Enterprise Key Agent for Cloud Data Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face security challenges when using cloud-based services due to the lack of enterprise-level controls, leading to risks associated with data security and compliance, particularly in managing encryption keys for sensitive data stored on third-party cloud service providers.
Innovation Solution
An encryption key management system that allows enterprises to maintain and manage their own encryption keys using a network intermediary, which intercepts and encrypts data before it reaches cloud service providers, ensuring that encryption keys never leave the enterprise's premises by using a key agent and hardware or virtual security modules to derive and manage data encryption keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If enterprises use cloud-based services provided by third parties, then access to computing resources and data storage is improved, but data security and control over encryption keys deteriorate
Solution Approach 1:
The patent introduces an on-premises key agent as an intermediary component that mediates between the enterprise's key management system and the cloud service provider. This key agent intercepts data before it leaves the enterprise network, performs encryption using enterprise-controlled keys, and then transmits the encrypted data to the cloud service provider. This intermediary approach allows the enterprise to maintain control over encryption keys while still utilizing cloud-based computing resources and storage services.
2Reliability
If enterprises implement strict enterprise-level controls for data security, then data protection is improved, but ease of using cloud-based services deteriorates
Solution Approach 1:
The patent implements a self-service encryption mechanism where the on-premises key agent automatically intercepts and encrypts data before it is transmitted to cloud service providers. This automated approach eliminates the need for manual encryption operations by enterprise staff, maintaining strong security controls while preserving the ease of use of cloud services. The encryption process occurs transparently in the background without requiring users to change their interaction patterns with cloud services.
3Reliability
If enterprises store encryption keys on-premises to maintain control, then key management security is improved, but ability to encrypt data in cloud services deteriorates
Solution Approach 1:
The patent applies preliminary action by performing encryption of data before it leaves the enterprise network. The on-premises key agent intercepts data at the network boundary and encrypts it using enterprise-controlled keys stored on-premises. This preliminary encryption ensures that keys never leave the enterprise environment while still enabling cloud service providers to store and process the encrypted data. The encryption action is performed in advance, before data transmission to the cloud.
Data Source
AI summary
An encryption key management system and method implements enterprise managed encryption key for an enterprise using encryption for cloud-based services. In some embodiments, the enterprise deploys a key agent on the enterprise data network to distribute encryption key material to the network intermediary on a periodic basis. The network intermediary receives the encryption key material from the enterprise and stores the encryption key material in temporary storage and uses the received encryption key material to derive a data encryption key to perform the encryption of the enterprise's data. In this manner, the enterprise can be provided with the added security assurance of maintaining and managing its own encryption key while using cloud-based data storage services. The encryption key management system and method can be applied to ensure that the enterprise's one or more encryption keys do not leave the enterprise's premises.


