Enterprise Key Management for Cloud Data Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in retaining control over sensitive data after exporting it to cloud-based services, as existing security mechanisms do not allow them to manage access or purge data effectively, leading to potential data exposure and lack of control over encryption keys.

Innovation Solution

A cloud-based data analytics and visualization platform is configured to use data encryption keys managed by the enterprise, allowing entities to revoke access and purge data, ensuring they retain control over their imported data by leveraging key management systems and secure protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If enterprises export data to cloud-based services, then data accessibility and processing capability are improved, but control over data access and encryption keys is lost

Engineering Contradiction:
Improvedata processing capabilityVSAvoidcontrol over data access
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent extracts the encryption key management function from the cloud service provider and places it under enterprise control through a key management service (KMS). The enterprise retains its encryption keys separately while the cloud service processes data, ensuring that even if data is exported to the cloud, the enterprise maintains control over access through key management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a key management service (KMS) as an intermediary between the enterprise and the cloud service provider. The KMS acts as a mediator that allows the cloud service to access encrypted data only when the enterprise authorizes through the intermediary, thus maintaining enterprise control while enabling cloud processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud services manage encryption keys, then data security is improved, but enterprise control over data is lost

Engineering Contradiction:
Improvedata securityVSAvoidenterprise control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent inverts the conventional approach by having the enterprise (rather than the cloud service) manage the encryption keys. The cloud service provider handles data storage and processing, but encryption and decryption operations are performed by the enterprise's key management service, reversing the traditional key management model to restore enterprise control.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The enterprise's key management service autonomously manages its own encryption keys without requiring cloud service provider intervention. The KMS independently performs encryption, decryption, and key rotation operations, allowing the enterprise to self-manage security while utilizing cloud infrastructure.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If enterprises retain encryption keys, then control over data is improved, but data accessibility by cloud service is reduced

Engineering Contradiction:
Improveenterprise controlVSAvoiddata accessibility
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The key management service acts as an intermediary that bridges enterprise key control and cloud data accessibility. When the cloud service needs to access encrypted data, it requests decryption from the KMS, which verifies enterprise authorization and provides decrypted data only when authorized, thus maintaining both control and accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The enterprise pre-configures access policies and authorizations in the key management service before data processing occurs. The KMS预先 establishes which cloud service components can access which encrypted data under what conditions, enabling seamless authorized access without real-time enterprise intervention while maintaining control.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If data is encrypted with enterprise-managed keys, then security control is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidkey management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key management service is designed as a universal system that handles multiple functions including encryption, decryption, key generation, key rotation, and access policy management within a single integrated service. This multi-functionality consolidates what could be multiple separate systems into one unified solution, reducing overall complexity while maintaining comprehensive security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11347868B2Systems and methods for securely managing data in distributed systems
Publication Date: 2022.05.31 DOMO
  • US11347868B2 patent drawing
  • US11347868B2 patent drawing
  • US11347868B2 patent drawing

AI summary

A cloud-based platform encrypts data imported from an organization using respective data encryption keys (DEK). The platform prevents decrypted data of the organization, and the DEK(s) used to encrypt such data, from being persistently retained within the platform. Access to the DEK may be controlled by the organization. Accordingly, the organization may retain control over access to its data, after the data has been exported to the platform. The platform may provide a purge control by which the organization can configure the platform the purge any cached DEK and/or unencrypted data pertaining to the organization.