/Electronic Apparatus For Managing Data Encryption Key
Abstract

An electronic apparatus is provided. The electronic apparatus includes a communication circuit, memory, comprising one or more storage media, storing instructions, and at least one processor communicatively coupled to the communication circuit and the memory, wherein the instructions, when executed by the at least one processor individually or collectively, cause the electronic apparatus to generate a data encryption key (DEK), transmit a first DEK encryption request message including the DEK to a first DEK encryption apparatus, transmit a second DEK encryption request message including the DEK to a second DEK encryption apparatus, receive, from the first DEK encryption apparatus, a first DEK encryption response message including a first encrypted DEK (EDEK) generated by encrypting the DEK by using a first key encryption key (KEK), and identification information of the first KEK, receive, from the second DEK encryption apparatus, a second DEK encryption response message including a second EDEK generated by encrypting the DEK by using a second KEK, and identification information of the second KEK, store the first EDEK, identification information of the DEK, and the identification information of the first KEK in a first storage area of memory corresponding to the first DEK encryption apparatus, and store the second EDEK, the identification information of the DEK, and the identification information of the second KEK in a second storage area of the memory corresponding to the second DEK encryption apparatus.

Full Text

What is claimed is:

An electronic apparatus is provided. The electronic apparatus includes a communication circuit, memory, comprising one or more storage media, storing instructions, and at least one processor communicatively coupled to the communication circuit and the memory, wherein the instructions, when executed by the at least one processor individually or collectively, cause the electronic apparatus to generate a data encryption key (DEK), transmit a first DEK encryption request message including the DEK to a first DEK encryption apparatus, transmit a second DEK encryption request message including the DEK to a second DEK encryption apparatus, receive, from the first DEK encryption apparatus, a first DEK encryption response message including a first encrypted DEK (EDEK) generated by encrypting the DEK by using a first key encryption key (KEK), and identification information of the first KEK, receive, from the second DEK encryption apparatus, a second DEK encryption response message including a second EDEK generated by encrypting the DEK by using a second KEK, and identification information of the second KEK, store the first EDEK, identification information of the DEK, and the identification information of the first KEK in a first storage area of memory corresponding to the first DEK encryption apparatus, and store the second EDEK, the identification information of the DEK, and the identification information of the second KEK in a second storage area of the memory corresponding to the second DEK encryption apparatus.
Timeline
Filed
04/01/2026
Published
08/06/2026
Granted
Not Available
IPC Codes(1)
H04L 9/08:Key distribution