Secure Domain Manager Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security techniques lack an effective solution for securing domain managers in cloud computing systems, which are critical for managing and transferring secure domains across devices while preventing unauthorized access and malicious attacks.

Innovation Solution

A communication system that includes a secure domain manager, which creates and manages secure domains by obtaining and encrypting access keys, allowing only authorized access, and facilitating secure migration of these domains between devices using a platform manager and verification engine, ensuring secure channel creation and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If domain managers are used to manage secure domains in cloud computing systems, then domain management and transfer capabilities are improved, but security vulnerabilities and unauthorized access risks increase

Engineering Contradiction:
Improvedomain management capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure channel as an intermediary between the domain manager and the secure domain. This secure channel acts as a mediator that protects the communication and key exchange processes, preventing unauthorized access while enabling domain management operations. The secure channel is established through a key exchange mechanism that ensures confidentiality and integrity of the management operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If secure domains are migrated between devices, then system flexibility and resource utilization are improved, but security risks during transfer increase

Engineering Contradiction:
Improvedomain migration capabilityVSAvoidsecurity during transfer
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent establishes a secure channel before the actual domain migration process begins. This preliminary action of creating a protected communication path ensures that when the domain and its keys are transferred between devices, the transfer occurs within a already-secured environment. The secure channel is set up in advance through key exchange protocols, preventing security risks during the critical transfer phase.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If access keys are stored locally on devices, then access speed and convenience are improved, but vulnerability to local attacks increases

Engineering Contradiction:
Improveaccess speedVSAvoidlocal attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a nested security structure where the access key is protected by multiple layers. The key exchange mechanism nests the actual domain access key within a secure channel that is itself protected by cryptographic protocols. This nested approach allows fast local access while maintaining security, as the key is stored locally but accessed through the nested secure channel that prevents local attacks.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10152350B2Secure domain manager
Publication Date: 2018.12.11 INTEL CORP
  • US10152350B2 patent drawing
  • US10152350B2 patent drawing
  • US10152350B2 patent drawing

AI summary

Particular embodiments described herein provide for an electronic device that can be configured to determine that a secure domain has been created on a device, where keys are required to access the secure domain, obtain the keys that are required to access the secure domain from a network element, and encrypt the keys and store the encrypted keys on the device. In an example, only the secure domain can decrypt the encrypted keys and the device is a virtual machine.