Key Escrow Server for Synchronized Encryption Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption key management systems face synchronization issues between device-level and communication-level management, leading to loose controls and potential breakdowns in communication security, particularly in public key infrastructure and enterprise key management.

Innovation Solution

A client-based service integrates local applications, servers, and infrastructure with an applied key management system, enabling automated key file collection, secure storage, and centralized escrow of encryption keys based on policies, using a Hardware Security Module or key management server for secure storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device-level encryption key management is implemented, then local security control is improved, but synchronization with communication-level management deteriorates

Engineering Contradiction:
Improvelocal security controlVSAvoidsynchronization with communication-level management
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent introduces a key escrow server as an intermediary between device-level key management and communication-level management. The server receives, stores, and manages encryption keys escrowed from multiple devices, enabling centralized control while maintaining device autonomy. This mediator resolves the synchronization conflict by providing a central coordination point without eliminating local key management capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized key management is implemented, then communication security control is improved, but device autonomy and local control deteriorate

Engineering Contradiction:
Improvecommunication security controlVSAvoiddevice autonomy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments key management into two independent but coordinated functions: local key generation and storage on devices, and centralized escrow and management on the server. Each device maintains autonomous control over its local keys while the server provides centralized oversight. This segmentation allows both device autonomy and centralized control to coexist without conflict.

Inventive Principle:
Principle #1Segmentation

3Productivity

If automated key collection and escrow is implemented, then key management efficiency is improved, but system complexity deteriorates

Engineering Contradiction:
Improvekey management efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where devices automatically generate, protect, and escrow their own encryption keys without requiring manual intervention. The key escrow server provides automated registration and storage services. This automation improves efficiency by eliminating manual key management tasks while the standardized protocols keep system complexity manageable.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11924345B2Server-client key escrow for applied key management system and process
Publication Date: 2024.03.05 FORNETIX LLC
  • US11924345B2 patent drawing
  • US11924345B2 patent drawing
  • US11924345B2 patent drawing

AI summary

Embodiments described herein relate to apparatuses and methods for registering and storing a local key associated with a local application of a communication device, including, but not limited to, receiving a request from the communication device to register and store the local key, evaluating the request based on at least one first policy, and sending the request to register and store the local key to a secure key storage.