Encryption Key Distribution via Brokered Customer-Controlled Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in managing encryption keys across multiple communication channels for different user groups, leading to potential security breaches and improper security protocols.

Innovation Solution

A key broker server dynamically allocates data encryption keys generated by customer-specific key management servers to various communication services within a software platform, ensuring secure encryption and decryption processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized key management system is used to manage encryption keys across multiple communication channels, then security control is improved, but system complexity and vulnerability to security breaches increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key management system into multiple independent key management servers, each responsible for specific user groups or communication channels. This segmentation reduces the risk that a compromise of one server affects the entire system, while still providing centralized control through the broker server that coordinates between segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The broker server acts as an intermediary between key management servers and communication services. It receives key management requests, determines which key management server should handle each request based on user group affiliations, and routes requests appropriately. This intermediary layer simplifies the overall system architecture by providing a single point of coordination.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are managed centrally, then security protocols are standardized, but onboarding time and system downtime increase

Engineering Contradiction:
Improvesecurity protocol standardizationVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Key management servers are pre-configured with encryption keys and security protocols before they are needed. When a communication service needs to encrypt or decrypt data, the broker server can immediately route the request to the appropriate pre-configured key management server, eliminating onboarding delays and reducing system downtime.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple key management servers are deployed for different user groups, then security isolation is improved, but key allocation complexity increases

Engineering Contradiction:
Improvesecurity isolationVSAvoidkey allocation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The broker server maintains knowledge of user group affiliations and key management server assignments. When a key management request arrives, the broker server uses this feedback information to determine the appropriate key management server, automatically routing requests without requiring complex manual allocation or increasing system complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250293857A1Encryption Key Distribution System
Publication Date: 2025.09.18 ZOOM COMMUNICATIONS INC
  • US20250293857A1 patent drawing
  • US20250293857A1 patent drawing
  • US20250293857A1 patent drawing

AI summary

Customers of a software platform, such as a unified communications as a service platform, are enabled to control their own encryption keys used to encrypt and decrypt data from various communication services in the software platform. A key connector service is used to coordinate communications with a key management server for generating plaintext keys for data encryption and encrypted keys based on the plain text keys, and with a key broker server for storing and retrieving copies of the encrypted keys. A context identifier may be associated with an encrypted key and used to track which data has been encrypted with an underlying plaintext key. Examples of data encrypted may include conference recordings, webinar recordings, phone call recordings, voicemails, emails, and calendar tokens.