Multi-Region Encryption Redundancy for Cloud Data Availability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based encryption systems face challenges in ensuring redundancy and fault tolerance for cryptographic processing systems across multiple regions, which can lead to data unavailability in case of failures within a single region.

Innovation Solution

Implementing a method where sensitive information is encrypted using key encryption keys generated by cryptographic processing systems in multiple regions, allowing for decryption by alternative systems if the primary system fails, with data stored in secure databases and volatile memory, and utilizing region redundancy to maintain data availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is encrypted using a single cryptographic processing system in one region, then encryption/decryption operations are simple and fast, but data becomes unavailable if that system fails

Engineering Contradiction:
Improvedata availabilityVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the encryption system into multiple independent cryptographic processing systems distributed across different geographic regions. Each region maintains its own encryption/decryption capability, so that if one region fails, data can still be accessed through other regions. This segmentation directly resolves the contradiction by trading centralized simplicity for distributed reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-configuring multiple encryption keys and establishing encryption relationships between regions before any failure occurs. When a primary cryptographic processing system fails, the system can immediately switch to using alternative keys from other regions without requiring complex real-time decision-making or reconfiguration, thus maintaining data availability while managing complexity through advance preparation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple cryptographic processing systems are deployed across regions, then fault tolerance and redundancy are improved, but system complexity and management difficulty increase

Engineering Contradiction:
Improvefault toleranceVSAvoidsystem management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements feedback mechanisms that automatically monitor the status of cryptographic processing systems across regions and dynamically adjust key selection and data routing decisions. This feedback system manages the complexity of multi-region operations by providing real-time visibility and automated control, reducing manual management burden while maintaining fault tolerance.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system employs self-service capabilities where cryptographic processing systems automatically select appropriate encryption keys and routes based on the operational status of various regions. This self-service approach reduces manual intervention requirements and simplifies operations despite the underlying complexity of having multiple distributed systems, as the system autonomously handles key management and failover decisions.

Inventive Principle:
Principle #25Self-service

3Reliability

If data is encrypted with multiple keys from different regions, then redundancy is increased, but decryption time and processing overhead increase

Engineering Contradiction:
ImproveredundancyVSAvoiddecryption time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing encryption key relationships and determining optimal key selection strategies before decryption is needed. When data needs to be decrypted, the system can immediately select the appropriate key from the pre-configured set without performing complex real-time analysis, thus maintaining redundancy benefits while minimizing decryption time through advance preparation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic key selection where the system adapts its decryption approach based on real-time conditions such as which regions are operational and which keys are currently accessible. This dynamic behavior allows the system to use the fastest available decryption path while maintaining redundancy, selecting from multiple pre-configured keys based on current system state rather than always using a fixed key set.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11539512B2Systems and methods for multi-region encryption/decryption redundancy
Publication Date: 2022.12.27 STRIPE INC
  • US11539512B2 patent drawing
  • US11539512B2 patent drawing
  • US11539512B2 patent drawing

AI summary

Methods and systems for encrypting and decrypting data comprising sending sensitive information to a first cryptographic processing system in a first cloud region for encryption with a first key encryption key generated by and stored by the first cryptographic processing system. The first encrypted sensitive information received from the first cryptographic processing system is stored in a first database. The sensitive information is also sent to a second cryptographic processing system in a second cloud region different from the first cloud region for encryption with a second key encryption key generated by and stored by the second cryptographic processing system. The second encrypted sensitive information received from the second cryptographic processing system is stored in a second database. If the first encrypted sensitive information cannot be decrypted by the first cryptographic processing system, the second encrypted sensitive information is sent to the second cryptographic processing system.