Remote Key Management with Client-Side Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current collaboration environments in cloud-based settings lack client-side control and configurability for security mechanisms, particularly in data encryption, which restricts enterprise-level management and flexibility in key encryption processes.

Innovation Solution

The implementation of a remote key management system that includes local key encryption and automatic generation of reason codes, utilizing a rule engine for client-side control and configurability, along with a kill switch for remote kill capabilities, to manage encryption keys dynamically based on pre-defined rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud-based collaboration environments provide high availability and shared access to files, then accessibility and collaboration capability are improved, but security control and data protection are worsened due to lack of client-side control

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments encryption into two distinct layers: client-side encryption for data protection and server-side encryption for key management. This segmentation allows users to maintain full accessibility and collaboration capabilities while the enterprise retains centralized security control through the key service engine that manages all encryption keys.

Inventive Principle:
Principle #1Segmentation

2Reliability

If centralized key management is implemented, then security control is improved, but flexibility and client-level customization are worsened

Engineering Contradiction:
Improvesecurity controlVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The key service engine provides dynamic key management capabilities that adapt to different client needs in real-time. The system can dynamically generate, rotate, and revoke encryption keys based on pre-configured rules and policies, allowing the centralized system to maintain security while adapting to varying organizational requirements without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes encryption parameters dynamically through the key service engine, which can modify encryption algorithms, key lengths, and management policies based on organizational needs. This allows centralized control to adapt to different security requirements while maintaining a unified management approach.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If manual key management processes are used, then control is improved, but efficiency and productivity are worsened due to time-consuming operations

Engineering Contradiction:
ImprovecontrolVSAvoidefficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The key service engine implements self-service automation where the system automatically manages encryption keys without manual intervention. The engine can autonomously generate new keys, rotate existing keys, and revoke access based on pre-configured rules, significantly improving efficiency while maintaining reliable control through automated policy enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-configuring encryption rules, policies, and key management procedures before actual data processing occurs. This allows the system to automatically handle key management tasks during data upload, storage, and access operations, eliminating manual processes and improving productivity while maintaining secure control.

Inventive Principle:
Principle #10Preliminary action

4Speed

If encryption keys are stored locally, then performance is improved, but security vulnerability is worsened due to loss or theft risks

Engineering Contradiction:
ImproveperformanceVSAvoidsecurity vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The key service engine acts as an intermediary between client-side encryption needs and centralized security management. It provides a secure communication channel that allows clients to encrypt data locally using keys managed by the server, eliminating the need to store encryption keys on client devices while maintaining both performance and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9628268B2Remote key management in a cloud-based environment
Publication Date: 2017.04.18 BOX INC
  • US9628268B2 patent drawing
  • US9628268B2 patent drawing
  • US9628268B2 patent drawing

AI summary

Systems and methods are disclosed for facilitating remote key management services in a collaborative cloud-based environment. In one embodiment, the remote key management architecture and techniques described herein provide for local key encryption and automatic generation of a reason code associated with content access. The reason code is used by a remote client device (e.g., an enterprise client) to control a second (remote) layer of key encryption. The remote client device provides client-side control and configurability of the second layer of key encryption.