Key Broker Architecture for Customer-Controlled UCaaS Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing UCaaS platforms face challenges in managing and maintaining encryption keys across multiple communication channels, leading to disruptions and security vulnerabilities due to changes in key management servers, which can render encrypted data inaccessible or implement improper security protocols.

Innovation Solution

A key broker server dynamically allocates customer-controlled data encryption keys across various communication services within the UCaaS platform, using a bring-your-own-key framework and envelope encryption to ensure secure storage and access, while maintaining separate trust boundaries for customers and agents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single key management server is used to manage encryption keys, then key management is simplified, but the system becomes vulnerable to disruptions and security issues when the server changes

Engineering Contradiction:
Improvekey management structureVSAvoidaccess to encrypted data
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the key management function by separating the key broker server from customer-controlled key management servers. The key broker server handles key allocation and distribution, while customer-controlled servers generate and secure the actual encryption keys. This segmentation allows the system to maintain simplified key management operations through the broker while ensuring reliability through customer control and redundancy at the key generation level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key broker server acts as an intermediary between communication services and key management infrastructure. It receives key generation requests, allocates encryption keys, and manages key distribution without requiring direct access to customer-controlled key management servers. This intermediary role simplifies the interface for services while maintaining secure, reliable key management through the customer-controlled backend.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If encryption keys are centrally managed, then key distribution is efficient, but customer control and security are reduced

Engineering Contradiction:
Improvekey allocation efficiencyVSAvoidcustomer control over keys
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system segments key management responsibilities: the key broker server handles efficient key allocation and distribution, while customer-controlled key management servers maintain security and adaptability. This division allows centralized efficiency in key logistics while preserving decentralized customer control over key generation and protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key broker server serves as an intermediary that enables efficient key distribution without compromising customer control. It manages the logistical aspects of key allocation while customer-controlled servers retain authority over key generation and security policies, combining the benefits of centralized efficiency with decentralized autonomy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If key management servers are changed to improve security or maintenance, then system security can be enhanced, but encrypted data becomes inaccessible

Engineering Contradiction:
Improvesecurity protocol complianceVSAvoidsystem downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The key broker server acts as a stable intermediary that maintains continuous key allocation functionality even when customer-controlled key management servers are changed. Services continue to access keys through the broker, which manages transitions between different key management infrastructure without causing service disruption or data inaccessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary key allocation and distribution through the key broker before changes to key management servers occur. By pre-establishing key access pathways and maintaining broker-mediated key distribution, the system prepares for infrastructure changes in advance, minimizing downtime and ensuring continuous access to encrypted data during transitions.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If multiple key management servers are used for redundancy, then system reliability improves, but key management complexity increases

Engineering Contradiction:
Improveavailability of encryption keysVSAvoidkey management infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key broker server serves as a unifying intermediary that simplifies access to multiple key management servers. Services interact with a single broker interface, which handles complexity of managing multiple redundant key management servers in the background. This maintains high availability through redundancy while presenting a simple, unified interface to services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The key broker server provides universal access to encryption keys regardless of which customer-controlled server generates them. It implements a unified interface and allocation mechanism that works with multiple key management servers, allowing redundancy without requiring services to manage each server individually. The broker handles diverse key sources through a single multi-functional interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260031983A1Distributed Management Of Encryption
Publication Date: 2026.01.29 ZOOM COMMUNICATIONS INC
  • US20260031983A1 patent drawing
  • US20260031983A1 patent drawing
  • US20260031983A1 patent drawing

AI summary

Customers of a software platform, such as a unified communications as a service platform, are enabled to control their own encryption keys used to encrypt and decrypt data from various communication services in the software platform. A key broker server is employed to map encryption and decryption requests from servers in the platform to key management servers of customers based on user identifiers. Examples of data encrypted may include conference recordings, webinar recordings, phone call recordings, voicemails, emails, and calendar tokens.