Secure Server Migration Using Customer-Managed Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers face challenges in securely migrating servers from on-premises data centers to cloud computing service providers due to concerns about data security, compliance with regulations, and the need for end-to-end encryption across multiple platforms and data centers.

Innovation Solution

A server migration service that uses customer-provided encryption keys to encrypt and decrypt replication data during migration, ensuring secure data transfer and storage, with the assistance of backup proxies and key management services, and logging/auditing services for compliance and visibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If servers are migrated from customer networks to service provider systems, then cloud computing resources and scalability are improved, but data security and compliance concerns worsen

Engineering Contradiction:
Improvecloud computing resourcesVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary encryption of replication data at the customer network before transmission to the service provider system. Encryption keys are obtained and data is encrypted in advance during the backup process, ensuring data security is established before migration occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A backup proxy acts as an intermediary component that facilitates secure data transfer between the customer network and service provider system. The backup proxy obtains encryption keys, encrypts replication data, and manages the migration process, serving as a trusted mediator that maintains security throughout the migration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If end-to-end encryption is implemented during server migration, then data security is improved, but system complexity and key management requirements worsen

Engineering Contradiction:
Improvedata securityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The backup proxy autonomously obtains encryption keys from the key management service and performs encryption operations without requiring manual intervention. The system self-manages the key acquisition and encryption process, reducing operational complexity despite the cryptographic operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The key management service provides feedback mechanisms that allow the backup proxy to obtain and manage encryption keys systematically. The logging and auditing services provide feedback on key usage and migration status, enabling controlled key management despite the complexity of end-to-end encryption.

Inventive Principle:
Principle #23Feedback

3Manufacturing precision

If replication data is encrypted and decrypted during migration, then data integrity is improved, but migration time and processing overhead worsen

Engineering Contradiction:
Improvedata integrityVSAvoidmigration time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

Encryption is performed preliminarily during the backup phase before data migration begins. By encrypting data in advance rather than during transmission or at the destination, the system minimizes the time encryption operations add to the overall migration process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption and decryption operations are integrated into the continuous data flow of the migration process rather than being separate batch operations. The backup proxy continuously encrypts replication data as it is generated, maintaining continuous useful action throughout the migration.

Inventive Principle:
Principle #20Continuity of useful action

4Ease of operation

If customer-provided encryption keys are used, then customer control and compliance visibility are improved, but key management service requirements and system overhead worsen

Engineering Contradiction:
Improvecustomer controlVSAvoidkey management service
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The key management service acts as an intermediary that bridges customer control requirements with the technical key management needs. Customers can provision and manage their encryption keys through the key management service interface, maintaining control while the service handles the complex key storage, distribution, and rotation operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The logging and auditing services provide feedback to customers about key usage and migration activities, enabling compliance visibility. This feedback mechanism allows customers to monitor and control their encryption keys and migration processes without directly managing the underlying key infrastructure.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10922132B1Secure migration of servers from customer networks to service provider systems
Publication Date: 2021.02.16 AMAZON TECH INC
  • US10922132B1 patent drawing
  • US10922132B1 patent drawing
  • US10922132B1 patent drawing

AI summary

Techniques for securely migrating servers from customer networks into service provider systems are described. A backup proxy can be deployed in a customer's network and associated with one or more servers in the customer's network and with a server migration service of a service provider system. A customer can identify a server in the customer's network to migrate and the server migration service coordinates the migration with the backup proxy. The backup proxy can be instructed to obtain replication data for the server, obtain an encryption key associated with the customer from a key management service (KMS), encrypt the replication data, and upload the encrypted replication data to the service provider system. The service provider system can obtain the same encryption key used to encrypt the replication data from the KMS and decrypt the uploaded encrypted replication data to generate migrated server resources at the service provider system.