Key Broker Allocation for Customer-Controlled UCaaS Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems, such as UCaaS platforms, face challenges in managing and utilizing different encryption keys across various communication channels, leading to broken encryption protocols and security issues when key management servers change, making encrypted content inaccessible or implementing improper security protocols.
Innovation Solution
A key broker server dynamically allocates data encryption keys generated by customer-specific key management servers, ensuring secure encryption and decryption within a UCaaS platform, using a bring-your-own-key framework and envelope encryption to manage customer-controlled encryption keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a centralized key management system is used, then key management is simplified, but system downtime and security issues occur when key management servers change
Solution Approach 1:
The patent segments the centralized key management system into multiple distributed key management servers. Each server manages encryption keys for specific services or user groups independently. When one server undergoes maintenance or failure, other servers continue to provide key management services, ensuring encryption continuity without system-wide downtime.
Solution Approach 2:
The patent introduces a key broker server as an intermediary between service servers and key management servers. The key broker caches encryption keys locally and provides them to service servers upon request. This intermediary layer decouples service servers from direct dependency on key management servers, allowing key management changes without service disruption.
2Reliability
If customer-controlled encryption keys are implemented, then security is improved, but onboarding time increases
Solution Approach 1:
The patent implements preliminary action by pre-provisioning encryption keys and configuring key management servers before customers join the UCaaS platform. When a customer onboards, their keys are already in place and the key broker is configured to retrieve them automatically, eliminating manual key setup time and accelerating the onboarding process while maintaining customer control over their encryption keys.
3Reliability
If multiple encryption keys are managed across services, then security is improved, but device complexity increases
Solution Approach 1:
The key broker server acts as an intermediary that simplifies key management complexity. It maintains a local cache of encryption keys and provides a standardized interface for service servers to retrieve keys. This eliminates the need for service servers to directly manage multiple key management servers, reducing their operational complexity while maintaining secure multi-key management across different services.
Solution Approach 2:
The key broker server provides universal key management functionality across all UCaaS services. It handles key retrieval, caching, and distribution for various services (telephony, messaging, conferencing) through a single unified mechanism. This multi-functional approach consolidates what would otherwise be service-specific key management logic into one universal system, reducing overall complexity.
Data Source
AI summary
Customers of a software platform, such as a unified communications as a service platform, are enabled to control their own encryption keys used to encrypt and decrypt data from various communication services in the software platform. A key broker server is employed to map encryption and decryption requests from servers in the platform to key management servers of customers based on user identifiers. Examples of data encrypted may includes conference recordings, webinar recordings, phone call recordings, voicemails, emails, and calendar tokens.


