Key Broker Allocation for Customer-Controlled UCaaS Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems, such as UCaaS platforms, face challenges in managing and utilizing different encryption keys across various communication channels, leading to broken encryption protocols and security issues when key management servers change, making encrypted content inaccessible or implementing improper security protocols.

Innovation Solution

A key broker server dynamically allocates data encryption keys generated by customer-specific key management servers, ensuring secure encryption and decryption within a UCaaS platform, using a bring-your-own-key framework and envelope encryption to manage customer-controlled encryption keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a centralized key management system is used, then key management is simplified, but system downtime and security issues occur when key management servers change

Engineering Contradiction:
Improvekey management simplicityVSAvoidencryption continuity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized key management system into multiple distributed key management servers. Each server manages encryption keys for specific services or user groups independently. When one server undergoes maintenance or failure, other servers continue to provide key management services, ensuring encryption continuity without system-wide downtime.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key broker server as an intermediary between service servers and key management servers. The key broker caches encryption keys locally and provides them to service servers upon request. This intermediary layer decouples service servers from direct dependency on key management servers, allowing key management changes without service disruption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If customer-controlled encryption keys are implemented, then security is improved, but onboarding time increases

Engineering Contradiction:
Improveencryption securityVSAvoidonboarding time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-provisioning encryption keys and configuring key management servers before customers join the UCaaS platform. When a customer onboards, their keys are already in place and the key broker is configured to retrieve them automatically, eliminating manual key setup time and accelerating the onboarding process while maintaining customer control over their encryption keys.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple encryption keys are managed across services, then security is improved, but device complexity increases

Engineering Contradiction:
Improveencryption securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key broker server acts as an intermediary that simplifies key management complexity. It maintains a local cache of encryption keys and provides a standardized interface for service servers to retrieve keys. This eliminates the need for service servers to directly manage multiple key management servers, reducing their operational complexity while maintaining secure multi-key management across different services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The key broker server provides universal key management functionality across all UCaaS services. It handles key retrieval, caching, and distribution for various services (telephony, messaging, conferencing) through a single unified mechanism. This multi-functional approach consolidates what would otherwise be service-specific key management logic into one universal system, reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12598060B2Distributed encryption key allocation
Publication Date: 2026.04.07 ZOOM COMMUNICATIONS INC
  • US12598060B2 patent drawing
  • US12598060B2 patent drawing
  • US12598060B2 patent drawing

AI summary

Customers of a software platform, such as a unified communications as a service platform, are enabled to control their own encryption keys used to encrypt and decrypt data from various communication services in the software platform. A key broker server is employed to map encryption and decryption requests from servers in the platform to key management servers of customers based on user identifiers. Examples of data encrypted may includes conference recordings, webinar recordings, phone call recordings, voicemails, emails, and calendar tokens.