Key Export Techniques for Cryptographic Service Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ensuring the secure access and management of cryptographic keys in complex distributed computer systems, particularly in cloud-based services where service providers need to perform cryptographic operations on behalf of customers while minimizing access to sensitive keys.
Innovation Solution
Implementing an API that allows customers to utilize a cryptography service with limited access by the service provider, using export key tokens and domain keys with different rotation schedules, ensuring that the service provider can only access encrypted keys temporarily and under specific conditions, thereby maintaining key security and flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If service providers host computing resources and perform cryptographic operations on behalf of customers, then service capability and convenience are improved, but security risk and access control complexity worsen
Solution Approach 1:
The patent extracts the cryptographic key material from the service provider's environment and places it in customer-controlled hardware security modules. The service provider only receives encrypted key data and cryptographic operation requests, never the actual keys. This extraction eliminates the security risk of key exposure while preserving the service provider's ability to perform cryptographic operations.
Solution Approach 2:
The patent introduces encrypted key data as an intermediary between the customer's key material and the service provider's cryptographic operations. The encrypted key data acts as a mediator that allows the service provider to access cryptographic functionality without direct access to the actual keys, thus maintaining security while enabling service capability.
2Ease of operation
If service providers maintain access to cryptographic keys for operational flexibility, then operational convenience is improved, but key security and customer control worsen
Solution Approach 1:
The patent extracts full key access from the service provider and relocates it to the customer's hardware security module. The service provider operates with limited access to only encrypted key data, which cannot be used to derive the actual keys. This maintains operational convenience for cryptographic operations while ensuring key security and customer control.
Solution Approach 2:
The patent enables customers to self-manage their cryptographic keys through hardware security modules that they control. The customers can perform key management operations locally without requiring service provider intervention, thus maintaining operational convenience while ensuring that the service provider never has access to the actual keys.
3Productivity
If cryptographic keys are stored in centralized locations for easy management, then management efficiency is improved, but vulnerability to security breaches worsens
Solution Approach 1:
The patent segments the cryptographic key management system into distributed components: customer-controlled hardware security modules that generate and store keys, and service provider systems that perform operations using only encrypted key data. This segmentation eliminates centralized key storage, reducing vulnerability to security breaches while maintaining management efficiency through automated cryptographic operations.
Solution Approach 2:
The patent uses encrypted key data as an intermediary that enables efficient cryptographic operations without requiring centralized key storage. The encrypted key data can be securely transmitted and stored in the service provider's environment, allowing efficient key management operations while the actual keys remain securely distributed in customer hardware security modules.
4Reliability
If service providers rotate domain keys frequently for security, then security is improved, but operational complexity and key management burden worsen
Solution Approach 1:
The patent extracts the burden of key rotation from the service provider and places it in the customer's hardware security module. The service provider only needs to manage encrypted key data, which can be rotated independently without affecting the actual cryptographic keys. This maintains security through frequent rotation while simplifying key management for the service provider.
Solution Approach 2:
The patent enables dynamic key rotation where encrypted key data can be independently rotated and updated without affecting the underlying cryptographic keys stored in customer hardware security modules. This dynamic approach allows frequent security rotations while maintaining operational simplicity, as the service provider only manages the rotatable encrypted wrappers, not the actual keys.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A computer system performs cryptographic operations as a service. The computer system is configured to allow users of the service to maintain control of their respective cryptographic material. The computer system uses inaccessible cryptographic material to encrypt a user's cryptographic material in a token that is then provided to the user. The user is unable to access a plaintext copy of the cryptographic material in the token, but can provide the token back to the service to cause the service to decrypt and use the cryptographic material.