Network Device Command for Shared Confidential Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing environments face challenges in securely communicating shared confidential data between devices within a network, particularly in storage area networks, where network devices lack access to key managers.

Innovation Solution

A computer program product is provided that enables a receiving network device to obtain and use shared confidential data by building and transmitting a command, such as a control unit port command, from a control program to the network device, allowing it to access and utilize the shared data for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network devices are isolated from key managers for security, then security is improved, but access to shared confidential data becomes unavailable

Engineering Contradiction:
ImprovesecurityVSAvoidaccess to shared confidential data
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a command structure as an intermediary mechanism that allows network devices to access shared confidential data without direct connection to the key manager. The command structure acts as a mediator, transmitting encrypted commands from network devices to the key manager and returning encrypted responses, thereby maintaining security isolation while enabling necessary data access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces direct mechanical access to the key manager with a cryptographic communication mechanism. Instead of network devices directly accessing the key manager's storage or memory, they use encrypted commands transmitted through the command structure, substituting physical access with cryptographic interaction.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If encrypted messages are transmitted between devices, then security is improved, but complexity of key management increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by having network devices generate their own wrapping keys independently. Each network device creates its own wrapping key to encrypt commands sent to the key manager and uses the same key to decrypt responses, eliminating the need for centralized key distribution and reducing key management complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameter of key management from centralized to distributed. Instead of a single centralized key management system, each network device maintains its own wrapping key as a parameter, simplifying the overall system architecture while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250080534A1Command to provide shared confidential data
Publication Date: 2025.03.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US20250080534A1 patent drawing
  • US20250080534A1 patent drawing
  • US20250080534A1 patent drawing

AI summary

A receiving network device of a network obtains a command built to enable a control program of a device coupled to the receiving network device to provide to the receiving network device shared confidential data. The receiving network device obtains the shared confidential data from the command and uses the shared confidential data in performing one or more actions.