Network Device Command for Shared Confidential Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing environments face challenges in securely communicating shared confidential data between devices within a network, particularly in storage area networks, where network devices lack access to key managers.
Innovation Solution
A computer program product is provided that enables a receiving network device to obtain and use shared confidential data by building and transmitting a command, such as a control unit port command, from a control program to the network device, allowing it to access and utilize the shared data for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network devices are isolated from key managers for security, then security is improved, but access to shared confidential data becomes unavailable
Solution Approach 1:
The patent introduces a command structure as an intermediary mechanism that allows network devices to access shared confidential data without direct connection to the key manager. The command structure acts as a mediator, transmitting encrypted commands from network devices to the key manager and returning encrypted responses, thereby maintaining security isolation while enabling necessary data access.
Solution Approach 2:
The patent replaces direct mechanical access to the key manager with a cryptographic communication mechanism. Instead of network devices directly accessing the key manager's storage or memory, they use encrypted commands transmitted through the command structure, substituting physical access with cryptographic interaction.
2Reliability
If encrypted messages are transmitted between devices, then security is improved, but complexity of key management increases
Solution Approach 1:
The patent implements self-service by having network devices generate their own wrapping keys independently. Each network device creates its own wrapping key to encrypt commands sent to the key manager and uses the same key to decrypt responses, eliminating the need for centralized key distribution and reducing key management complexity.
Solution Approach 2:
The patent changes the parameter of key management from centralized to distributed. Instead of a single centralized key management system, each network device maintains its own wrapping key as a parameter, simplifying the overall system architecture while maintaining security.
Data Source
AI summary
A receiving network device of a network obtains a command built to enable a control program of a device coupled to the receiving network device to provide to the receiving network device shared confidential data. The receiving network device obtains the shared confidential data from the command and uses the shared confidential data in performing one or more actions.


