External Key Management Service for Customer Data Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud service providers face challenges in securely managing access to customer data stored in distributed storage systems, where unauthorized access can occur without proper justification and validation, potentially violating privacy laws and compromising sensitive information.
Innovation Solution
A method and system that involve receiving an access request with a justification, validating the justification, and transmitting it to an external key management service to grant or deny access using a customer-side cryptographic key, ensuring that only authorized access is allowed based on a predefined security policy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If cloud service providers implement traditional access control mechanisms, then data access efficiency is improved, but data security and customer control are compromised
Solution Approach 1:
The patent introduces an external key management service as an intermediary between the cloud service provider and customer data. This service holds customer-side cryptographic keys and controls access to encrypted data, allowing efficient data retrieval while maintaining strong security through customer-controlled key management and justification-based access validation.
2Speed
If cloud service providers store cryptographic keys internally for fast access, then data retrieval speed is improved, but customer control and security are reduced
Solution Approach 1:
The patent extracts cryptographic key management from the cloud service provider's internal systems and places it in an external key management service controlled by the customer. This separation allows the provider to maintain fast data retrieval capabilities while the customer retains full control over key access through security policies and justification validation.
3Reliability
If cloud service providers implement comprehensive access logging and validation, then security compliance is improved, but system complexity and processing time increase
Solution Approach 1:
The patent implements preliminary action by requiring access justifications to be validated against pre-defined security policies before data access is granted. The external key management service maintains pre-approved credentials and policies, enabling automated validation that ensures compliance without adding significant complexity to the access process.
Data Source
AI summary
A method for accessing customer data includes receiving an access request requesting access to customer data stored on a storage abstraction. The access request includes a justification that specifies a purpose/reason for requesting access to the customer data. The method also includes validating the justification, and after validating the justification, transmitting the justification to an external key management service associated with a customer of the customer data. The external key management service is configured to grant or deny access to the customer data based on the justification. The method also includes receiving an approved access token from the external key management service when the external key management service grants access to the customer data and accessing the customer data stored on the storage abstraction using the approved access token received from the external key management service.


