Federated Key Management with Tenant-Isolated Key Stores

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing distributed computing environments lack robust security measures for managing cryptographic keys, leading to potential unauthorized access and data breaches, especially in multi-tenant systems where keys are shared among various entities.

Innovation Solution

Implementing a cryptography service that manages and enforces policies on cryptographic keys, using secure key management techniques, including automatic rotation, enforced access controls, and federated key management to prevent unauthorized use and ensure secure data operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cryptographic keys are shared among multiple entities in distributed computing environments, then key accessibility and operational flexibility are improved, but security risks and unauthorized access potential increase

Engineering Contradiction:
Improvekey accessibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments key management by creating separate key stores for different tenants and implementing granular access control lists (ACLs) that divide key access permissions among multiple entities. Each tenant has isolated key storage with controlled access paths, preventing unauthorized cross-tenant access while maintaining operational flexibility within each tenant's key space.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary key management service that mediates all key access requests between entities and cryptographic operations. This service enforces access control policies, audits key usage, and manages key rotation without exposing raw keys to end entities, thereby maintaining security while enabling broad key accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If key rotation is implemented to enhance security, then unauthorized access prevention is improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements automated key rotation where the key management service autonomously generates new keys, updates access control lists, and rotates encryption keys without manual intervention. The system self-manages the complexity of key rotation scheduling, key generation, and distribution, reducing operational overhead while maintaining enhanced security through regular key rotation.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If federated key management is implemented across multiple organizations, then collaboration and data sharing are improved, but control over cryptographic assets and security policy enforcement become more difficult

Engineering Contradiction:
Improvecollaboration capabilityVSAvoidkey control management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal key management framework that handles both internal and federated key operations through a common interface and policy enforcement mechanism. The system manages local tenant keys and federated shared keys using the same access control model and rotation protocols, enabling multi-organization collaboration while maintaining centralized policy control and simplified operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3661121B1Federated key management
Publication Date: 2025.10.15 AMAZON TECH INC
  • EP3661121B1 patent drawingFigure 1
  • EP3661121B1 patent drawingFigure 2
  • EP3661121B1 patent drawingFigure 3

AI summary

A system uses information submitted in connection with a request to determine if and how to process the request. The information may be electronically signed by a requestor using a key such that the system processing the request can verify that the requestor has the key and that the information is authentic. The information may include information that identifies a holder of a key needed for processing the request, where the holder of the key can be the system or another, possibly third party, system. Requests to decrypt data may be processed to ensure that a certain amount of time passes before access to the decrypted data is provided, thereby providing an opportunity to cancel such requests and/or otherwise mitigate potential security breaches.