Encryption Key Lockbox Backup via System Stable Values
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data encryption technologies face challenges in securely managing and scaling encryption keys for large data sets, particularly in preventing unauthorized access and ensuring key availability, which can lead to data loss or unauthorized access.
Innovation Solution
A data encryption lockbox system that uses system stable values (SSV) derived from unique data storage system components to securely store and backup encryption keys, requiring a minimum number of matching SSV for access, with a backup copy stored remotely to ensure secure recovery and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption keys are stored securely with strict access controls, then data security is improved, but key availability and accessibility deteriorate
Solution Approach 1:
The encryption key management system is segmented into multiple components: primary lockbox storage, backup lockbox storage, and SSV-based access verification. The key itself is segmented into encrypted form stored in lockbox, with access controlled by separate SSV values. This segmentation allows secure storage while maintaining availability through distributed access paths.
Solution Approach 2:
System Stable Values (SSV) act as intermediaries between the encrypted key data and the decryption process. Instead of direct access to encryption keys, authorized users must first obtain and verify SSV values, which then enable key access. This intermediary layer enhances security while preserving availability for authorized operations.
2Ease of operation
If backup copies of encryption keys are stored, then key availability is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The backup key management system is segmented with separate backup lockbox storage distinct from primary storage. Access to backup keys requires verification of SSV values matching the original system configuration, creating segmented access paths that maintain security while enabling recovery.
Solution Approach 2:
Backup lockboxes are pre-configured with encrypted key copies and associated SSV requirements before actual key loss occurs. The system performs preliminary verification of SSV matching against system configuration, ensuring that backup access is only permitted when properly authorized, thus maintaining security while ensuring availability.
3Reliability
If multiple encryption keys are managed for large data sets, then data protection coverage is improved, but management complexity increases
Solution Approach 1:
The lockbox system serves multiple functions: primary key storage, backup key storage, and access control verification. A single SSV-based verification mechanism handles access control for both primary and backup lockboxes, reducing management complexity while maintaining comprehensive data protection across multiple encryption keys.
Solution Approach 2:
The system uses SSV (System Stable Values) as a parameter change mechanism to manage key access. Instead of managing multiple complex access control lists for different keys, the system transforms access control into verification of stable system parameters, simplifying management of multiple encryption keys while maintaining comprehensive protection.
4Reliability
If encryption technology is deployed across enterprise infrastructure, then data security is improved, but scalability and service disruption issues arise
Solution Approach 1:
The encryption key management system performs self-verification through automatic SSV matching against system configuration. The backup lockbox automatically verifies whether SSV values match the current system state, enabling scalable deployment across enterprise infrastructure without requiring manual configuration or causing service disruption. Each system independently manages its own key access verification.
Data Source
AI summary
The techniques presented herein provide for associating a data encryption lockbox backup with a data storage system. A first set of software system stable values (SSV) is derived from data storage system component values unique to the data storage system. A lockbox storing the first set of SSV and a set of encryption keys associated with a corresponding respective set of data storage system drives is created. Access to the lockbox requires providing a first minimum number of SSV that match corresponding SSV in the first set of SSV. A backup copy of the lockbox is created, wherein access to the backup copy requires providing a second minimum number of SSV that match corresponding SSV in the first set of SSV, wherein the minimum number of SSV is equal to a second match value. The backup copy of the lockbox is stored at a remote location.


