Cloud Key Management via Extraction and Intermediary Principles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud computing key management systems expose encryption keys or data in plaintext, compromising security, especially in distributed key management systems where physical and network vulnerabilities can lead to sensitive data exposure.

Innovation Solution

Implementing a key management system that maintains cryptographic functions on administrative hosts and endpoints outside cloud resources, ensuring only encrypted data is stored in the cloud, using platform-independent cryptographic functions and libraries within web browsers for secure data handling and storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If encryption keys are stored in cloud-based resources for key management, then key management functionality is improved and user flexibility is increased, but security is worsened because keys may be exposed in plaintext form due to physical vulnerabilities

Engineering Contradiction:
Improvekey management functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the cryptographic key management functions from cloud-based resources and places them on locally controlled administrative hosts and endpoints. This ensures that encryption keys never reside in cloud-based resources in plaintext form, eliminating the security vulnerability while preserving key management functionality through cloud-based coordination and key distribution.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cloud-based resources as intermediaries that facilitate key management operations without storing plaintext keys. The cloud resources transmit encrypted key material and coordinate key distribution, acting as a mediator that enables remote key management while maintaining security by never exposing plaintext keys in the cloud environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic keys are maintained outside cloud resources on administrative hosts, then security is improved by preventing key exposure, but device complexity increases due to distributed key management requirements

Engineering Contradiction:
ImprovesecurityVSAvoidkey management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universal cryptographic functions and libraries that can operate across different platforms (cloud resources, administrative hosts, endpoints). This multi-functionality reduces the need for platform-specific key management solutions, thereby reducing overall system complexity while maintaining security through distributed key management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the key management system into distinct functional components: key generation on administrative hosts, key distribution through cloud resources, and key usage on endpoints. This segmentation allows each component to be optimized independently and simplifies the overall architecture by clearly defining responsibilities and interfaces between components.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If cloud-based resources are used for data storage and processing, then user flexibility and accessibility are improved, but security vulnerabilities increase due to lack of physical and network security control

Engineering Contradiction:
Improveuser flexibilityVSAvoidphysical and network security vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive cryptographic operations and key material from cloud-based resources to locally controlled administrative hosts and endpoints. This ensures that even though data is stored and processed in the cloud, the security-critical key management functions remain under local control, eliminating the security vulnerability while preserving cloud-based accessibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies preliminary encryption to data before it is transmitted to or stored in cloud-based resources. By encrypting data with keys that never leave local control, the system preemptively protects against potential security breaches in the cloud environment, ensuring that even if cloud resources are compromised, the encrypted data remains secure.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS9621524B2Cloud-based key management
Publication Date: 2017.04.11 SOPHOS LTD
  • US9621524B2 patent drawing
  • US9621524B2 patent drawing
  • US9621524B2 patent drawing

AI summary

Cloud storage of sensitive data is improved by ensuring that all cloud-based data is encrypted at all times, not only when the data is at rest (i.e., stored), but also while data is being processed or communicated. Cryptographic keys can advantageously be managed via cloud based resources without exposing sensitive data. Instead, a key management system maintains cryptographic functions on administrative hosts and endpoints outside of cloud-based resources so that any vulnerabilities of the cloud-based resources will expose only encrypted data, and keys and sensitive data will never be exposed in unencrypted form. Thus sensitive data is protected end-to-end among hosts and endpoints using, e.g., platform independent cryptographic functions and libraries within a web browser or the like, and the cloud functions simply as a storing and forwarding medium for secure data.