Trusted Container for Sealed Encryption Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current implementations for encrypted network traffic have multiple attack points that can be exploited to steal security credentials, and existing solutions do not effectively prevent direct access to encryption keys, making them vulnerable to theft.

Innovation Solution

A computer system with a network encryption device and a trusted container that includes a key store for storing secret encryption keys and a network traffic encryption engine for negotiating and storing encryption keys, along with a flow analyzer to analyze network traffic, ensuring that encryption keys are used to negotiate session keys for encrypting network traffic without being directly accessible to the user or operating system, and using a sandbox to run untrusted programs safely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If encryption keys are stored in accessible locations for use by applications and operating systems, then ease of operation is improved, but security is worsened due to multiple attack points that can be exploited to steal security credentials

Engineering Contradiction:
Improveaccess to encryption keysVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the encryption keys from the accessible software environment (operating system and applications) and places them in an inaccessible hardware security module. The keys are taken out of the trusted computing base and stored in a physically separate, secure location that can only be accessed through encrypted channels, eliminating the attack points in the software layer.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a hardware security module as an intermediary between the applications and the encryption keys. This mediator handles all key operations securely within the hardware boundary, allowing applications to use encryption without directly accessing the keys. The intermediary prevents direct access while enabling operational functionality through controlled interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a sandbox is introduced to run untrusted programs safely and a flow analyzer is added to analyze network traffic, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the sandbox environment and flow analyzer functionality into the same isolated hardware security module. Rather than creating separate complex systems, the containment mechanism and traffic analysis capability are integrated within the secure boundary, sharing the same hardware resources and security enforcement mechanisms, thus reducing overall system complexity while maintaining enhanced security.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10911491B2Encryption with sealed keys
Publication Date: 2021.02.02 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10911491B2 patent drawing
  • US10911491B2 patent drawing
  • US10911491B2 patent drawing

AI summary

An aspect includes a computer system with a network encryption device and a trusted container within firmware or hardware and/or within a virtual machine running on the computer system. The network encryption device includes a key store for storing secret encryption keys and a network traffic encryption engine for negotiating and/or storing encryption keys in the key store and/or for encrypting and/or decrypting network traffic using the encryption keys from the key store. The trusted container includes a flow analyzer for analyzing network traffic received from the network encryption device.