Encrypted Disk Inspection via Custom Key Policy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Encrypted disks in cloud computing environments pose a challenge for cybersecurity threat detection, as scanners require unencrypted volumes to access and decrypt keys may not be readily available.

Innovation Solution

A method and system for inspecting encrypted disks using a custom key, which involves detecting encrypted disks, authorizing a key policy on a security policy server, decrypting the disk with the custom key, and generating an inspectable disk based on the decrypted encrypted disk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If disks are encrypted to protect information, then security is improved, but the ability to scan for cybersecurity threats is lost

Engineering Contradiction:
ImprovesecurityVSAvoidthreat detection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a key management service and inspector account as intermediaries between the encrypted disk and the scanner. The key policy authorizes the inspector account to decrypt the disk, enabling the scanner to access and inspect the decrypted contents while the original encryption remains intact for production use.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the disk inspection process into separate stages: the production environment maintains encrypted disks for security, while an inspector account creates and manages decrypted copies specifically for scanning purposes. This segmentation allows both security and threat detection to coexist.

Inventive Principle:
Principle #1Segmentation

2Difficulty of detecting and measuring

If decryption keys are made available for scanning, then inspection capability is improved, but security is compromised

Engineering Contradiction:
Improveinspection capabilityVSAvoidsecurity
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent applies different access permissions to different accounts and purposes. The key policy is configured with specific conditions that grant decryption access only to the inspector account for scanning operations, while maintaining encryption for all other access scenarios. This localized permissioning enables inspection without compromising overall security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The key management service acts as an intermediary that controls key access based on policies. It evaluates requests from different accounts and grants decryption permissions only when policy conditions are met, thereby enabling necessary inspection while maintaining security through controlled access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If custom key policies are configured for inspector accounts, then access control is improved, but system complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The key management service provides a universal platform that handles multiple functions: key storage, policy configuration, decryption authorization, and access control. This multi-functional system manages the complexity internally while presenting a simplified interface for configuring inspector account access.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250141666A1System and method for encrypted disk inspection
Publication Date: 2025.05.01 WIZ INC
  • US20250141666A1 patent drawing
  • US20250141666A1 patent drawing
  • US20250141666A1 patent drawing

AI summary

A system and method for inspecting encrypted disks for a cybersecurity object using a custom key is presented. The method includes detecting an encrypted disk associated with a workload in a cloud computing environment, the cloud computing environment including a security policy server; authorizing a key policy for decrypting the encrypted disk on the security policy server for a custom key associated with an inspector account; decrypting the encrypted disk with the custom key by the inspector account; and generating an inspectable disk based on the decrypted encrypted disk.