Perimeter Encryption Key Management via Gateway Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for improved endpoint security, particularly at the perimeter of enterprise networks, to prevent data leakage and other negative consequences from compromised endpoints, as existing security measures are inadequate in effectively managing and encrypting communications.
Innovation Solution
The solution involves storing encryption keys on perimeter devices like gateways and applying rules to control the use of these keys for cryptographic processing of communications, including decrypting attachments, performing security scans, and routing communications based on scan results, while also using portable encryption containers for secure handling and decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption keys are stored at the perimeter device and communications are encrypted, then data security and prevention of data leakage are improved, but the complexity of the security system increases
Solution Approach 1:
The patent introduces a perimeter device as an intermediary component that centralizes encryption key storage and cryptographic processing. This mediator handles the complexity of key management and encryption operations, allowing the main network to benefit from enhanced security without directly managing the complexity of encryption infrastructure.
Solution Approach 2:
The system segments security functions by separating encryption key storage and cryptographic processing from the main network infrastructure. The perimeter device acts as a dedicated segment that handles security operations, while the rest of the network remains relatively simple and focused on data transmission.
2Adaptability or versatility
If encryption keys are stored at the perimeter device, then control over encryption is improved, but the risk of key compromise increases
Solution Approach 1:
The patent implements feedback mechanisms where the perimeter device receives instructions from authorized users or systems about when and how to decrypt communications. This feedback loop ensures that encryption control remains flexible and adaptable while maintaining security through centralized management of decryption capabilities.
Solution Approach 2:
The system performs preliminary actions by pre-configuring the perimeter device with encryption keys and decryption capabilities before communications occur. This allows for controlled encryption from the outset while the feedback mechanism provides ongoing control and adjustment capabilities.
3Reliability
If communications are encrypted at the perimeter, then data protection is improved, but the speed of communication processing decreases
Solution Approach 1:
The perimeter device performs encryption and decryption operations in advance of communication transmission. By preparing encrypted communications before they enter the network and pre-decryption before delivery to authorized recipients, the system minimizes processing delays during actual data transmission.
Solution Approach 2:
The system maintains continuous encryption and decryption operations as communications pass through the perimeter device, ensuring that data protection is maintained throughout the entire communication lifecycle without interrupting the flow of useful information.
Data Source
AI summary
Encryption keys for an enterprise are stored at a perimeter device such as a gateway, and rules are applied at the network perimeter to control whether and how these keys are used for cryptographic processing of communications passing through the perimeter device. The encrypted status of communications, e.g. whether and how files are encrypted with the encryption keys, may also be used to assist in selecting appropriate security handling and routing of the communications.


