Secure Data Access via Intermediary Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data centers face challenges in securely sharing customer data with third parties without compromising data confidentiality, as existing solutions often require centralized storage and access to unencrypted data.
Innovation Solution
Implementing a system where the provider network facilitates secure data access by encrypting data with customer-generated keys, ensuring only encrypted data is transmitted, and the provider network does not possess decryption keys, thus maintaining data confidentiality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If centralized storage and access to unencrypted data is implemented, then data accessibility and ease of operation are improved, but data confidentiality and security are compromised
Solution Approach 1:
The patent introduces an intermediary encryption system where data is encrypted using customer-generated keys before being stored or transmitted through the provider network. The provider network acts as a mediator that facilitates data exchange without having access to decryption keys, thus maintaining confidentiality while enabling accessibility. This resolves the contradiction by allowing centralized storage and transmission (improving accessibility) while using encryption intermediaries (preserving confidentiality).
Solution Approach 2:
The patent segments the data access system into multiple independent components: customer-controlled encryption keys, encrypted data storage, and key management separate from data storage. This segmentation ensures that no single entity has both data and decryption capability, allowing centralized infrastructure (improving accessibility) while distributing trust and maintaining confidentiality through separate key and data management.
2Ease of operation
If provider network accesses unencrypted data for facilitation, then ease of operation is improved, but reliability of data confidentiality is worsened
Solution Approach 1:
The provider network facilitates data operations (storage, transmission, access) without directly accessing unencrypted data by using encryption intermediaries. Customer-generated encryption keys and encrypted data formats allow the provider network to perform facilitation functions while maintaining confidentiality, thus improving ease of operation without compromising reliability.
Solution Approach 2:
The system enables self-service data protection where customers generate and manage their own encryption keys. This allows the provider network to facilitate operations without needing to access or manage decryption keys, improving ease of operation while maintaining reliable confidentiality through customer-controlled security.
3Object-affected harmful factors
If customer-generated encryption keys are used, then data confidentiality is improved, but device complexity increases
Solution Approach 1:
Customers generate and manage their own encryption keys through self-service mechanisms provided by the system. This approach improves confidentiality by giving customers direct control over their data security while managing complexity through automated key management interfaces and integrated workflows that hide the underlying complexity from end users.
Solution Approach 2:
The system introduces intermediary key management services that mediate between customer security requirements and system operational needs. These intermediaries handle key storage, transmission, and management tasks, improving confidentiality through customer-controlled keys while reducing perceived complexity by abstracting key management operations through standardized interfaces.
Data Source
AI summary
A request is received by a provider network from a requestor for data associated with a customer of the provider network. The data is not stored at the provider network, and the request includes a first encryption key. The provider network verifies that the requestor is authorized to request data from the customer of the multi provider network. The provider network sends information pertaining to the requested data to the customer. The provider network also sends the identity of the requestor and the first encryption key. The provider network sends, to the requestor, data that is encrypted, and a decryption key for decrypting the encrypted data.


