Client Device Encryption Key Binding to Network Presence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems face challenges in securely managing encryption keys, particularly in ensuring data protection 'at rest' on client devices, as remote key escrow systems require key transmission over encrypted channels, which can be complex and vulnerable to attacks, and maintaining secure backups impacts performance.

Innovation Solution

The system enables encryption/decryption on a client device without exchanging encryption keys, using a public key from a communications device to generate and recalculate the encryption key when in range, allowing metadata storage and key recovery, thus eliminating the need for key exchange and reducing vulnerability to unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a remote key escrow system is used to store and manage encryption keys, then data security is improved, but system complexity and vulnerability to attacks increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the encryption key from the remote escrow system and stores it locally on the client device. The key is embedded within encrypted data on the client device itself, eliminating the need for remote key management infrastructure. This reduces system complexity while maintaining security through local key availability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The client device performs self-service by locally storing and managing its own encryption key without requiring external key escrow services. The device can independently encrypt and decrypt data using its locally stored key, eliminating dependence on remote key management systems and their associated complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If encryption keys are transmitted over encrypted channels for key escrow, then data protection is improved, but vulnerability to unauthorized access and system attacks increases

Engineering Contradiction:
Improvedata protectionVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent removes the key transmission process entirely by extracting the encryption key from remote storage and embedding it locally on the client device. This eliminates the encrypted channel transmission step that creates vulnerability points, while the key remains protected through local encryption of data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The encryption key is preliminarily established and stored on the client device before any data encryption operations. This preliminary local key establishment eliminates the need for subsequent key transmission over networks, removing the vulnerability to interception and attacks on key channels.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If remote key storage and authentication are implemented, then key management security is improved, but system performance decreases

Engineering Contradiction:
Improvekey management securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts key management functions from the remote server and implements them locally on the client device. The device independently manages its encryption key without requiring remote authentication or key retrieval operations, eliminating network latency and server processing overhead that degrade performance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The client device performs self-service key management operations locally, including encryption and decryption of data without contacting remote key escrow services. This eliminates network communication overhead and server authentication delays, significantly improving system performance while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11032254B2Binding data to a network in the presence of an entity
Publication Date: 2021.06.08 RED HAT INC
  • US11032254B2 patent drawing
  • US11032254B2 patent drawing
  • US11032254B2 patent drawing

AI summary

Implementations of the disclosure provide for binding data to a network in the presence of an entity. In one implementation, a cryptographic system is provided. The cryptographic system includes a memory to store encrypted data, and a processing device, operatively coupled to the memory, to identify a public key for a communications device in response to an indication of a presence of the communications device on a network. A first intermediate is determined in view of the public key for the communications device and in view of an acquisitioning public key. The acquisitioning public key associated with the encrypted data. A second intermediate public key is received from the communications device in view of the first intermediate public key. Thereupon, the encrypted data is decrypted using an encryption key derived at least from the second intermediate public key.