{
  "patent_number": "US 12739106",
  "country": "US",
  "title": "Inspecting Encrypted Cloud Disks While Bypassing Provider Rules",
  "original_title": "Techniques for circumventing provider-imposed limitations in snapshot inspection of disks for cybersecurity",
  "summary": "This patent describes a method to inspect encrypted data disks in cloud environments for cybersecurity threats by re-encrypting a copy of the disk with a new key, allowing security tools to access it without violating cloud provider restrictions.",
  "what_it_does": "This system helps cybersecurity teams inspect encrypted disks in cloud computing environments, even when cloud providers limit direct access. First, it detects an encrypted disk that uses a 'first key' from a Key Management System (KMS). Then, it creates a 'second key' in the KMS, specifically granting access to the inspection tools. The system generates a snapshot of the original encrypted disk, then creates a new data volume from this snapshot. Crucially, this new volume is re-encrypted using the 'second key'. Finally, another snapshot is taken of this re-encrypted volume, and an 'inspectable disk' is generated from it, allowing cybersecurity tools to begin scanning for threats.",
  "what_it_does_not_cover": [
    "Does not cover inspecting unencrypted disks in a cloud environment, as the method specifically starts with 'detecting an encrypted disk'.",
    "Does not cover inspection methods that do not involve generating a snapshot of the disk, as 'generating a snapshot' is a core step.",
    "Does not cover scenarios where cloud providers already offer direct, unrestricted access to encrypted disk contents for cybersecurity inspection.",
    "Does not cover inspection without re-encrypting the volume with a new key that grants access to the inspection environment.",
    "Does not cover inspecting data that is not stored on a disk or volume, such as data in memory or network traffic."
  ],
  "filed": "2024-12-20",
  "granted": "2026-09-15",
  "expires": null,
  "status": "active",
  "holder": null,
  "holder_url": null,
  "inventors": [],
  "times_cited": 0,
  "tags": [
    "cloud_computing",
    "cybersecurity",
    "software",
    "telecommunications"
  ],
  "abstract": "A system and method reduces use of restricted operations in a cloud computing environment during cybersecurity threat inspection. The method includes: detecting an encrypted disk in a cloud computing environment, the encrypted disk encrypted utilizing a first key in a key management system (KMS); generating a second key in the KMS, the second key providing access for a principal of an inspection environment; generating a snapshot of the encrypted disk; generating a volume based on the snapshot, wherein the volume is re-encrypted with the second key; generating a snapshot of the re-encrypted volume; generating an inspectable disk from the snapshot of the re-encrypted volume; and initiating inspection for a cybersecurity object on the inspectable disk.",
  "url": "https://patentbrief.org/patent/us/12739106/techniques-for-circumventing-provider-imposed-limitations-in-snapshot",
  "markdown_url": "https://patentbrief.org/patent/us/12739106/techniques-for-circumventing-provider-imposed-limitations-in-snapshot/md",
  "google_patents_url": "https://patents.google.com/patent/US12739106",
  "relatedPatents": []
}