Distributed Key Management with Trust-Based Key Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional centralized key management systems in information handling systems are vulnerable to attacks and require redundant subsystems that do not provide additional functionality, leading to potential unauthorized access and inefficiencies.

Innovation Solution

A distributed key management system utilizing System Control Processor (SCP) subsystems with independent key management engines and databases, enabling secure communication channels and trust determination to manage keys in a decentralized manner, ensuring only trusted systems access the keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized key management system is used, then key management functionality is provided, but the system becomes vulnerable to attacks and requires redundant subsystems

Engineering Contradiction:
Improvekey management availabilityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the centralized key management system into multiple distributed key management subsystems, each operating independently. Each subsystem manages keys for a specific subset of server devices, eliminating the single point of failure while reducing the attack surface for each individual subsystem.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key distribution subsystem that acts as an intermediary between client devices and the key management subsystems. This intermediary component securely distributes encryption keys to client devices without requiring direct access to the key storage databases, adding an additional layer of security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If redundant key management subsystems are implemented, then high availability is achieved, but device complexity increases and functionality is reduced

Engineering Contradiction:
Improvekey management availabilityVSAvoidkey management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs key management subsystems that can serve multiple purposes: they manage encryption keys for server devices, provide key distribution through the key distribution subsystem, and offer backup capabilities. This multi-functionality reduces the need for separate dedicated components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines the key storage database and key management processing into integrated subsystems that operate together as a unified unit. The key distribution subsystem merges key management functions with distribution functions, reducing overall system complexity while maintaining availability.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If a centralized key management system is used, then key management is simplified, but security is compromised due to single point of failure

Engineering Contradiction:
Improvekey management simplicityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the centralized key management into multiple distributed subsystems, each managing keys for specific server devices. This segmentation ensures that compromise of one subsystem does not affect others, reducing the overall security risk while maintaining operational simplicity through automated key distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key distribution subsystem serves as an intermediary that simplifies key management operations by automatically distributing encryption keys to client devices without requiring manual intervention. This intermediary layer maintains security by preventing direct access to key storage databases while preserving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4229818B1Distributed key management system
Publication Date: 2025.11.26 DELL PROD LP

AI summary

A distributed key management system includes a first SCP subsystem coupled to second SCP subsystems via a network. The first SCP subsystem establishes secure communication channels with the second SCP subsystems, and a first key management subsystem in the first SCP subsystem retrieves enabling key(s) for communicating via the secure communication channels from a second key management subsystem in one of the second SCP subsystems, and stores the enabling key(s). The first key management subsystem then receives a first enabling key request from the first SCP subsystem and determines whether the first SCP subsystem is trusted. If the first SCP subsystem is trusted, the first key management subsystem provides the first SCP subsystem access to the at least one enabling key. If the first SCP subsystem is not trusted, the first key management subsystem prevents the first SCP subsystem from accessing the at least one enabling key stored.