Encryption Key Distribution via Brokered Customer-Controlled Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face challenges in managing encryption keys across multiple communication channels for different user groups, leading to potential security breaches and improper security protocols.
Innovation Solution
A key broker server dynamically allocates data encryption keys generated by customer-specific key management servers to various communication services within a software platform, ensuring secure encryption and decryption processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a centralized key management system is used to manage encryption keys across multiple communication channels, then security control is improved, but system complexity and vulnerability to security breaches increase
Solution Approach 1:
The patent segments the key management system into multiple independent key management servers, each responsible for specific user groups or communication channels. This segmentation reduces the risk that a compromise of one server affects the entire system, while still providing centralized control through the broker server that coordinates between segments.
Solution Approach 2:
The broker server acts as an intermediary between key management servers and communication services. It receives key management requests, determines which key management server should handle each request based on user group affiliations, and routes requests appropriately. This intermediary layer simplifies the overall system architecture by providing a single point of coordination.
2Reliability
If encryption keys are managed centrally, then security protocols are standardized, but onboarding time and system downtime increase
Solution Approach 1:
Key management servers are pre-configured with encryption keys and security protocols before they are needed. When a communication service needs to encrypt or decrypt data, the broker server can immediately route the request to the appropriate pre-configured key management server, eliminating onboarding delays and reducing system downtime.
3Reliability
If multiple key management servers are deployed for different user groups, then security isolation is improved, but key allocation complexity increases
Solution Approach 1:
The broker server maintains knowledge of user group affiliations and key management server assignments. When a key management request arrives, the broker server uses this feedback information to determine the appropriate key management server, automatically routing requests without requiring complex manual allocation or increasing system complexity.
Data Source
AI summary
Customers of a software platform, such as a unified communications as a service platform, are enabled to control their own encryption keys used to encrypt and decrypt data from various communication services in the software platform. A key connector service is used to coordinate communications with a key management server for generating plaintext keys for data encryption and encrypted keys based on the plain text keys, and with a key broker server for storing and retrieving copies of the encrypted keys. A context identifier may be associated with an encrypted key and used to track which data has been encrypted with an underlying plaintext key. Examples of data encrypted may include conference recordings, webinar recordings, phone call recordings, voicemails, emails, and calendar tokens.


