Enterprise Key Arbitration for Cloud File Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in maintaining centralized decryption capabilities for encrypted files across various devices and cloud services, especially when users leave or devices are lost/stolen, and need to ensure that encryption keys remain secure and inaccessible to cloud service providers.

Innovation Solution

A method involving double encryption of file entity keys and signed access metadata, where a third computerized system determines access entitlement and facilitates decryption only if authorized, ensuring that encryption keys are kept invisible to the cloud service provider and can be managed by an additional company-hosted server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a cloud service provider stores and manages encryption keys for enterprise files, then file access and sharing becomes convenient and centralized, but the encryption keys become accessible to the cloud service provider and potentially vulnerable to unauthorized access or data breaches

Engineering Contradiction:
Improvefile access and sharingVSAvoidkey exposure to cloud provider
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the encryption key management function from the cloud service provider by introducing a separate key arbitration facility (enterprise-controlled system) that exclusively manages encryption keys. The cloud service provider only stores encrypted files and cannot access decryption keys, thereby eliminating key exposure risk while maintaining centralized access control through the enterprise's own system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an enterprise-controlled key arbitration facility as an intermediary between the cloud service provider and enterprise users. This mediator holds the encryption keys and controls all decryption operations, allowing the cloud provider to offer convenient file access without having access to sensitive key material.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If an enterprise uses a third-party encryption service, then key management becomes simplified, but the enterprise loses centralized decryption capability and control over its own data

Engineering Contradiction:
Improvekey management complexityVSAvoidcentralized decryption capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent merges key management with the enterprise's existing infrastructure by implementing the key arbitration facility within the enterprise's controlled environment. This combines the benefits of centralized key management with maintained enterprise control, allowing the enterprise to decrypt files whenever needed while keeping the system integrated with their security policies.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The enterprise-controlled key arbitration facility serves multiple functions: it manages encryption keys, enforces access control policies, enables centralized decryption, and provides audit capabilities. This multi-functional system replaces the need for external encryption services while maintaining simplified key management through a single enterprise-owned component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If encryption keys are stored on user devices for local decryption, then user autonomy and speed are improved, but centralized control and emergency decryption capability are lost when users leave or devices are compromised

Engineering Contradiction:
Improvedecryption speedVSAvoidcentralized control
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent adds a new dimension to key storage by implementing a hierarchical key structure where encryption keys are stored in multiple locations: encrypted on user devices for fast local access, and securely archived in the enterprise-controlled key arbitration facility. This multi-dimensional storage enables both rapid decryption when authorized and centralized recovery when needed, resolving the speed-control tradeoff.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10083307B2Distributed encryption and access control scheme in a cloud environment
Publication Date: 2018.09.25 BARRACUDA NETWORKS INC
  • US10083307B2 patent drawing
  • US10083307B2 patent drawing
  • US10083307B2 patent drawing

AI summary

An approach is proposed that contemplates systems, methods, and computer-readable storage mediums to support receiving, from a computerized system, a first encrypted file entity key and signed access metadata, wherein the first encrypted file entity key is created by encrypting a file entity key using a first encryption key, the signed access metadata is signed by the file entity key and the encrypted file entity is created by encrypting a file entity using the file entity key. The approach then determines whether to facilitate the decryption of the encrypted file entity by the computerized system and sends a second encrypted file entity key to the computerized system if it is determined to facilitate the decryption. The approach prevents the computerized system to decrypt the encrypted file entity if it is determined not to facilitate the decryption of the encrypted file entity by the computerized system.