Key Metadata Integration in Encrypted Storage Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing key management systems lack the ability to manage encrypted storage resources based on metadata associated with cryptographic keys, leading to inefficiencies in administrative tasks and potential database synchronization issues.
Innovation Solution
A key-metadata based management system where per-key metadata is stored alongside cryptographic keys in a key management server, allowing for a consolidated view and administrative tasks to be performed without accessing individual hosts or nodes, and eliminating the need for a separate metadata database.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a separate metadata database is used to store key-metadata, then administrative tasks can be performed, but database desynchronization and security risks occur
Solution Approach 1:
The patent merges the metadata storage directly into the key management server's existing database structure, eliminating the separate metadata database. Key-metadata is stored as structured data within the same database that stores cryptographic keys, ensuring automatic synchronization and eliminating the reliability issues caused by separate databases.
Solution Approach 2:
The key management server's database is enhanced to serve multiple functions: storing cryptographic keys, storing key-metadata, and providing administrative interfaces. This multi-functional approach eliminates the need for separate specialized databases while maintaining all necessary capabilities.
2Reliability
If per-key metadata is stored alongside cryptographic keys in the key management server, then centralized management and database synchronization are improved, but system complexity increases
Solution Approach 1:
The patent segments metadata into discrete key-metadata records with specific attributes (key ID, storage resource identifiers, administrative information) that can be independently managed and queried. This segmentation allows the system to handle complex metadata requirements through structured, modular data organization rather than increasing overall system complexity.
3Productivity
If a consolidated view of encrypted storage resources is implemented through the key management server, then administrative efficiency is improved, but access control and security management become more complex
Solution Approach 1:
The key management server acts as an intermediary between administrators and encrypted storage resources. It provides a consolidated view and centralized control interface while maintaining security through authenticated access to the database. The server mediates all administrative operations, simplifying the interface for administrators while maintaining robust security controls internally.
Data Source
AI summary
Techniques are disclosed for managing encrypted storage resources based on key-metadata. The per-key key-metadata is stored in a key management system/server (KMS) along with respective cryptographic keys. The cryptographic keys in the KMS may be data keys or wrapping keys for the data keys. The management of the storage resources is provided via a central console which is a user interface of a console server in authenticated communication with the KMS. The key-metadata associates cryptographic keys to their respective encrypted storage resources. This association is used by the console server to drive the console. The console allows an admin to view/list all encrypted storage resources and related cryptographic objects including keys and digital certificates, as well as to perform various administrative/management functions on them.


