Enterprise Disk Encryption Password Management via Intermediary Service
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise computing environments face security challenges with disk encryption key storage and retrieval, as storing keys on a server outside the enterprise control and retrieving them via personal information do not meet high security standards, and existing solutions compromise pre-boot authentication and data integrity.
Innovation Solution
A system and method for enterprise management of full-disk encryption that generates, stores, and manages disk passwords securely within an enterprise computer system, allowing controlled access for forensic analysis and user recovery, while maintaining pre-boot authentication and data integrity by using a client management system and encryption service to create and manage unique, complex passwords.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If disk encryption key is stored on a server outside enterprise control, then user can retrieve key via personal information, but enterprise security protocol is compromised
Solution Approach 1:
The patent introduces an intermediary system (enterprise-controlled key management server) that mediates between the user and the encryption key. This intermediary authenticates users through enterprise-validated methods and controls key access, resolving the contradiction by providing convenient retrieval while maintaining security through enterprise control.
Solution Approach 2:
The system performs preliminary actions by pre-establishing enterprise authentication mechanisms and key management protocols before any key retrieval operation. The enterprise controls the key storage and retrieval process in advance, ensuring security is built into the system architecture rather than added as an afterthought.
2Ease of operation
If telephone-based key retrieval with personal information is implemented, then user access is enabled, but security protocol standards are not met
Solution Approach 1:
The patent replaces the mechanical/manual telephone-based retrieval process with an automated, enterprise-controlled digital key management system. The system uses cryptographic protocols, authentication mechanisms, and secure communication channels to enable key retrieval while maintaining security protocol compliance.
Solution Approach 2:
An enterprise-controlled intermediary system manages the key retrieval process, replacing direct user access to encryption keys. This intermediary validates user identities through enterprise-authorized methods and controls key delivery, ensuring both accessibility and security protocol compliance.
3Reliability
If pre-boot authentication is maintained, then data integrity is protected, but key retrieval complexity increases
Solution Approach 1:
The patent segments the authentication and key retrieval processes into distinct phases: pre-boot authentication phase (for data integrity protection) and post-authentication key retrieval phase (for convenient access). This segmentation allows each phase to optimize for its specific requirements without compromising the other.
Solution Approach 2:
The system performs preliminary authentication actions during the pre-boot phase to establish security context before allowing any data access or key retrieval operations. This preliminary action ensures data integrity is maintained while setting up streamlined retrieval pathways for authorized users.
Data Source
AI summary
A method for deploying a disk encryption password to a client computer includes installing a disk encryption agent on a client computer, where the agent communicates with an enterprise encryption service that encrypts a disk password using a public key generated at the client computer. The encrypted disk password is transmitted to the client computer where it is set as the current disk password. A system to deploy a disk encryption password includes one or more client computers and at least one server having a control processor configured to support operation of an enterprise encryption service. The encryption service is configured to install a disk encryption agent on a client computer and generate an encrypted disk password using a public key generated by the client computer. An enterprise encryption database in communication with the enterprise encryption service stores the disk password.


