Policy Controlled Cryptography for Workload Encryption Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large computing environments with hundreds or thousands of workloads, managing encryption control mechanisms for each individual workload is time-consuming and inefficient.

Innovation Solution

Implementing policy-controlled service routing encryption, where workloads are associated with metadata and policy groups, using an intermediate certificate authority to generate and manage certificates for encrypting traffic based on policy requirements, ensuring secure and efficient cryptographic communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Manufacturing precision

If individual encryption control mechanisms are configured for each workload, then security control precision is improved, but management time and complexity increase significantly

Engineering Contradiction:
Improveencryption control precisionVSAvoidmanagement time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent merges multiple individual workload encryption configurations into a single policy group that can be applied to multiple workloads simultaneously. The policy group consolidates encryption settings, certificates, and security parameters that previously required separate configuration for each workload, thereby reducing management time while maintaining precise security control through the unified policy structure.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The policy group mechanism provides universal encryption control that can be applied across multiple workloads with different characteristics. A single policy group can serve multiple workloads while allowing individual customization through workload-specific metadata, achieving both broad applicability and precise control without requiring separate mechanisms for each workload.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If policy groups are used to manage multiple workloads, then management efficiency is improved, but control flexibility may be reduced

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidcontrol flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The policy group mechanism applies local quality by allowing different encryption parameters and certificates to be assigned to different workloads within the same policy group based on their specific requirements. Each workload can have customized metadata labels that determine its specific encryption settings, ensuring that while management is consolidated, each workload receives appropriately tailored security control.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system enables dynamic assignment of workloads to policy groups based on changing requirements. Workloads can be added to or removed from policy groups, and policy group configurations can be updated without recreating entire encryption architectures. This dynamic structure maintains control flexibility while improving management efficiency through automated policy application.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11290284B2Policy controlled cryptography
Publication Date: 2022.03.29 TIGERA INC
  • US11290284B2 patent drawing
  • US11290284B2 patent drawing
  • US11290284B2 patent drawing

AI summary

One or more data packets intended for a workload running on the server are received from an endpoint at a proxy associated with a server. The proxy associated with the server determines whether the one or more data packets intended for the workload are encrypted with a certificate associated with a policy group that includes the workload. The one or more data packets are provided to the workload based on whether the one or more data packets intended for the workload are encrypted with a certificate associated with a policy group that includes the workload.