Multi-Region Encrypted Data Caching via Envelope Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data encryption systems face challenges in scaling the encryption of digital secrets efficiently and providing resilient accessibility, often resulting in bottlenecks and latency issues due to centralized storage and management.
Innovation Solution
The system employs envelope encryption combined with a key management system to generate and cache encrypted data packages, allowing for scalable storage of digital secrets across multiple regional storage servers while maintaining security and resilience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is encrypted using conventional centralized encryption management services, then data security is improved, but scalability and accessibility resilience deteriorate due to bottlenecks and latency
Solution Approach 1:
The patent segments the centralized encryption service into distributed regional encryption services. Each region has its own encryption management capability, allowing independent operation and reducing bottlenecks. The segmentation enables parallel processing of encryption operations across multiple regions, improving scalability while maintaining security through distributed architecture.
Solution Approach 2:
The patent introduces a new dimension of geographic distribution by deploying encryption services across multiple regional locations rather than relying on a single centralized service. This spatial dimensionality change enables local encryption operations to occur closer to data sources, reducing latency and improving accessibility resilience without compromising security.
2Device complexity
If data is stored in centralized storage, then security management is simplified, but accessibility resilience and latency performance worsen due to single-point failures and remote access requirements
Solution Approach 1:
The patent segments centralized storage into multiple regional storage locations, each capable of independently storing and providing access to encrypted data. This segmentation eliminates single-point failures by distributing storage capacity across regions, improving accessibility resilience. Security management remains relatively simple through standardized encryption interfaces while gaining the reliability benefits of distribution.
Solution Approach 2:
The patent introduces regional encryption services as intermediaries between data storage and access requests. These intermediaries handle encryption and decryption operations locally, reducing the need for remote access to centralized storage and improving accessibility resilience. The intermediaries maintain security through consistent encryption practices while enabling faster local operations.
3Device complexity
If decryption operations are centralized, then key management is simplified, but throttling and performance bottlenecks worsen under high demand
Solution Approach 1:
The patent segments centralized decryption operations into distributed regional decryption services. Each region can independently perform decryption operations on data stored locally, eliminating the bottleneck of centralized processing. This segmentation increases overall throughput by enabling parallel decryption operations across multiple regions while maintaining simplified key management through consistent cryptographic interfaces.
Data Source
AI summary
This disclosure describes one or more implementations of systems, non-transitory computer-readable media, and methods that create a secured, versioned, and resilient multi-region caching of digital secrets and application credentials that facilitates scalability of digital secrets without compromising the security of the digital secrets. In particular, in one or more embodiments, the disclosed systems leverage envelope encryption along with management keys of a key management system to cache encrypted data packages that include encrypted digital secrets and encrypted envelope keys at regional storage servers. Furthermore, in some embodiments, the disclosed systems access encrypted digital secrets through regional storage servers by decrypting envelope keys through a key management system and utilizing the envelope keys to extract digital secrets from the encrypted data packages.


