Centralized Data Encryption Service Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing data encryption across various resources and applications in a centralized manner is challenging due to differing encryption requirements based on the type of services provided, such as business analytics versus financial services, within an organization.

Innovation Solution

A data encryption service that provides a centralized framework for managing data encryption, including application policies, cryptographic policies, and encryption objects, allowing for customized encryption based on specific conditions and actions for different user sets or access scenarios, and providing monitoring and alert services for encryption objects.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a centralized framework for managing data encryption is implemented, then encryption management efficiency and compliance are improved, but system complexity increases due to the need to handle different encryption requirements for various services

Engineering Contradiction:
Improveencryption management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments encryption management by creating distinct policy types (application policies, cryptographic policies, data classification policies) that can be independently configured and applied to different resources. This allows the centralized framework to handle diverse encryption requirements through modular policy units rather than monolithic complex logic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces policy templates as intermediary artifacts that mediate between encryption requirements and actual encryption implementation. These templates pre-define encryption configurations and can be selectively applied to resources, simplifying the management interface while maintaining the ability to handle complex service-specific requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If customized encryption policies are applied to different applications and resources, then security compliance is improved, but the difficulty of policy configuration and management increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidpolicy configuration difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary action by pre-configuring encryption policies as templates with all necessary parameters and settings. These templates are prepared in advance and can be directly applied to resources without requiring users to configure complex encryption settings from scratch, thereby maintaining security compliance while simplifying operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables parameter changes by allowing policy templates to be dynamically instantiated with different parameters for different resources. Users can modify template parameters (such as encryption algorithm, key length, key management settings) to match specific resource requirements without changing the underlying policy structure, making configuration easier while maintaining customization.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple encryption objects are managed across diverse services, then encryption coverage is improved, but the challenge of monitoring and lifecycle management increases

Engineering Contradiction:
Improveencryption coverageVSAvoidmonitoring complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements universality by creating a unified encryption object model that can represent different types of encryption artifacts (keys, certificates, secrets) in a consistent manner. The centralized management framework uses universal operations (create, retrieve, rotate, delete, monitor) that work across all encryption object types, improving coverage while simplifying monitoring through standardized interfaces.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent incorporates feedback mechanisms that automatically monitor the state and lifecycle of encryption objects across all services. The system provides status information about key expiration, usage metrics, and compliance state, enabling automated lifecycle management and reducing the complexity of monitoring through continuous feedback loops.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11244061B2Data encryption service
Publication Date: 2022.02.08 ORACLE INT CORP
  • US11244061B2 patent drawing
  • US11244061B2 patent drawing
  • US11244061B2 patent drawing

AI summary

A centralized framework for managing the data encryption of resources is disclosed. A data encryption service is disclosed that provides various services related to the management of the data encryption of resources. The services may include managing application policies, cryptographic policies, and encryption objects related to applications. The encryption objects may include encryption keys and certificates used to secure the resources. In an embodiment, the data encryption service may be included or implemented in a cloud computing environment and may provide a centralized framework for effectively managing the data encryption requirements of various applications hosted or provided by different customer systems. The disclosed data encryption service may provide monitoring and alert services related to encryption objects managed by the data encryption service and transmit the alerts related to the encryption objects via various communication channels.