Organization-Specific Encryption Key Management for Multi-Organization Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing group-based communication systems face challenges in encryption key management, particularly for channels involving multiple organizations, where organizations cannot revoke access to media after disconnection, and encryption key management is limited, leading to security concerns.

Innovation Solution

A system and method for dynamic encryption key management that allows each organization in a group-based communication system to use organization-specific encryption keys for messages and files, enabling encryption and decryption based on their respective policies, and allowing organizations to revoke access even after channel disconnection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption key management is enabled for channels with multiple organizations, then data security and access control are improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidencryption key management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the encryption key management system into organization-specific key pairs, where each organization has its own private key for encryption and the system maintains corresponding public keys. This segmentation allows independent key management per organization while maintaining overall system security, resolving the contradiction by making complex multi-organization key management manageable through modular organization of cryptographic materials.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary key management mechanism that handles the complexity of multi-organization encryption transparently. When messages are transmitted between organizations, the system automatically manages key selection, encryption, and decryption without requiring users to directly handle cryptographic complexity. This intermediary layer maintains data security while shielding users from the underlying system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If organizations are disconnected from the channel and receive a read-only copy, then access control is simplified, but the ability to revoke access is lost

Engineering Contradiction:
Improvechannel disconnection simplicityVSAvoidaccess revocation capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing organization-specific encryption keys before disconnection occurs. Each organization's data in the channel is encrypted with their unique private key. When disconnection happens, the system can immediately revoke access by simply withholding or destroying the decryption keys, without needing to modify the disconnected read-only copy. This preliminary key establishment enables both simple disconnection and maintainable access revocation capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the state parameter of encryption keys dynamically - maintaining active key pairs for connected organizations and transitioning to revoked/key-withheld state for disconnected organizations. This parameter change approach allows the system to move from a state where access control is difficult to revoke to a state where revocation is achieved simply by key state management, resolving the contradiction between disconnection simplicity and revocation capability.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If a single encryption key is used for all organizations in a channel, then system complexity is reduced, but data security and organization-specific control are compromised

Engineering Contradiction:
Improveencryption key managementVSAvoiddata security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies local quality by implementing organization-specific encryption keys rather than a universal key. Each organization has its own private key for encrypting their data and the system maintains corresponding public keys for decryption. This local quality approach ensures that compromise of one organization's key does not affect others, maintaining data security while managing complexity through localized key management rather than centralized single-key management.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11818250B2Encryption key management for channels with multiple organizations
Publication Date: 2023.11.14 SALESFORCE INC
  • US11818250B2 patent drawing
  • US11818250B2 patent drawing
  • US11818250B2 patent drawing

AI summary

Media, system, and method for providing encryption key management to a channel within a group-based communication system. The contents of the channel is encrypted according to the encryption key management policy of the organization to which the author of the content belongs and is stored in a data store. Responsive to a revocation request from a first organization, the encryption keys associated with any content in the channel submitted by the authors of said first organization may be revoked from a second organization, such that users of the second organization no longer have access to the content.