: taking a snapshot of an encrypted disk, creating a new volume, re-encrypting that volume with a *different* key accessible to the inspection system, and then creating an inspectable disk. This allows security tools to access the data without needing the original encryption key or direct access to the original encrypted disk.
Why it matters
In cloud computing, data is often encrypted for security and compliance, but this can make it hard for cybersecurity tools to scan for threats. This patent provides a technique to overcome these limitations, enabling thorough security inspections without compromising the original encryption or violating cloud provider policies. This capability is vital for organizations needing to maintain strong security postures and comply with regulations like HIPAA or GDPR while operating in the cloud.
Real-world examples
- 1.Cloud security posture management (CSPM) platforms
- 2.Cloud workload protection platforms (CWPP)
- 3.Endpoint detection and response (EDR) solutions for cloud instances
- 4.Cloud compliance and auditing tools
Generated by PatentBrief · Not legal advice · patentbrief.org
US 12739106 · 2026