Key Master Service Hydration for Secret Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online secret distribution infrastructures are insecure and prone to failure, as they rely on local data stores that are not only unsecure but also vulnerable to failures of dependent components, leading to potential service disruptions when metadata systems or key vaults fail.

Innovation Solution

A highly available and reliable key master service (KMS) system is implemented, which uses multiple KMS systems to hydrate each other for secure secret information distribution, allowing the system to maintain high availability even when external dependencies like metadata storage or key vaults fail, by polling and synchronizing data across instances.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If secret information is stored in local data stores (files or databases), then the system structure is simple, but the security is compromised and the system becomes prone to failure

Engineering Contradiction:
Improvesystem structureVSAvoidsystem availability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces an intermediary key master service that acts as a mediator between clients and the secret information storage. Instead of storing secrets directly in local data stores, the system uses a key master service to manage and distribute encrypted secret information. This intermediary layer provides both security enhancements and reliability through service-level agreements and distributed architecture, resolving the contradiction between simple structure and reliable operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If secret information is stored in local data stores, then the implementation is straightforward, but the security is compromised

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the secret information management function from local data stores and places it in a dedicated key master service. By separating the secret information from general-purpose storage systems, the invention achieves enhanced security through specialized handling, encryption management, and access control mechanisms while maintaining implementation feasibility through standardized service interfaces.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The key master service serves as an intermediary that securely manages secret information without requiring changes to the underlying storage infrastructure. This mediator provides security functions including encryption, key management, and controlled distribution, thereby protecting secret information while maintaining ease of implementation through service abstraction.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If the system relies on external dependencies like metadata storage or key vaults, then the initial setup is simplified, but the system becomes vulnerable to failures of these dependencies

Engineering Contradiction:
Improveinitial setup complexityVSAvoidsystem availability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements beforehand cushioning by establishing service-level agreements and redundancy mechanisms in advance. The key master service is designed with built-in resilience to handle failures of external dependencies such as metadata storage or key vaults. This includes implementing fallback mechanisms, distributed service instances, and pre-configured recovery procedures that cushion against dependency failures before they impact service availability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The system dynamically changes operational parameters based on the availability of external dependencies. When metadata storage or key vaults become unavailable, the key master service adjusts its operation mode, switching to alternative data sources or degraded functionality. This parameter adaptation allows the system to maintain availability despite changes in external dependency status.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11018860B2Highly available and reliable secret distribution infrastructure
Publication Date: 2021.05.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11018860B2 patent drawing
  • US11018860B2 patent drawing
  • US11018860B2 patent drawing

AI summary

The techniques discussed herein relate to providing a highly available and reliable secret distribution infrastructure. In an implementation, a key master service (KMS) system is disclosed. The KMS system includes one or more computer readable storage media having program instructions stored thereon which, when executed by one or more processing systems, direct the one or more processing systems to identify a hydration event and, responsive to the hydration event, determine if other KMS systems are running in a secret distribution infrastructure. The program instructions, when executed by one or more processing systems, further direct the KMS system to hydrate the KMS system with secret information obtained from the one or more of the other KMS systems when the other KMS systems are running in the secret distribution infrastructure.