Customer Data Encryption via Segmented Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Third-party service providers storing customer data face challenges in securing access to sensitive data, as employees or hackers with unauthorized access can compromise the information, leading to additional workload and customer concerns.
Innovation Solution
A system utilizing processor-based customer premise equipment (CPE) with an application programming interface (API) and a key manager to generate and manage encryption keys, ensuring that customer data is encrypted and accessible only to the customer, with the service provider storing encrypted data and keys in secure channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If customer data is stored by a third party service provider, then data storage and management capabilities are improved, but data security and access control deteriorate
Solution Approach 1:
The encryption key is segmented into two parts: a customer-controlled secret key and a service provider-controlled master key. The CPE generates the secret key, which is then encrypted by the service provider using the master key. This segmentation ensures that neither party alone can access the plaintext data, resolving the contradiction between storage capability and security.
Solution Approach 2:
The patent introduces an intermediary encryption mechanism where the service provider acts as a mediator that encrypts the secret key with its own master key before storing it. This intermediary layer ensures that the service provider can store and manage customer data without having direct access to the decryption keys, thus maintaining security while enabling storage.
2Ease of operation
If service provider employees or systems access customer data, then service management and support are improved, but unauthorized access risks increase
Solution Approach 1:
The secret key is extracted from the service provider's control environment and generated exclusively by the customer's CPE. The service provider only stores the encrypted version of this key, which cannot be decrypted without the customer's secret key. This extraction eliminates the risk of service provider employees accessing customer data while still allowing service management operations.
3Reliability
If data is encrypted with customer-controlled keys, then data privacy and security are improved, but key management complexity increases
Solution Approach 1:
The patent merges the key generation and key encryption processes into a unified workflow performed by the CPE. The CPE generates the secret key, encrypts it with the service provider's master key, and stores both the encrypted key and encrypted data together in the service provider's system. This merging simplifies key management by automating the process and eliminating the need for separate key management infrastructure.
Data Source
AI summary
Systems and methods are provided for encrypting data at a customer for storage at a hosted service provider. In addition to the data being encrypted by the client, the secret encryption key used to encrypt the data is also encrypted. Both the encrypted data and the encrypted secret encryption key are transmitted to the service provider who may further encrypt the data with another encryption key and who stores the further encrypted data, the encrypted secret encryption key and the another encryption key.


