Gateway Server Encryption Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, there is a security concern regarding the management of cryptographic keys, as customers may generate keys that are not compliant with security standards, leading to vulnerabilities, and relying on cloud providers to generate keys does not ensure customer control or safe storage of decryption keys.

Innovation Solution

A method where a gateway server generates unique encryption keys and sends them to user devices for download and validation, ensuring that the keys are saved locally by the customer, providing control over the encryption and decryption of data stored in the cloud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If customers generate their own encryption keys, then they have control over their data, but the keys may not comply with security standards leading to vulnerabilities

Engineering Contradiction:
Improvecustomer controlVSAvoidsecurity compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a key generation service as an intermediary between the customer and the key generation process. This service automatically generates encryption keys that comply with security standards, eliminating the need for customers to manually create keys while maintaining security compliance. The service acts as a mediator that provides both control and security assurance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cloud providers generate encryption keys, then security standards are met, but customers do not have control or safe storage of decryption keys

Engineering Contradiction:
Improvesecurity complianceVSAvoidcustomer control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the key management process into two distinct parts: key generation (performed by the cloud provider's key generation service to ensure security compliance) and key storage (performed by the customer's local device to ensure control). This segmentation allows both security standards and customer control to coexist by separating these previously conflicting functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the decryption key storage function from the cloud provider's control and places it locally on the customer's device. The encryption keys are generated by the cloud provider but the decryption keys are extracted and stored locally, giving customers direct control over their data access while maintaining security compliance through the cloud provider's generation process.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If encryption keys are stored in the cloud, then data can be recovered, but security and privacy are compromised

Engineering Contradiction:
Improvedata recoverabilityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by storing different types of cryptographic keys in different locations with different security properties. Encryption keys are stored in the cloud for data recoverability, while decryption keys are stored locally on the customer's device for security. This localized differentiation of key storage locations ensures that data can be recovered when needed while maintaining security and privacy.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10270593B2Managing security in a computing environment
Publication Date: 2019.04.23 KYNDRYL INC
  • US10270593B2 patent drawing
  • US10270593B2 patent drawing
  • US10270593B2 patent drawing

AI summary

In response to at least one message received by a processor of a gateway server from a user device wherein each message requests that an encryption key be downloaded to the user device, the processor generates at least one unique encryption key for each message and sends the at least one generated encryption key to the user device, but does not store any of the generated encryption keys in the cloud. For each encryption key having been sent to the user device, the processor receives each encryption key returned from the user device. For each encryption key received from the user device, the processor stores each received encryption key in the cloud.