Perimeter Encryption Key Management via Gateway Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved endpoint security, particularly at the perimeter of enterprise networks, to prevent data leakage and other negative consequences from compromised endpoints, as existing security measures are inadequate in effectively managing and encrypting communications.

Innovation Solution

The solution involves storing encryption keys on perimeter devices like gateways and applying rules to control the use of these keys for cryptographic processing of communications, including decrypting attachments, performing security scans, and routing communications based on scan results, while also using portable encryption containers for secure handling and decryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption keys are stored at the perimeter device and communications are encrypted, then data security and prevention of data leakage are improved, but the complexity of the security system increases

Engineering Contradiction:
Improvedata securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a perimeter device as an intermediary component that centralizes encryption key storage and cryptographic processing. This mediator handles the complexity of key management and encryption operations, allowing the main network to benefit from enhanced security without directly managing the complexity of encryption infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments security functions by separating encryption key storage and cryptographic processing from the main network infrastructure. The perimeter device acts as a dedicated segment that handles security operations, while the rest of the network remains relatively simple and focused on data transmission.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If encryption keys are stored at the perimeter device, then control over encryption is improved, but the risk of key compromise increases

Engineering Contradiction:
Improvecontrol over encryptionVSAvoidkey compromise risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where the perimeter device receives instructions from authorized users or systems about when and how to decrypt communications. This feedback loop ensures that encryption control remains flexible and adaptable while maintaining security through centralized management of decryption capabilities.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by pre-configuring the perimeter device with encryption keys and decryption capabilities before communications occur. This allows for controlled encryption from the outset while the feedback mechanism provides ongoing control and adjustment capabilities.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If communications are encrypted at the perimeter, then data protection is improved, but the speed of communication processing decreases

Engineering Contradiction:
Improvedata protectionVSAvoidcommunication processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The perimeter device performs encryption and decryption operations in advance of communication transmission. By preparing encrypted communications before they enter the network and pre-decryption before delivery to authorized recipients, the system minimizes processing delays during actual data transmission.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous encryption and decryption operations as communications pass through the perimeter device, ensuring that data protection is maintained throughout the entire communication lifecycle without interrupting the flow of useful information.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10931648B2Perimeter encryption
Publication Date: 2021.02.23 SOPHOS LTD
  • US10931648B2 patent drawing
  • US10931648B2 patent drawing
  • US10931648B2 patent drawing

AI summary

Encryption keys for an enterprise are stored at a perimeter device such as a gateway, and rules are applied at the network perimeter to control whether and how these keys are used for cryptographic processing of communications passing through the perimeter device. The encrypted status of communications, e.g. whether and how files are encrypted with the encryption keys, may also be used to assist in selecting appropriate security handling and routing of the communications.