Scalable Key Archival via Network Device Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current key management systems for data at rest encryption require modifications and configuration changes when integrating multiple systems, and often lack redundancy and high availability features, making them inefficient for ensuring secure key archival and retrieval.

Innovation Solution

A scalable key archival method that detects new key management devices, determines their capabilities, and creates bindings between virtual device drivers and security processors using APIs, ensuring redundancy and high availability by archiving keys across multiple systems if needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple key management systems are integrated into an enterprise system, then key management capability is improved, but system complexity and configuration effort increase

Engineering Contradiction:
Improvekey management capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a network device as an intermediary component that sits between storage devices and multiple key management systems. This network device automatically discovers available key management systems, selects appropriate ones, and manages the bindings between them, eliminating the need for enterprise systems to directly configure and manage multiple key management system interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network device performs automatic discovery and binding of key management systems without requiring manual configuration. The system self-configures by detecting key management systems on the network, determining their capabilities, and establishing bindings autonomously, thereby reducing configuration effort and complexity for the enterprise system.

Inventive Principle:
Principle #25Self-service

2Reliability

If key management systems provide redundancy and high availability, then system reliability is improved, but device complexity increases

Engineering Contradiction:
Improveredundancy and high availabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network device acts as a mediator that manages redundancy and high availability by maintaining bindings to multiple key management systems. It automatically selects appropriate systems for key archival and retrieval operations, handling the complexity of redundancy management internally while presenting a simplified interface to the enterprise system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network device performs preliminary discovery and capability assessment of key management systems before they are needed for key archival. By pre-establishing bindings and evaluating system capabilities in advance, it prepares the redundancy infrastructure beforehand, reducing the complexity of real-time redundancy management.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If key archival is performed across multiple key management systems, then key availability is improved, but integration complexity increases

Engineering Contradiction:
Improvekey availabilityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network device serves as an intermediary that abstracts the complexity of multi-system key archival. It discovers key management systems, evaluates their capabilities, and automatically creates bindings to appropriate systems, enabling key archival across multiple systems without requiring the enterprise system to manage the integration complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network device provides universal functionality by supporting multiple key management systems through a standardized interface. It can bind to different types of key management systems and manage key archival operations uniformly, thereby improving key availability across heterogeneous systems while hiding integration complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If enterprise systems modify themselves to accommodate multiple key management system interfaces, then compatibility is improved, but system complexity and maintenance burden increase

Engineering Contradiction:
ImprovecompatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The network device acts as an intermediary that handles compatibility with multiple key management system interfaces. It translates between different key management system protocols and provides a unified interface to the enterprise system, eliminating the need for the enterprise system to modify itself to accommodate multiple interfaces while maintaining broad compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8311225B2Scalable key archival
Publication Date: 2012.11.13 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8311225B2 patent drawing
  • US8311225B2 patent drawing
  • US8311225B2 patent drawing

AI summary

A solution for scalable key archival includes, at a network device, determining whether a key management device that is not part of a current key management device configuration has been newly added to a network. The method also includes, if the key management device has been newly added to the network, determining whether the network device has a first application program interface (API) or device driver for communicating with the key management device. The method also includes, if the network device does not have the first API, obtaining the API. The method also includes creating a binding between a virtual device driver of the network device and the key management device via the first API, the network device having a second API for communications between the virtual device driver and a security processor of the network device. The security processor communicates with the key management device using the second API.