Domain-Specific Key Hierarchy for Secure Data Backup Without Re-Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage and communication systems are vulnerable to key theft and resource-intensive due to the use of a single key for all data, and decrypting and re-encrypting data during migration, backup, and restore operations is inefficient.
Innovation Solution
A data management system that uses domain protection keys specific to each domain, secured by a system protection key and a master key, allowing for secure data storage and transfer without decrypting and re-encrypting data, utilizing the key management interoperability protocol for key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single key is used for all data in storage system, then key management is simplified, but the system becomes vulnerable to key theft and security breaches
Solution Approach 1:
The patent divides the storage system into multiple domains, each with its own domain protection key. This segmentation allows independent security management for each domain, so that compromise of one key does not affect other domains. The system maintains simplified key management within each domain while achieving enhanced overall security through the multi-domain structure.
2Reliability
If multiple keys are used for different data domains, then data security is improved, but key management becomes more complex and resource-intensive
Solution Approach 1:
The patent implements a nested key hierarchy where domain protection keys are secured by a system protection key, which in turn is secured by a master key. This nesting structure allows secure management of multiple domain keys through a hierarchical relationship, reducing the operational complexity of managing multiple keys while maintaining security.
Solution Approach 2:
The system introduces a system protection key as an intermediary between the master key and domain protection keys. This intermediary layer simplifies key management operations by providing a single system-level key that can manage multiple domain keys, reducing the complexity of direct master-key-to-domain-key management.
3Adaptability or versatility
If data is decrypted and re-encrypted during migration, backup, or restore operations, then key flexibility is improved, but system performance decreases due to resource intensity and time consumption
Solution Approach 1:
The patent applies preliminary encryption by domain protection keys to data before storage. During migration, backup, or restore operations, the pre-applied encryption allows data to be moved or copied in encrypted form without requiring decryption and re-encryption, significantly improving system efficiency while maintaining key flexibility through the domain-specific key structure.
Solution Approach 2:
The system maintains data in continuously encrypted form using domain protection keys throughout storage, migration, backup, and restore operations. This continuous encryption state eliminates the need to interrupt the data protection action by decrypting and re-encrypting, thereby maintaining high system productivity while preserving key management flexibility.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A data management system is provided. The system includes at least one processor, configured to couple to a plurality of domains of a storage memory. The at least one processor is configured to perform actions. The actions include securing data in each of the plurality of domains, using a plurality of domain protection keys, each domain protection key specific to one of the plurality of domains, and securing the plurality of domain protection keys, using a system protection key. A method for protecting user data is also provided.