External Key Management Service for Customer Data Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud service providers face challenges in securely managing access to customer data stored in distributed storage systems, where unauthorized access can occur without proper justification and validation, potentially violating privacy laws and compromising sensitive information.

Innovation Solution

A method and system that involve receiving an access request with a justification, validating the justification, and transmitting it to an external key management service to grant or deny access using a customer-side cryptographic key, ensuring that only authorized access is allowed based on a predefined security policy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If cloud service providers implement traditional access control mechanisms, then data access efficiency is improved, but data security and customer control are compromised

Engineering Contradiction:
Improvedata access efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an external key management service as an intermediary between the cloud service provider and customer data. This service holds customer-side cryptographic keys and controls access to encrypted data, allowing efficient data retrieval while maintaining strong security through customer-controlled key management and justification-based access validation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If cloud service providers store cryptographic keys internally for fast access, then data retrieval speed is improved, but customer control and security are reduced

Engineering Contradiction:
Improvedata retrieval speedVSAvoidcustomer control
Core Design Contradiction:
SpeedVSEase of operation

Solution Approach 1:

The patent extracts cryptographic key management from the cloud service provider's internal systems and places it in an external key management service controlled by the customer. This separation allows the provider to maintain fast data retrieval capabilities while the customer retains full control over key access through security policies and justification validation.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If cloud service providers implement comprehensive access logging and validation, then security compliance is improved, but system complexity and processing time increase

Engineering Contradiction:
Improvesecurity complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by requiring access justifications to be validated against pre-defined security policies before data access is granted. The external key management service maintains pre-approved credentials and policies, enabling automated validation that ensures compliance without adding significant complexity to the access process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11924344B2Access sovereignty
Publication Date: 2024.03.05 GOOGLE LLC
  • US11924344B2 patent drawing
  • US11924344B2 patent drawing
  • US11924344B2 patent drawing

AI summary

A method for accessing customer data includes receiving an access request requesting access to customer data stored on a storage abstraction. The access request includes a justification that specifies a purpose/reason for requesting access to the customer data. The method also includes validating the justification, and after validating the justification, transmitting the justification to an external key management service associated with a customer of the customer data. The external key management service is configured to grant or deny access to the customer data based on the justification. The method also includes receiving an approved access token from the external key management service when the external key management service grants access to the customer data and accessing the customer data stored on the storage abstraction using the approved access token received from the external key management service.