Cloud Key Management Service with Hardware Security Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing collaboration environments in cloud-based settings lack client-side control and configurability for security mechanisms, particularly in data encryption, which limits enterprise control over key management and access monitoring.

Innovation Solution

The implementation of a hardware security module (HSM) with local key encryption and automatic generation of audit log information, along with a rule engine for client-side control and configurability, enables enterprise clients to monitor and manage key access, including a 'kill switch' for remote key management services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security mechanisms are added to cloud-based collaboration environments, then data security is improved, but client-level control and configurability of security mechanisms deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidclient-level control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments key management control into two distinct layers: enterprise-level administrative control and user-level operational access. The key management service separates encryption key storage (enterprise-controlled) from data encryption/decryption operations (user-accessible), allowing enterprises to maintain security policies while users perform collaborative operations. This segmentation resolves the contradiction by enabling both strong security and client-level configurability through differentiated access controls.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key management service as an intermediary component between enterprise administrators and end users. This service acts as a mediator that receives encryption/decryption requests from users, validates them against enterprise policies, and performs key operations. The intermediary enables user-level control for collaboration while maintaining enterprise-level security oversight, resolving the contradiction between security and adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If remote key management services are implemented, then enterprise control over key encryption is improved, but system complexity deteriorates

Engineering Contradiction:
Improveenterprise controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts key management functionality from the core collaboration platform into a separate, dedicated key management service. This extraction isolates the complexity of cryptographic operations, key storage, and policy enforcement into a specialized component, allowing the main collaboration system to remain simple while enterprise control over encryption is enhanced through the dedicated service.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The key management service is designed as a universal component that handles multiple functions: key generation, storage, encryption, decryption, key rotation, and policy enforcement. By consolidating these diverse functions into a single multi-functional service, the patent reduces overall system complexity compared to having separate mechanisms for each cryptographic operation, while maintaining strong enterprise control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If access monitoring and audit logging are implemented, then security monitoring capability is improved, but processing overhead and system performance deteriorates

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-configuring access policies, permissions, and audit rules in the key management service before actual cryptographic operations occur. Enterprise administrators define access control policies and monitoring parameters in advance, allowing the system to quickly evaluate requests against pre-established rules rather than making complex decisions in real-time during encryption/decryption operations, thus minimizing performance overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where audit log information is generated and returned to the key management service for analysis. This feedback loop allows the service to learn from access patterns and enforce policies more efficiently over time, improving security monitoring capability while the structured feedback process prevents excessive processing overhead by focusing analysis on relevant access events.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9756022B2Enhanced remote key management for an enterprise in a cloud-based environment
Publication Date: 2017.09.05 BOX INC
  • US9756022B2 patent drawing
  • US9756022B2 patent drawing
  • US9756022B2 patent drawing

AI summary

Systems and methods are disclosed for facilitating remote key management services in a collaborative cloud-based environment. In one embodiment, the remote key management architecture and techniques described herein provide for local key encryption and automatic generation of a reason code associated with content access. The reason code is logged by a hardware security module which is monitored by a remote client device (e.g., an enterprise client) to control a second (remote) layer of key encryption. The remote client device provides client-side control and configurability of the second layer of key encryption.