Domain transcendent file cryptology network for multi-cloud key management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern data workflows face significant administrative overhead due to the need for separate key management solutions when working across multiple cloud service providers with different security protocols, and outsourcing to a third party can introduce additional costs and vulnerabilities.

Innovation Solution

Domain transcendent file cryptology networks and methods that enable unique identification and secure transfer of data files based on their attributes, using a single crypto-key solution across multiple cloud providers, eliminating the need for third-party key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate key management solutions are used for each cloud service provider, then data security is maintained according to each provider's protocol, but administrative overhead increases significantly

Engineering Contradiction:
Improvedata securityVSAvoidadministrative overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate key management solutions into a single unified key management system that can handle multiple cloud service providers. The key management system generates and manages cryptographic keys that work across different cloud providers (AWS, Azure, Google Cloud, etc.), eliminating the need for separate key management infrastructure for each provider and reducing administrative overhead while maintaining security compliance.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The key management system is designed with universal functionality to work with multiple cloud service providers through a single interface. It can generate keys, manage key lifecycles, and enforce security policies across diverse cloud environments using a standardized approach, making the system adaptable to different cloud providers without requiring provider-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If key management functions are outsourced to a third party vendor, then administrative burden is reduced, but licensing costs and security vulnerabilities increase

Engineering Contradiction:
Improveadministrative burdenVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The key management system enables organizations to self-manage their cryptographic keys without relying on third-party vendors. The system provides automated key generation, storage, rotation, and revocation capabilities that organizations can control internally, eliminating the need for external key management services while reducing both administrative burden and security risks associated with third-party outsourcing.

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple key management solutions are implemented across cloud providers, then data protection is ensured, but tracking and monitoring become more difficult

Engineering Contradiction:
Improvedata protectionVSAvoidtracking and monitoring
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The key management system segments key management operations into standardized functional components (key generation, storage, access control, rotation, revocation) that can be consistently applied across different cloud providers. This segmentation allows for uniform tracking and monitoring of key lifecycle events regardless of which cloud provider is being used, making it easier to detect and measure security events across the entire multi-cloud environment.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11201857B2Domain transcendent file cryptology network
Publication Date: 2021.12.14 DISNEY ENTERPRISES INC
  • US11201857B2 patent drawing
  • US11201857B2 patent drawing
  • US11201857B2 patent drawing

AI summary

A domain transcendent file cryptology network includes a first data cryptology node in a first data domain having a first security protocol. A hardware processor of the first data cryptology node executes a first instantiation of a software code to receive a request to transfer a data file from the first data domain to a second data domain having a second, different, security protocol, obtain one or more characteristics of the data file, and generate an authentication tag for the data file based on the characteristic(s). The first instantiation of the software code also encrypts the data file and transmits the encrypted data file, the authentication tag, and a decryption key to a second data cryptology node in the second data domain. The decryption key and the authentication tag enable decryption of the encrypted data file by a second instantiation of the software code on the second data cryptology node.