Centralized Security Object Orchestration for Key Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption key management systems face synchronization issues between device-level encryption key management and communication management, leading to loose controls and potential breakdowns in communication security due to procedural unsynchronization and inadequate controls in public key infrastructure and symmetric key distribution.

Innovation Solution

A centralized security object orchestration system that defines and enforces policies for the management, distribution, and federation of security objects, including encryption keys, based on attributes such as size, generation time, geo-location, and role associations, ensuring secure communication by evaluating and accepting or rejecting security objects according to predefined criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If device-level encryption key management is implemented, then encryption keys can be managed at the source and target devices, but procedural unsynchronization with communication management occurs leading to loose controls

Engineering Contradiction:
Improvedevice-level key managementVSAvoidsynchronization with communication management
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A centralized key management server is introduced as an intermediary between devices and communication management systems. This server receives key generation requests, manages the encryption keys centrally, and distributes them to authorized devices, ensuring procedural synchronization while maintaining device-level operational capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges device-level key management operations with centralized communication management by establishing a unified key management architecture where the key management server coordinates both device operations and communication protocols, eliminating procedural unsynchronization.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If centralized key management is implemented, then communication management and encryption key management are synchronized, but system complexity increases

Engineering Contradiction:
Improvesynchronization with communication managementVSAvoidcentralized management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized key management system is segmented into distinct functional modules: key generation module, key storage module, key distribution module, and policy enforcement module. This segmentation reduces overall system complexity by making each component independent and manageable while maintaining centralized coordination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key management server is designed with multi-functionality, handling key generation, storage, distribution, revocation, and policy enforcement through a single unified platform, reducing the need for multiple separate systems and thereby lowering overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11503076B2System and method for encryption key management, federation and distribution
Publication Date: 2022.11.15 FORNETIX LLC
  • US11503076B2 patent drawing
  • US11503076B2 patent drawing
  • US11503076B2 patent drawing

AI summary

Systems and methods are described for orchestrating a security object, including, for example, defining and storing a plurality of policies in a database coupled to a policy engine and receiving, by the policy engine, the security object and at least one object attribute associated with the security object. In addition, the policy engine determines the acceptability of the security object based, at least in part, on the at least one object attribute and at least one of the plurality of policies corresponding to the at least one object attribute. The security object to at least one communication device associated with the policy engine is distributed when the security object is determined to be acceptable. The at least one communication device establishes communication based, at least in part, on the security object.