Hybrid Authorization Key Rotation for Four-Key Access Continuity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In hybrid software deployment environments, the management of shared authorization keys is challenging due to the need for frequent rotation while adhering to security constraints and key availability limits, leading to conflicts between key rotation frequency and the number of active keys.

Innovation Solution

A key rotation mechanism that creates new access keys for both cloud and on-premise components periodically, ensuring a maximum of 4 keys are active at a time, with a specified validity period, allowing seamless access during key updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If key rotation is performed frequently to maintain security, then security level is improved, but the number of active keys exceeds system limits

Engineering Contradiction:
Improvesecurity levelVSAvoidnumber of active keys
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the key lifecycle into distinct phases: creation, activation, rotation, and deletion. By dividing the key management process into manageable segments with specific timing, the system can rotate keys frequently without accumulating excessive active keys, thus resolving the contradiction between security (frequent rotation) and key quantity limits.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by creating new keys before deleting old ones, and by pre-scheduling key rotations. This ensures that key availability is maintained throughout the rotation process, preventing security gaps while controlling the number of concurrent active keys through advance planning.

Inventive Principle:
Principle #10Preliminary action

2Quantity of substance

If key rotation period is extended to reduce key quantity, then number of active keys is reduced, but security effectiveness deteriorates

Engineering Contradiction:
Improvenumber of active keysVSAvoidsecurity effectiveness
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent implements periodic key rotation with fixed intervals, ensuring that keys are rotated regularly to maintain security effectiveness. The periodic nature of the rotation ensures that no key remains active indefinitely, balancing security requirements with key quantity management by systematically limiting the rotation frequency.

Inventive Principle:
Principle #19Periodic action

3Ease of operation

If manual key management is used to control key rotation, then operational control is improved, but system complexity and error risk increase

Engineering Contradiction:
Improveoperational controlVSAvoidkey management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service key management where the system automatically creates, rotates, and deletes keys according to predefined policies without requiring manual intervention. This automation reduces operational complexity and human error while maintaining control through systematic, rule-based key lifecycle management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms that monitor key usage, rotation status, and system state to dynamically adjust key management operations. This feedback loop ensures that automated key rotation responds to actual system conditions, maintaining security and operational control while adapting to changing requirements without increasing complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250252200A1Management of shared authorization keys in a hybrid software deployment
Publication Date: 2025.08.07 SAP SE
  • US20250252200A1 patent drawing
  • US20250252200A1 patent drawing
  • US20250252200A1 patent drawing

AI summary

In an example embodiment, a solution is provided that performs the rotation of access keys of cloud components that are shared in on-premise software components (such as in a hybrid deployment environment) such that a minimal number of keys are needed. The solution also provides for having a specified validity of the access key, so that the hybrid or on-premise components can retain access to the software components while the new access keys are being generated.