Remote Key Management via HSM Audit Logging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing collaboration environments in enterprise settings lack client-level control over security mechanisms for data access and encryption, leading to inadequate security configurability and monitoring capabilities.

Innovation Solution

The implementation of a remote key management system using a Hardware Security Module (HSM) that provides local key encryption, automatic audit logging, and client-side control through a rule engine, enabling enterprises to configure and monitor access to encryption keys, with a kill switch for managing access inconsistencies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security mechanisms are added to content access in collaboration environments, then data security is improved, but client-level control and configurability are lost

Engineering Contradiction:
Improvedata securityVSAvoidclient-level control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments security control into multiple layers: enterprise-level policy configuration, department-level key management, and individual file-level encryption. This hierarchical segmentation allows each level to have appropriate control authority, resolving the contradiction between centralized security and decentralized configurability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of control by implementing a multi-tier key management system with enterprise keys, department keys, and file keys. This dimensional approach to key hierarchy enables granular control at different organizational levels, providing both security and configurability simultaneously.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Stability of the object's composition

If encryption keys are managed centrally, then security consistency is improved, but real-time monitoring and client control are reduced

Engineering Contradiction:
Improvesecurity consistencyVSAvoidreal-time monitoring
Core Design Contradiction:
Stability of the object's compositionVSEase of operation

Solution Approach 1:

The patent implements comprehensive audit logging that provides real-time feedback on key access and file encryption events. The system logs all key usage, file access, and decryption events, enabling enterprises to monitor and respond to security events in real-time while maintaining centralized key management consistency.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an enterprise key management service as an intermediary between the centralized key storage and client applications. This intermediary layer provides controlled access to encryption keys, maintaining security consistency while enabling real-time monitoring and client-level operations through standardized APIs.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access control mechanisms are implemented, then data protection is improved, but collaboration speed and accessibility are reduced

Engineering Contradiction:
Improvedata protectionVSAvoidcollaboration speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary encryption of files at upload time, so that data is protected before access requests occur. Encryption keys are pre-distributed to authorized users and devices, eliminating the need for time-consuming key negotiation during collaboration, thus maintaining both security and speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses cryptographic copying where encryption keys are replicated and distributed to all authorized users and devices in advance. This allows multiple users to access and collaborate on encrypted files simultaneously without requiring real-time key exchange, maintaining collaboration speed while ensuring data protection.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10574442B2Enhanced remote key management for an enterprise in a cloud-based environment
Publication Date: 2020.02.25 BOX INC
  • US10574442B2 patent drawing
  • US10574442B2 patent drawing
  • US10574442B2 patent drawing

AI summary

Systems and methods are disclosed for facilitating remote key management services in a collaborative cloud-based environment. In one embodiment, the remote key management architecture and techniques described herein provide for local key encryption and automatic generation of a reason code associated with content access. The reason code is logged by a hardware security module which is monitored by a remote client device (e.g., an enterprise client) to control a second (remote) layer of key encryption. The remote client device provides client-side control and configurability of the second layer of key encryption.