Credential Vault Key Management for Data Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face a challenge in providing both strong security and good performance for data at rest, as increased security measures often lead to decreased system performance and user experience, especially with limited processing resources in trusted platform modules (TPM) and the risk of compromised TPMs exposing user data.
Innovation Solution
The implementation of an out-of-band management platform with a credential vault using an advanced encryption standard (AES) key, which provides an additional layer of security by storing and managing data encryption keys separately from the TPM, allowing for faster access and secure storage, thereby reducing reliance on TPM processing and minimizing exposure to memory attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data encryption keys are stored and managed using TPM, then security is provided, but response times increase due to constant TPM processing and limited processing resources
Solution Approach 1:
The patent introduces a credential vault as an intermediary component that manages data encryption keys separately from the TPM. The credential vault acts as a mediator between the filesystem and TPM, caching decryption keys to reduce direct TPM processing requirements and thereby decreasing response times while maintaining security through controlled key access
Solution Approach 2:
The patent segments the key management function from the TPM by creating a separate credential vault component. This segmentation allows the credential vault to handle key caching and management tasks independently, reducing the constant processing burden on the TPM and improving system response times
2Reliability
If TPM is used for hardware-based security functions, then security protection is provided, but a compromised TPM can expose user data
Solution Approach 1:
The credential vault serves as a protective intermediary that isolates decryption keys from direct TPM exposure. By caching keys in the credential vault and controlling access patterns, the system reduces the attack surface for memory attacks while maintaining the security benefits of TPM-based key protection
Solution Approach 2:
The patent extracts decryption keys from permanent storage and places them in a controlled credential vault environment. This extraction allows for temporary key availability when needed while limiting exposure to memory attacks, as keys are not permanently resident in vulnerable memory locations
3Reliability
If constant TPM processing is used for encryption operations, then security is maintained, but processing resources are limited and performance decreases
Solution Approach 1:
The credential vault performs preliminary actions by caching decryption keys in advance before they are needed for decryption operations. This preliminary key availability eliminates the need for constant TPM processing during normal filesystem operations, thereby improving system performance while maintaining security
Solution Approach 2:
The credential vault acts as a mediator that reduces the frequency of TPM processing by caching keys locally. This intermediary layer handles key management tasks without requiring constant TPM involvement, improving overall system productivity while preserving security through controlled key access
Data Source
AI summary
A subset of data encryption keys are stored in plain text form in system memory of an information handling system. A master key and another subset of the data encryption keys are stored in a credential vault of the information handling system. The credential vault forms part of an out-of-band management platform and is protected by an AES key. A request is received for a data encryption key to decrypt a unit of data backed up to backup storage of the information handling system, the unit of data having been encrypted by the data encryption key, and the data encryption key having been encrypted by the master key and stored at the backup storage as an encrypted data encryption key. One or more locations are checked for the data encryption key. The one or more locations include the system memory, credential vault, and backup storage.


