Dual-Layer Encryption for Integrated Infrastructure Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Integrated infrastructure systems face security issues with communications between components due to vulnerabilities in conventional security techniques, such as static vendor-based certificates, which can be exploited by attacks like denial-of-service and man-in-the-middle attacks, and Multi-Factor Authentication solutions hinder automation, making them infeasible for most deployments.
Innovation Solution
An Information Handling System (IHS) with a processing system and memory that includes instructions to provide an integrated infrastructure secure communication engine, which receives communications, retrieves vendor-based keys, encrypts them, generates random keys, and transmits second-level encrypted communications to ensure secure data transmission between components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security techniques (SSL, TLS) with static vendor-based certificates are used to secure communications, then communication security is improved, but the system becomes vulnerable to denial-of-service and man-in-the-middle attacks that can compromise the certificates
Solution Approach 1:
The patent transitions from static vendor-based certificates to dynamic key exchange mechanisms. Each communication session generates unique random keys that are exchanged between components, replacing the static certificate model with a dynamic key derivation process that prevents replay attacks and compromises from static certificate theft.
Solution Approach 2:
The security model is segmented into multiple independent layers: vendor-based root certificates for identity verification, component-specific random keys for session encryption, and hierarchical trust boundaries. This segmentation isolates compromises at lower levels from affecting the entire system, as each component has its own key pair rather than sharing a common certificate.
2Reliability
If Multi-Factor Authentication (MFA) is implemented to secure computing devices, then security against unauthorized access is improved, but automation of the integrated infrastructure system is prevented
Solution Approach 1:
The system implements self-service authentication where components automatically present their unique identifiers and random keys to verify trust relationships. The authentication process is automated through cryptographic proof mechanisms that eliminate the need for manual MFA verification while maintaining security through unique, non-reusable credentials for each component.
3Reliability
If firewalls are deployed to protect computing devices in the integrated infrastructure system, then endpoint security is improved, but the security can be circumvented via attacks on vendor-based certificates
Solution Approach 1:
The patent introduces cryptographic intermediaries in the form of unique random keys and trust boundaries that mediate between components. These intermediaries create a layer of cryptographic verification that sits between the firewall and the actual data transmission, allowing the system to verify identity and integrity without relying solely on perimeter firewalls that can be circumvented.
Data Source
AI summary
An integrated infrastructure secure communication system includes at least one chassis, and a plurality of computing devices that are located in the at least one chassis and that are coupled to each other. A first computing device included in the plurality of computing device receives a communication from a first component in the first computing device, retrieves a vendor-based key, and encrypts the communication using the vendor-based key to provide a first-level encrypted communication. The first computing device also generates a first random key, encrypts the first-level encrypted communication with the first random key to provide a second-level encrypted communication, and transmits the second-level encrypted communication to a second computing device that is included in the plurality of computing devices.


