Cryptographic Key Import via Encrypted Token Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Customers of computing resource service providers face complexity and resource-intensive processes when trying to import their own cryptographic keys for secure data encryption, requiring secure management while ensuring access control and key security.
Innovation Solution
A cryptographic key management service generates an import key token, encrypted with a domain cryptographic key, which customers use to import their cryptographic keys, ensuring only the service can decrypt and manage the keys, with expiration dates for secure access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If customers import their own cryptographic keys, then key security and customer control are improved, but system complexity and resource management burden increase
Solution Approach 1:
The patent introduces an import key token as an intermediary mechanism that mediates between customer control and service provider management. The token contains encrypted customer keys that can only be decrypted by the service provider's domain cryptographic key, enabling secure key import without requiring complex manual management procedures. This resolves the contradiction by providing automated secure key management while maintaining customer control.
Solution Approach 2:
The service provider performs preliminary actions by generating domain cryptographic keys and configuring the key management infrastructure before customers need to import their keys. The import key token is prepared in advance with pre-established encryption relationships, eliminating the need for customers to navigate complex key management procedures themselves. This reduces system complexity from the customer perspective while maintaining security.
2Reliability
If service providers manage cryptographic keys, then access control and security are improved, but customer flexibility and autonomy deteriorate
Solution Approach 1:
The patent enables customers to perform self-service key import operations using the import key token mechanism. Customers can independently import their own cryptographic keys without requiring service provider intervention for each key operation. The service provider maintains security through domain cryptographic key control, while customers gain flexibility through autonomous key import capability. This resolves the contradiction by distributing appropriate responsibilities.
Solution Approach 2:
The key management system is segmented into distinct functional components: customer-controlled key generation and import initiation, and service provider-controlled key decryption and management. The import key token encapsulates the customer's key material separately from the service provider's domain cryptographic key, allowing each party to exercise control over their respective functions. This segmentation enables both access control and customer flexibility simultaneously.
3Reliability
If extensive resource management is implemented for imported keys, then key security is improved, but operational efficiency and ease of use deteriorate
Solution Approach 1:
The patent replaces manual mechanical key management processes with automated cryptographic operations. Instead of customers manually managing key security through complex procedures, the system uses automated encryption/decryption operations based on the import key token and domain cryptographic key relationships. This substitution maintains high security through cryptographic mechanisms while dramatically improving operational efficiency and ease of use.
Data Source
AI summary
A cryptographic key management service receives a request to import a first cryptographic key. In response to the request, the service creates a public cryptographic key and a private cryptographic key. The private cryptographic key is encrypted using a second cryptographic key to create an import key token. The import key token and the public cryptographic key are provided in response to the request. The service receives an encrypted first cryptographic key, which the service decrypts using the private cryptographic key to obtain the first cryptographic key. The service stores the first cryptographic key and enables its use for the performance of cryptographic operations.


