Encrypted Disk Inspection via Custom Key Policy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Encrypted disks in cloud computing environments pose a challenge for cybersecurity threat detection, as scanners require unencrypted volumes to access and decrypt keys may not be readily available.
Innovation Solution
A method and system for inspecting encrypted disks using a custom key, which involves detecting encrypted disks, authorizing a key policy on a security policy server, decrypting the disk with the custom key, and generating an inspectable disk based on the decrypted encrypted disk.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If disks are encrypted to protect information, then security is improved, but the ability to scan for cybersecurity threats is lost
Solution Approach 1:
The patent introduces a key management service and inspector account as intermediaries between the encrypted disk and the scanner. The key policy authorizes the inspector account to decrypt the disk, enabling the scanner to access and inspect the decrypted contents while the original encryption remains intact for production use.
Solution Approach 2:
The patent segments the disk inspection process into separate stages: the production environment maintains encrypted disks for security, while an inspector account creates and manages decrypted copies specifically for scanning purposes. This segmentation allows both security and threat detection to coexist.
2Difficulty of detecting and measuring
If decryption keys are made available for scanning, then inspection capability is improved, but security is compromised
Solution Approach 1:
The patent applies different access permissions to different accounts and purposes. The key policy is configured with specific conditions that grant decryption access only to the inspector account for scanning operations, while maintaining encryption for all other access scenarios. This localized permissioning enables inspection without compromising overall security.
Solution Approach 2:
The key management service acts as an intermediary that controls key access based on policies. It evaluates requests from different accounts and grants decryption permissions only when policy conditions are met, thereby enabling necessary inspection while maintaining security through controlled access.
3Adaptability or versatility
If custom key policies are configured for inspector accounts, then access control is improved, but system complexity increases
Solution Approach 1:
The key management service provides a universal platform that handles multiple functions: key storage, policy configuration, decryption authorization, and access control. This multi-functional system manages the complexity internally while presenting a simplified interface for configuring inspector account access.
Data Source
AI summary
A system and method for inspecting encrypted disks for a cybersecurity object using a custom key is presented. The method includes detecting an encrypted disk associated with a workload in a cloud computing environment, the cloud computing environment including a security policy server; authorizing a key policy for decrypting the encrypted disk on the security policy server for a custom key associated with an inspector account; decrypting the encrypted disk with the custom key by the inspector account; and generating an inspectable disk based on the decrypted encrypted disk.


