Cryptographic Key Import via Encrypted Token Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers of computing resource service providers face complexity and resource-intensive processes when trying to import their own cryptographic keys for secure data encryption, requiring secure management while ensuring access control and key security.

Innovation Solution

A cryptographic key management service generates an import key token, encrypted with a domain cryptographic key, which customers use to import their cryptographic keys, ensuring only the service can decrypt and manage the keys, with expiration dates for secure access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If customers import their own cryptographic keys, then key security and customer control are improved, but system complexity and resource management burden increase

Engineering Contradiction:
Improvekey securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an import key token as an intermediary mechanism that mediates between customer control and service provider management. The token contains encrypted customer keys that can only be decrypted by the service provider's domain cryptographic key, enabling secure key import without requiring complex manual management procedures. This resolves the contradiction by providing automated secure key management while maintaining customer control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The service provider performs preliminary actions by generating domain cryptographic keys and configuring the key management infrastructure before customers need to import their keys. The import key token is prepared in advance with pre-established encryption relationships, eliminating the need for customers to navigate complex key management procedures themselves. This reduces system complexity from the customer perspective while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If service providers manage cryptographic keys, then access control and security are improved, but customer flexibility and autonomy deteriorate

Engineering Contradiction:
Improveaccess controlVSAvoidcustomer flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent enables customers to perform self-service key import operations using the import key token mechanism. Customers can independently import their own cryptographic keys without requiring service provider intervention for each key operation. The service provider maintains security through domain cryptographic key control, while customers gain flexibility through autonomous key import capability. This resolves the contradiction by distributing appropriate responsibilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The key management system is segmented into distinct functional components: customer-controlled key generation and import initiation, and service provider-controlled key decryption and management. The import key token encapsulates the customer's key material separately from the service provider's domain cryptographic key, allowing each party to exercise control over their respective functions. This segmentation enables both access control and customer flexibility simultaneously.

Inventive Principle:
Principle #1Segmentation

3Reliability

If extensive resource management is implemented for imported keys, then key security is improved, but operational efficiency and ease of use deteriorate

Engineering Contradiction:
Improvekey securityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces manual mechanical key management processes with automated cryptographic operations. Instead of customers manually managing key security through complex procedures, the system uses automated encryption/decryption operations based on the import key token and domain cryptographic key relationships. This substitution maintains high security through cryptographic mechanisms while dramatically improving operational efficiency and ease of use.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11184155B2Cryptographic key management for imported cryptographic keys
Publication Date: 2021.11.23 AMAZON TECH INC
  • US11184155B2 patent drawing
  • US11184155B2 patent drawing
  • US11184155B2 patent drawing

AI summary

A cryptographic key management service receives a request to import a first cryptographic key. In response to the request, the service creates a public cryptographic key and a private cryptographic key. The private cryptographic key is encrypted using a second cryptographic key to create an import key token. The import key token and the public cryptographic key are provided in response to the request. The service receives an encrypted first cryptographic key, which the service decrypts using the private cryptographic key to obtain the first cryptographic key. The service stores the first cryptographic key and enables its use for the performance of cryptographic operations.