Domain-Specific Key Hierarchy for Secure Data Backup Without Re-Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage and communication systems are vulnerable to key theft and resource-intensive due to the use of a single key for all data, and decrypting and re-encrypting data during migration, backup, and restore operations is inefficient.

Innovation Solution

A data management system that uses domain protection keys specific to each domain, secured by a system protection key and a master key, allowing for secure data storage and transfer without decrypting and re-encrypting data, utilizing the key management interoperability protocol for key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single key is used for all data in storage system, then key management is simplified, but the system becomes vulnerable to key theft and security breaches

Engineering Contradiction:
Improvekey management complexityVSAvoiddata security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the storage system into multiple domains, each with its own domain protection key. This segmentation allows independent security management for each domain, so that compromise of one key does not affect other domains. The system maintains simplified key management within each domain while achieving enhanced overall security through the multi-domain structure.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple keys are used for different data domains, then data security is improved, but key management becomes more complex and resource-intensive

Engineering Contradiction:
Improvedata securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a nested key hierarchy where domain protection keys are secured by a system protection key, which in turn is secured by a master key. This nesting structure allows secure management of multiple domain keys through a hierarchical relationship, reducing the operational complexity of managing multiple keys while maintaining security.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The system introduces a system protection key as an intermediary between the master key and domain protection keys. This intermediary layer simplifies key management operations by providing a single system-level key that can manage multiple domain keys, reducing the complexity of direct master-key-to-domain-key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If data is decrypted and re-encrypted during migration, backup, or restore operations, then key flexibility is improved, but system performance decreases due to resource intensity and time consumption

Engineering Contradiction:
Improvekey flexibilityVSAvoidsystem efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent applies preliminary encryption by domain protection keys to data before storage. During migration, backup, or restore operations, the pre-applied encryption allows data to be moved or copied in encrypted form without requiring decryption and re-encryption, significantly improving system efficiency while maintaining key flexibility through the domain-specific key structure.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains data in continuously encrypted form using domain protection keys throughout storage, migration, backup, and restore operations. This continuous encryption state eliminates the need to interrupt the data protection action by decrypting and re-encrypting, thereby maintaining high system productivity while preserving key management flexibility.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP3529739B1Method and system for protecting user data using individualized keys to enable secure compartmentalized data backup/restore
Publication Date: 2022.04.27 THALES DIS CPL USA INC
  • EP3529739B1 patent drawingFigure 1
  • EP3529739B1 patent drawingFigure 2
  • EP3529739B1 patent drawingFigure 3

AI summary

A data management system is provided. The system includes at least one processor, configured to couple to a plurality of domains of a storage memory. The at least one processor is configured to perform actions. The actions include securing data in each of the plurality of domains, using a plurality of domain protection keys, each domain protection key specific to one of the plurality of domains, and securing the plurality of domain protection keys, using a system protection key. A method for protecting user data is also provided.