Enterprise Disk Encryption Password Management via Intermediary Service

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise computing environments face security challenges with disk encryption key storage and retrieval, as storing keys on a server outside the enterprise control and retrieving them via personal information do not meet high security standards, and existing solutions compromise pre-boot authentication and data integrity.

Innovation Solution

A system and method for enterprise management of full-disk encryption that generates, stores, and manages disk passwords securely within an enterprise computer system, allowing controlled access for forensic analysis and user recovery, while maintaining pre-boot authentication and data integrity by using a client management system and encryption service to create and manage unique, complex passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If disk encryption key is stored on a server outside enterprise control, then user can retrieve key via personal information, but enterprise security protocol is compromised

Engineering Contradiction:
Improvekey retrieval convenienceVSAvoidenterprise security protocol
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary system (enterprise-controlled key management server) that mediates between the user and the encryption key. This intermediary authenticates users through enterprise-validated methods and controls key access, resolving the contradiction by providing convenient retrieval while maintaining security through enterprise control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-establishing enterprise authentication mechanisms and key management protocols before any key retrieval operation. The enterprise controls the key storage and retrieval process in advance, ensuring security is built into the system architecture rather than added as an afterthought.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If telephone-based key retrieval with personal information is implemented, then user access is enabled, but security protocol standards are not met

Engineering Contradiction:
Improveuser access capabilityVSAvoidsecurity protocol compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical/manual telephone-based retrieval process with an automated, enterprise-controlled digital key management system. The system uses cryptographic protocols, authentication mechanisms, and secure communication channels to enable key retrieval while maintaining security protocol compliance.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

An enterprise-controlled intermediary system manages the key retrieval process, replacing direct user access to encryption keys. This intermediary validates user identities through enterprise-authorized methods and controls key delivery, ensuring both accessibility and security protocol compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If pre-boot authentication is maintained, then data integrity is protected, but key retrieval complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidkey retrieval process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication and key retrieval processes into distinct phases: pre-boot authentication phase (for data integrity protection) and post-authentication key retrieval phase (for convenient access). This segmentation allows each phase to optimize for its specific requirements without compromising the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication actions during the pre-boot phase to establish security context before allowing any data access or key retrieval operations. This preliminary action ensures data integrity is maintained while setting up streamlined retrieval pathways for authorized users.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8732456B2Enterprise environment disk encryption
Publication Date: 2014.05.20 BLUE RIDGE INNOVATIONS LLC
  • US8732456B2 patent drawing
  • US8732456B2 patent drawing
  • US8732456B2 patent drawing

AI summary

A method for deploying a disk encryption password to a client computer includes installing a disk encryption agent on a client computer, where the agent communicates with an enterprise encryption service that encrypts a disk password using a public key generated at the client computer. The encrypted disk password is transmitted to the client computer where it is set as the current disk password. A system to deploy a disk encryption password includes one or more client computers and at least one server having a control processor configured to support operation of an enterprise encryption service. The encryption service is configured to install a disk encryption agent on a client computer and generate an encrypted disk password using a public key generated by the client computer. An enterprise encryption database in communication with the enterprise encryption service stores the disk password.