Client Key Management Service for Centralized Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption key management systems face challenges in synchronization with communication management, leading to loose controls and potential breakdowns in communication security due to the lack of automation in key management across devices and the absence of a mechanism for centralized key registration and distribution.

Innovation Solution

A client-based service is introduced to integrate local applications, servers, and infrastructure with an encryption key management system, enabling automated key management operations through a data connection with a file kernel driver, request handling, and policy-based key management, facilitating key registration, recertification, and distribution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If encryption key management is initiated and executed at the device level, then local control and autonomy are improved, but synchronization with communication management deteriorates leading to loose controls

Engineering Contradiction:
Improvelocal controlVSAvoidsynchronization with communication management
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a key management server as an intermediary between devices and communication management systems. This server receives key management requests from devices, processes them according to communication management policies, and returns appropriate keys. This intermediary structure maintains local device autonomy while ensuring centralized synchronization and control, resolving the contradiction between local control and communication management synchronization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If no automation mechanism exists for obtaining and registering keys, then device simplicity is improved, but key management efficiency deteriorates

Engineering Contradiction:
Improvedevice simplicityVSAvoidkey management efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent implements automated key management where devices automatically generate key management requests, retrieve appropriate keys from the key management server, and register them without manual intervention. The system includes automated key generation, automatic key registration, and proactive key distribution based on communication needs. This automation maintains device simplicity while dramatically improving key management efficiency and speed.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If separate key distribution activities are required for different applications, then application-specific security control is improved, but system complexity deteriorates

Engineering Contradiction:
Improveapplication-specific security controlVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal key management server that serves multiple applications and communication types through a single integrated system. The server handles symmetric keys, asymmetric keys, and ephemeral keys for various applications (messaging, communication, storage) through unified key generation, distribution, and management processes. This universal approach maintains application-specific security requirements while reducing overall system complexity compared to separate key management systems for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9967289B2Client services for applied key management systems and processes
Publication Date: 2018.05.08 FORNETIX LLC
  • US9967289B2 patent drawing
  • US9967289B2 patent drawing
  • US9967289B2 patent drawing

AI summary

Embodiments described herein relate to apparatuses and methods for enabling applied key management operations at a client including establishing a data connection with a file kernel driver of the client to enable the applied key management operation, receiving a request pertaining to encryption key data, relaying the request pertaining to the encryption key data to an applied key management system, and receiving a response regarding the request from the applied key management system based on at least one policy of the applied key management system.