Encryption Key Ticket Management for Cloud Data Confidentiality

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud-based Software-Defined Data Centers, managing encryption keys becomes challenging due to increased virtualization, leading to potential compromises in data security, as existing solutions often provide unnecessary access to hosts, increasing the risk of encryption scheme compromises.

Innovation Solution

A method is introduced where a hypervisor receives an encryption key ticket to retrieve an encryption key from a key manager, with a key policy defining specifications like algorithm and strength, and a controller generates security parameter indices and key identifiers, ensuring that only necessary encryption rules are applied to specific hosts, implementing the principle of least privilege.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption keys are distributed to verified trusted hosts, then data confidentiality is protected, but hosts gain access to unnecessary keys increasing security risk

Engineering Contradiction:
Improvedata confidentialityVSAvoidsecurity risk from unnecessary key access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments key access rights by creating a hierarchical structure where key policies are divided into multiple encryption rules. Each rule specifies particular conditions under which a host can access specific keys, rather than providing blanket access. This segmentation allows precise control over which keys each host can access based on their actual needs for different virtual machines or workloads.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by making key access rights specific to individual hosts, virtual machines, and encryption scenarios. Each host receives only the keys necessary for its specific functions, with access rights tailored to local requirements rather than uniform distribution. This is achieved through host-specific encryption rules that define precise access conditions.

Inventive Principle:
Principle #3Local quality

2Reliability

If encryption keys are distributed broadly to ensure data protection, then data security is maintained, but the complexity of key management increases

Engineering Contradiction:
Improvedata securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal key management framework where a single key policy object can serve multiple purposes through its multiple encryption rules. This universal structure allows the same policy to govern access for different hosts, virtual machines, and key types, reducing the need for separate management systems for each scenario while maintaining comprehensive security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary key manager component that mediates between key generation and distribution. This intermediary automatically manages the complex tasks of key generation, policy evaluation, and selective distribution based on encryption rules, relieving the burden of manual key management complexity while ensuring secure distribution appropriate to each host's needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If hosts are given access to multiple encryption keys, then comprehensive data protection is achieved, but the opportunity for compromising the encryption scheme increases

Engineering Contradiction:
Improvedata protectionVSAvoidcompromise risk
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent implements dynamic key access control where encryption rules can be modified, added, or removed based on changing security requirements. Host access rights are not static but can be adjusted dynamically through policy updates, allowing the system to adapt to evolving threats and operational needs while maintaining the principle of least privilege throughout the system's lifecycle.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11533301B2Secure key management protocol for distributed network encryption
Publication Date: 2022.12.20 VMWARE INC
  • US11533301B2 patent drawing
  • US11533301B2 patent drawing
  • US11533301B2 patent drawing

AI summary

For an encryption management module of a host that executes one or more data compute nodes (DCNs), some embodiments of the invention provide a method of providing key management and encryption services. The method initially receives an encryption key ticket at an encryption management module to be used to retrieve an encryption key identified by the ticket from a key manager. When the encryption key has been retrieved, the method uses the encryption key to encrypt a message sent by a data compute node executing on the host requiring encryption according to an encryption rule. The encryption key ticket, in some embodiments, is generated for an encryption management module to implement the principle of least privilege. The ticket acts as a security token in retrieving encryption keys from a key manager. Ticket distribution and encryption rule distribution are independent of each other in some embodiments.