Centralized Key Management System for Heterogeneous Stores

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in managing heterogeneous security environments due to disparate devices and services, requiring different key management tools and leading to complex key administration tasks, such as certificate management and key migration, which can expose confidential information and lead to operational failures.

Innovation Solution

A centralized key management system that uses key agents to translate and process instructions across multiple key stores with disparate interfaces, providing a unified management interface and ensuring synchronization, thus enabling efficient management of keys across different security databases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple key management tools are used to manage different types of security databases, then the ability to manage heterogeneous key stores is improved, but the device complexity and difficulty of operation increase

Engineering Contradiction:
Improveability to manage heterogeneous key storesVSAvoidcomplexity of key management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized key management system as an intermediary layer between administrators and multiple heterogeneous key stores. This mediator translates diverse key management operations into a unified interface, eliminating the need for administrators to directly interact with multiple different tools and formats. The intermediary handles the complexity of translating between different key store formats (Java key stores, PEM, DER, etc.) and manages synchronization across all stores centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The centralized key management system provides a universal interface that can manage multiple types of key stores through a single tool. Instead of requiring separate management tools for each key store type, the system performs multiple functions (management of Java key stores, PEM files, DER files, and other formats) through one unified interface, thereby reducing operational complexity while maintaining versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If administrators use multiple key management tools for different security databases, then coverage of different key store types is improved, but the ease of operation deteriorates

Engineering Contradiction:
Improvecoverage of different key store typesVSAvoidease of key administration
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The centralized key management system serves as an intermediary that presents a consistent, user-friendly interface to administrators while handling the complexity of interacting with different key store formats in the background. This mediator translates simple administrator commands into the appropriate operations for each specific key store type, eliminating the need for administrators to learn and use multiple different tools.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system provides universal operations (such as creating, deleting, synchronizing, and managing keys) that work across all supported key store types through a single interface. Administrators perform the same operations regardless of whether they are managing Java key stores, PEM files, or other formats, thereby improving ease of operation while maintaining broad coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If key management operations are performed across multiple dispersed key stores, then the coverage of key administration tasks is improved, but the loss of time increases

Engineering Contradiction:
Improvecoverage of key administration tasksVSAvoidtime for key administration
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent merges multiple dispersed key management operations into a single centralized operation. Instead of administrators needing to manually connect to and operate each individual key store separately, the centralized system combines all key administration tasks (certificate management, key generation, synchronization) into one unified operation that executes across all key stores simultaneously, thereby reducing time loss.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized key management system maintains continuous synchronization with all connected key stores, ensuring that key administration tasks are performed consistently and continuously across the entire network. This continuous action eliminates the need for administrators to perform repetitive manual synchronization operations, thereby reducing the time required for key administration while maintaining comprehensive coverage.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8116456B2Techniques for managing heterogeneous key stores
Publication Date: 2012.02.14 ORACLE INT CORP
  • US8116456B2 patent drawing
  • US8116456B2 patent drawing
  • US8116456B2 patent drawing

AI summary

Techniques for managing heterogeneous key stores are presented. A centralized key management service receives key instructions in a generic format. These key instructions are communicated to distributed key agents distributed over a network. The key agents translate the key instructions into native formats expected by distributed key stores. The key agents then process the key instructions in the native formats against the distributed key stores on behalf of the centralized key management service.