Directory Service Device for Cloud Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a cloud key system, client devices face difficulties in accessing the appropriate key cloud device for decryption services when multiple key cloud devices are dispersed and use different decryption keys, especially when they do not possess the name information of the key cloud device.

Innovation Solution

The solution involves obtaining address information of a key cloud device providing a cloud-key management type decryption service using name information generated from a value corresponding to the decryption key, allowing clients to access the correct key cloud device for decryption services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple key cloud devices are dispersed and use different decryption keys, then decryption service capability is improved, but client device's ability to access the correct key cloud device deteriorates

Engineering Contradiction:
Improvedecryption service capabilityVSAvoidaccess to correct key cloud device
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces a directory service device as an intermediary between client devices and key cloud devices. This mediator stores the correspondence between decryption keys and key cloud device address information, enabling clients to easily locate the correct key cloud device without directly managing the dispersed key infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a single key cloud device provides decryption service, then system complexity is reduced, but service availability and scalability deteriorate

Engineering Contradiction:
Improvesystem complexityVSAvoidservice availability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the key management functionality across multiple key cloud devices, each holding different decryption keys. This segmentation improves service availability and scalability while the directory service device maintains low system complexity by providing a simple lookup mechanism for key-device correspondence.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10033711B2Directory service device, client device, key cloud system, method thereof, and program
Publication Date: 2018.07.24 NIPPON TELEGRAPH & TELEPHONE CORP
  • US10033711B2 patent drawing
  • US10033711B2 patent drawing
  • US10033711B2 patent drawing

AI summary

Name information which is generated by using a value corresponding to a decryption key and address information of a key cloud device which provides a cloud-key management type decryption service in which the decryption key is used are stored in a storage of a directory service device in a manner to associate the name information with the address information, and a searching unit of the directory service device searches the storage by using the inputted name information to obtain address information corresponding to the inputted name information.