Encryption Key Lockbox Backup via System Stable Values

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data encryption technologies face challenges in securely managing and scaling encryption keys for large data sets, particularly in preventing unauthorized access and ensuring key availability, which can lead to data loss or unauthorized access.

Innovation Solution

A data encryption lockbox system that uses system stable values (SSV) derived from unique data storage system components to securely store and backup encryption keys, requiring a minimum number of matching SSV for access, with a backup copy stored remotely to ensure secure recovery and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption keys are stored securely with strict access controls, then data security is improved, but key availability and accessibility deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidkey availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The encryption key management system is segmented into multiple components: primary lockbox storage, backup lockbox storage, and SSV-based access verification. The key itself is segmented into encrypted form stored in lockbox, with access controlled by separate SSV values. This segmentation allows secure storage while maintaining availability through distributed access paths.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

System Stable Values (SSV) act as intermediaries between the encrypted key data and the decryption process. Instead of direct access to encryption keys, authorized users must first obtain and verify SSV values, which then enable key access. This intermediary layer enhances security while preserving availability for authorized operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If backup copies of encryption keys are stored, then key availability is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvekey availabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The backup key management system is segmented with separate backup lockbox storage distinct from primary storage. Access to backup keys requires verification of SSV values matching the original system configuration, creating segmented access paths that maintain security while enabling recovery.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Backup lockboxes are pre-configured with encrypted key copies and associated SSV requirements before actual key loss occurs. The system performs preliminary verification of SSV matching against system configuration, ensuring that backup access is only permitted when properly authorized, thus maintaining security while ensuring availability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple encryption keys are managed for large data sets, then data protection coverage is improved, but management complexity increases

Engineering Contradiction:
Improvedata protection coverageVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The lockbox system serves multiple functions: primary key storage, backup key storage, and access control verification. A single SSV-based verification mechanism handles access control for both primary and backup lockboxes, reducing management complexity while maintaining comprehensive data protection across multiple encryption keys.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses SSV (System Stable Values) as a parameter change mechanism to manage key access. Instead of managing multiple complex access control lists for different keys, the system transforms access control into verification of stable system parameters, simplifying management of multiple encryption keys while maintaining comprehensive protection.

Inventive Principle:
Principle #35Parameter changes

4Reliability

If encryption technology is deployed across enterprise infrastructure, then data security is improved, but scalability and service disruption issues arise

Engineering Contradiction:
Improvedata securityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The encryption key management system performs self-verification through automatic SSV matching against system configuration. The backup lockbox automatically verifies whether SSV values match the current system state, enabling scalable deployment across enterprise infrastructure without requiring manual configuration or causing service disruption. Each system independently manages its own key access verification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9870481B1Associating a data encryption keystore backup with a computer system
Publication Date: 2018.01.16 EMC IP HLDG CO LLC
  • US9870481B1 patent drawing
  • US9870481B1 patent drawing
  • US9870481B1 patent drawing

AI summary

The techniques presented herein provide for associating a data encryption lockbox backup with a data storage system. A first set of software system stable values (SSV) is derived from data storage system component values unique to the data storage system. A lockbox storing the first set of SSV and a set of encryption keys associated with a corresponding respective set of data storage system drives is created. Access to the lockbox requires providing a first minimum number of SSV that match corresponding SSV in the first set of SSV. A backup copy of the lockbox is created, wherein access to the backup copy requires providing a second minimum number of SSV that match corresponding SSV in the first set of SSV, wherein the minimum number of SSV is equal to a second match value. The backup copy of the lockbox is stored at a remote location.