Orchestrating Agent for Volume Encryption Lifecycle Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Many companies are reluctant to adopt volume encryption technologies due to the complexity and time required for secure encryption of employee devices, which can hinder their implementation in practical settings.

Innovation Solution

An orchestrating agent is installed on devices to manage encryption throughout their lifecycle, facilitating data protection by interacting with external entities and escrowing protector data to ensure access for legitimate stakeholders, thereby simplifying the encryption process and ensuring data security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If volume encryption is implemented to secure data, then data security is improved, but the complexity and time required for encryption management increases

Engineering Contradiction:
Improvedata securityVSAvoidencryption management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an orchestrating agent as an intermediary component that mediates between the encryption system and external entities. This agent automates encryption management tasks, handles key escrow operations, and coordinates with external services, thereby reducing the complexity burden on the main system while maintaining strong data security through centralized management

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If volume encryption is implemented to secure data, then data security is improved, but the time required for encryption setup and management increases

Engineering Contradiction:
Improvedata securityVSAvoidencryption setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary actions by pre-configuring encryption parameters, pre-establishing key escrow mechanisms, and pre-defining management policies before data encryption begins. The orchestrating agent performs setup tasks in advance, allowing rapid deployment of encryption without requiring lengthy configuration processes during actual data protection operations

Inventive Principle:
Principle #10Preliminary action

3Reliability

If encryption keys are securely managed to protect data, then data security is improved, but the difficulty of ensuring access for legitimate stakeholders increases

Engineering Contradiction:
Improvedata securityVSAvoiddata access for authorized users
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements feedback mechanisms where the orchestrating agent continuously monitors access requests, validates authorized stakeholders, and coordinates key release operations. This feedback loop ensures that encryption remains secure while automatically granting access to legitimate users through verified identity checks and controlled key delivery, eliminating manual intervention requirements

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8561209B2Volume encryption lifecycle management
Publication Date: 2013.10.15 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8561209B2 patent drawing
  • US8561209B2 patent drawing
  • US8561209B2 patent drawing

AI summary

Aspects of the subject matter described herein relate to encryption lifecycle management. In aspects, an orchestrating agent is installed on a device upon which encryption management is desired. During the lifecycle of the device, the orchestrating agent facilitates performing actions to protect the data of the device. For example, at certain points during the actions, the orchestrating agent may deduce the presence of external entities needed to perform the actions and interact with those entities to protect the data. During its facilitating activities, the orchestrating agent may also escrow protector data to use to unlock the data for legitimate stakeholders of the data.