On-Premises Listener for Encrypted Calendar Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing video conferencing systems face challenges in maintaining the privacy of calendar data, as sensitive information can be exposed due to storage in remote cloud components, risking security breaches.

Innovation Solution

Implementing a key-distribution secret and asymmetric key pair, where the first-private key is stored on-premises and never shared with cloud components, ensuring that only the customer can decrypt calendar items, thus maintaining control over sensitive data within their private network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If calendar data is stored in remote cloud components for distributed video conferencing access, then service accessibility and convenience are improved, but data privacy and security are worsened due to potential exposure outside customer's private network

Engineering Contradiction:
Improveservice accessibilityVSAvoiddata exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments calendar data into encrypted portions stored in cloud components and decryption keys stored locally on-premises. The encrypted calendar data can be accessed remotely through the distributed service, but the sensitive plaintext information remains segmented and stored only within the customer's private network, thus maintaining accessibility while preventing data exposure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an on-premises listener component as an intermediary between the distributed service and the customer's calendar data. This listener receives encrypted calendar data from cloud components, decrypts it locally using on-premises stored keys, and processes it within the private network. The intermediary ensures that sensitive data never leaves the customer's network while still enabling cloud-based service functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If private keys are stored on-premises and never shared with cloud components, then data security is improved, but system complexity increases due to key distribution and management requirements

Engineering Contradiction:
Improvedata securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The on-premises listener component serves multiple functions: it acts as a key management system for securing calendar data, as an intermediary for receiving encrypted data from cloud components, and as a local decryption and processing unit. This multi-functional component consolidates key management complexity into a single on-premises system rather than distributing it across multiple components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary key distribution during the initial setup and provisioning phase. The on-premises listener is pre-configured with necessary cryptographic keys and credentials before operational use. This preliminary action establishes secure key management infrastructure in advance, reducing ongoing operational complexity while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10491577B2Secure, customer-controlled storage for cloud-managed meeting details
Publication Date: 2019.11.26 VERIZON PATENT & LICENSING INC
  • US10491577B2 patent drawing
  • US10491577B2 patent drawing
  • US10491577B2 patent drawing

AI summary

Embodiments are described for securing access to sensitive information used by on-premises devices in a distributed system. For example, embodiments include securing access to sensitive calendar items in a video conferencing service.