Customer Data Encryption via Segmented Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Third-party service providers storing customer data face challenges in securing access to sensitive data, as employees or hackers with unauthorized access can compromise the information, leading to additional workload and customer concerns.

Innovation Solution

A system utilizing processor-based customer premise equipment (CPE) with an application programming interface (API) and a key manager to generate and manage encryption keys, ensuring that customer data is encrypted and accessible only to the customer, with the service provider storing encrypted data and keys in secure channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If customer data is stored by a third party service provider, then data storage and management capabilities are improved, but data security and access control deteriorate

Engineering Contradiction:
Improvedata storage capabilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The encryption key is segmented into two parts: a customer-controlled secret key and a service provider-controlled master key. The CPE generates the secret key, which is then encrypted by the service provider using the master key. This segmentation ensures that neither party alone can access the plaintext data, resolving the contradiction between storage capability and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary encryption mechanism where the service provider acts as a mediator that encrypts the secret key with its own master key before storing it. This intermediary layer ensures that the service provider can store and manage customer data without having direct access to the decryption keys, thus maintaining security while enabling storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If service provider employees or systems access customer data, then service management and support are improved, but unauthorized access risks increase

Engineering Contradiction:
Improveservice managementVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The secret key is extracted from the service provider's control environment and generated exclusively by the customer's CPE. The service provider only stores the encrypted version of this key, which cannot be decrypted without the customer's secret key. This extraction eliminates the risk of service provider employees accessing customer data while still allowing service management operations.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If data is encrypted with customer-controlled keys, then data privacy and security are improved, but key management complexity increases

Engineering Contradiction:
Improvedata privacyVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the key generation and key encryption processes into a unified workflow performed by the CPE. The CPE generates the secret key, encrypts it with the service provider's master key, and stores both the encrypted key and encrypted data together in the service provider's system. This merging simplifies key management by automating the process and eliminating the need for separate key management infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10250385B2Customer call logging data privacy in cloud infrastructure
Publication Date: 2019.04.02 CLOUD9 TECHNOLOGIES LLC
  • US10250385B2 patent drawing
  • US10250385B2 patent drawing
  • US10250385B2 patent drawing

AI summary

Systems and methods are provided for encrypting data at a customer for storage at a hosted service provider. In addition to the data being encrypted by the client, the secret encryption key used to encrypt the data is also encrypted. Both the encrypted data and the encrypted secret encryption key are transmitted to the service provider who may further encrypt the data with another encryption key and who stores the further encrypted data, the encrypted secret encryption key and the another encryption key.