Security Chaining for Instant End-to-End Encryption Rekeying

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing end-to-end encryption technologies lack security coordination across multiple network segments and operational capabilities for instant rekeying and flexible encryption control, particularly in peer-to-peer communication and encrypted data storage systems.

Innovation Solution

Implementing end-to-end efficient encryption with security chaining by using a security chaining logic component to manage encryption key slots and metadata across network segments, enabling instant rekeying through out-of-data signals and state machine transitions to maintain encryption and decryption across all data connection segments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If typical end-to-end encryption is implemented, then encryption of data segments is achieved, but security coordination across multiple network segments is lacking

Engineering Contradiction:
Improvesecurity coordinationVSAvoidencryption system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the encryption system into multiple key slots (current key slot and next key slot) and separates encryption functions across different network segments. Each segment maintains its own encryption state while coordinating through security chaining logic, allowing independent management of encryption keys across segments without requiring complete system reconfiguration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security chaining logic component acts as an intermediary that coordinates encryption operations across multiple network segments. It manages the propagation of out-of-data signals and coordinates state machine transitions between segments, enabling security coordination without direct complex interactions between all segments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If traditional encryption systems are used, then data encryption is provided, but instant rekeying capability is lacking

Engineering Contradiction:
Improverekeying speedVSAvoidkey management mechanism
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system prepares the next key slot in advance with the subsequent encryption key before it is needed. When rekeying is required, the transition is instantaneous because the next key is already prepared and validated in the next key slot, eliminating the need for time-consuming key generation and distribution during the rekeying operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption system dynamically switches between key slots based on operational requirements. The state machine can transition between using the current key slot and the next key slot, and between different encryption modes (encryption/decryption), enabling flexible and instant rekeying without system downtime or reconfiguration.

Inventive Principle:
Principle #15Dynamics

3Reliability

If encryption is maintained across all network segments, then data security is ensured, but operational flexibility for encryption control is reduced

Engineering Contradiction:
Improvedata securityVSAvoidencryption control flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The state machine provides dynamic control over encryption operations across network segments. It can transition between different states (encryption, decryption, key slot switching) based on operational requirements, allowing the system to maintain security while adapting to different operational modes and control scenarios.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes encryption parameters (key slots, encryption/decryption modes) to achieve different operational states. By modifying which key slot is active and whether encryption or decryption is performed, the system maintains data security while providing operational flexibility for different control scenarios.

Inventive Principle:
Principle #35Parameter changes

4Productivity

If key slot switching is implemented, then instant rekeying is achieved, but coordination complexity across network segments increases

Engineering Contradiction:
Improverekeying efficiencyVSAvoidstate machine coordination
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The security chaining logic serves as an intermediary that simplifies coordination of key slot switching across network segments. It manages the propagation of out-of-data signals and coordinates state machine transitions, reducing the complexity of direct coordination between multiple segments while enabling efficient rekeying operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The state machine uses feedback from out-of-data signals to trigger key slot switching operations. When a segment receives an out-of-data signal, it feeds back to the security chaining logic, which coordinates the switching across all segments, ensuring synchronized key slot transitions without complex direct communication between all segments.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12407506B2Rekeying end-to-end efficient encryption with security chaining
Publication Date: 2025.09.02 DELL PROD LP
  • US12407506B2 patent drawing
  • US12407506B2 patent drawing
  • US12407506B2 patent drawing

AI summary

Rekeying an Information Handling System (IHS) network End-to-End Efficient Encryption (E2EEE) with security chaining includes locking an encrypted data volume, preventing reading of, and writing to, the encrypted data volume by applications. A data source IHS may request a new key from a key management system and write new metadata in a trailer of the encrypted data block using a different key slot than a currently used and active metadata key slot, wherein the different key slot is updated with the with the new key. The data source IHS then sends an out-of-data signal to change the use key slot from the currently used key slot to the different key slot. Thereafter, the data source IHS unlocks the encrypted data volume, enabling writing and/or reading user data by the data source IHS and encryption and decryption in all IHS E2EEE data connection segment interfaces.