Key Broker Architecture for Customer-Controlled UCaaS Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing UCaaS platforms face challenges in managing and maintaining encryption keys across multiple communication channels, leading to disruptions and security vulnerabilities due to changes in key management servers, which can render encrypted data inaccessible or implement improper security protocols.
Innovation Solution
A key broker server dynamically allocates customer-controlled data encryption keys across various communication services within the UCaaS platform, using a bring-your-own-key framework and envelope encryption to ensure secure storage and access, while maintaining separate trust boundaries for customers and agents.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single key management server is used to manage encryption keys, then key management is simplified, but the system becomes vulnerable to disruptions and security issues when the server changes
Solution Approach 1:
The patent segments the key management function by separating the key broker server from customer-controlled key management servers. The key broker server handles key allocation and distribution, while customer-controlled servers generate and secure the actual encryption keys. This segmentation allows the system to maintain simplified key management operations through the broker while ensuring reliability through customer control and redundancy at the key generation level.
Solution Approach 2:
The key broker server acts as an intermediary between communication services and key management infrastructure. It receives key generation requests, allocates encryption keys, and manages key distribution without requiring direct access to customer-controlled key management servers. This intermediary role simplifies the interface for services while maintaining secure, reliable key management through the customer-controlled backend.
2Productivity
If encryption keys are centrally managed, then key distribution is efficient, but customer control and security are reduced
Solution Approach 1:
The system segments key management responsibilities: the key broker server handles efficient key allocation and distribution, while customer-controlled key management servers maintain security and adaptability. This division allows centralized efficiency in key logistics while preserving decentralized customer control over key generation and protection.
Solution Approach 2:
The key broker server serves as an intermediary that enables efficient key distribution without compromising customer control. It manages the logistical aspects of key allocation while customer-controlled servers retain authority over key generation and security policies, combining the benefits of centralized efficiency with decentralized autonomy.
3Reliability
If key management servers are changed to improve security or maintenance, then system security can be enhanced, but encrypted data becomes inaccessible
Solution Approach 1:
The key broker server acts as a stable intermediary that maintains continuous key allocation functionality even when customer-controlled key management servers are changed. Services continue to access keys through the broker, which manages transitions between different key management infrastructure without causing service disruption or data inaccessibility.
Solution Approach 2:
The system performs preliminary key allocation and distribution through the key broker before changes to key management servers occur. By pre-establishing key access pathways and maintaining broker-mediated key distribution, the system prepares for infrastructure changes in advance, minimizing downtime and ensuring continuous access to encrypted data during transitions.
4Reliability
If multiple key management servers are used for redundancy, then system reliability improves, but key management complexity increases
Solution Approach 1:
The key broker server serves as a unifying intermediary that simplifies access to multiple key management servers. Services interact with a single broker interface, which handles complexity of managing multiple redundant key management servers in the background. This maintains high availability through redundancy while presenting a simple, unified interface to services.
Solution Approach 2:
The key broker server provides universal access to encryption keys regardless of which customer-controlled server generates them. It implements a unified interface and allocation mechanism that works with multiple key management servers, allowing redundancy without requiring services to manage each server individually. The broker handles diverse key sources through a single multi-functional interface.
Data Source
AI summary
Customers of a software platform, such as a unified communications as a service platform, are enabled to control their own encryption keys used to encrypt and decrypt data from various communication services in the software platform. A key broker server is employed to map encryption and decryption requests from servers in the platform to key management servers of customers based on user identifiers. Examples of data encrypted may include conference recordings, webinar recordings, phone call recordings, voicemails, emails, and calendar tokens.


