Redundant Key Management via Segmented Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ensuring the security and durability of data storage systems, particularly in complex network configurations where data access and storage across multiple geographic boundaries are involved, is challenging due to the need for robust authorization and encryption to prevent unauthorized access and data loss.
Innovation Solution
A data storage system employs redundant storage techniques, such as erasure coding, and cryptographic methods using content encryption keys and key encrypting keys, with key rotation and disaster recovery mechanisms to ensure secure data access and durability, maintaining compliance with service-level agreements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If redundant storage techniques and key rotation mechanisms are implemented, then data security and durability are improved, but system complexity increases
Solution Approach 1:
The patent divides the key management system into separate components: content encryption keys for data encryption, key encrypting keys for protecting the content keys, and service encryption keys for key rotation. This segmentation allows each component to have specialized functionality while working together to provide comprehensive security without overwhelming complexity in a single system.
Solution Approach 2:
The patent implements key rotation mechanisms where service encryption keys are rotated in advance according to a schedule or triggered by security events. This preliminary action ensures that if a key is compromised, the system can switch to a new key before the compromised key is used to access data, maintaining security without requiring complex real-time detection and response systems.
2Reliability
If key encrypting keys are stored securely, then data protection is improved, but access difficulty increases
Solution Approach 1:
The patent introduces service encryption keys as intermediary elements that mediate between the key encrypting keys and content encryption keys. The service encryption keys are stored in a key rotation service and can be retrieved by authorized users, providing a convenient access mechanism while maintaining security. This intermediary layer simplifies the access process compared to directly managing key encrypting keys.
Solution Approach 2:
The key rotation service enables users to retrieve service encryption keys independently without requiring direct access to the key encrypting keys or the complex key management infrastructure. Users can perform key retrieval operations autonomously through the service interface, improving ease of operation while the service backend maintains secure storage of the actual encryption keys.
Data Source
AI summary
A data storage service redundantly stores data and keys used to encrypt the data. Data objects are encrypted with first cryptographic keys. The first cryptographic keys are encrypted by second cryptographic keys. The first cryptographic keys and second cryptographic keys are redundantly stored in a data storage system to enable access of the data objects, such as to respond to requests to retrieve the data objects. The second cryptographic keys may be encrypted by third keys and redundantly stored in the event access to a second cryptographic key is lost.


