Key Metadata Integration in Encrypted Storage Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key management systems lack the ability to manage encrypted storage resources based on metadata associated with cryptographic keys, leading to inefficiencies in administrative tasks and potential database synchronization issues.

Innovation Solution

A key-metadata based management system where per-key metadata is stored alongside cryptographic keys in a key management server, allowing for a consolidated view and administrative tasks to be performed without accessing individual hosts or nodes, and eliminating the need for a separate metadata database.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a separate metadata database is used to store key-metadata, then administrative tasks can be performed, but database desynchronization and security risks occur

Engineering Contradiction:
Improveadministrative task executionVSAvoiddatabase synchronization
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges the metadata storage directly into the key management server's existing database structure, eliminating the separate metadata database. Key-metadata is stored as structured data within the same database that stores cryptographic keys, ensuring automatic synchronization and eliminating the reliability issues caused by separate databases.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The key management server's database is enhanced to serve multiple functions: storing cryptographic keys, storing key-metadata, and providing administrative interfaces. This multi-functional approach eliminates the need for separate specialized databases while maintaining all necessary capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If per-key metadata is stored alongside cryptographic keys in the key management server, then centralized management and database synchronization are improved, but system complexity increases

Engineering Contradiction:
Improvedatabase synchronizationVSAvoidkey management server structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments metadata into discrete key-metadata records with specific attributes (key ID, storage resource identifiers, administrative information) that can be independently managed and queried. This segmentation allows the system to handle complex metadata requirements through structured, modular data organization rather than increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

3Productivity

If a consolidated view of encrypted storage resources is implemented through the key management server, then administrative efficiency is improved, but access control and security management become more complex

Engineering Contradiction:
Improveadministrative efficiencyVSAvoidaccess control structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The key management server acts as an intermediary between administrators and encrypted storage resources. It provides a consolidated view and centralized control interface while maintaining security through authenticated access to the database. The server mediates all administrative operations, simplifying the interface for administrators while maintaining robust security controls internally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11677553B2Managing encrypted storage based on key-metadata
Publication Date: 2023.06.13 TPK INVESTMENTS LLC
  • US11677553B2 patent drawing
  • US11677553B2 patent drawing
  • US11677553B2 patent drawing

AI summary

Techniques are disclosed for managing encrypted storage resources based on key-metadata. The per-key key-metadata is stored in a key management system/server (KMS) along with respective cryptographic keys. The cryptographic keys in the KMS may be data keys or wrapping keys for the data keys. The management of the storage resources is provided via a central console which is a user interface of a console server in authenticated communication with the KMS. The key-metadata associates cryptographic keys to their respective encrypted storage resources. This association is used by the console server to drive the console. The console allows an admin to view/list all encrypted storage resources and related cryptographic objects including keys and digital certificates, as well as to perform various administrative/management functions on them.