Secure Execution Platform Cluster Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security systems face challenges in maintaining confidentiality and integrity of sensitive data, particularly due to potential leaks from human administrators or rogue software, and the risk of insider attacks, as cryptographic keys are often accessible to human users who can misuse or compromise them.

Innovation Solution

A cluster of Secure Execution Platforms (SEPs) automatically generates and shares a key among its members, ensuring only authorized agents can access and manage encrypted data, preventing unauthorized access and maintaining confidentiality by encrypting and decrypting data within the cluster, thus keeping the key from human users and external entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If human administrators are given unrestricted access to data for management purposes, then ease of operation is improved, but security and confidentiality of data deteriorate

Engineering Contradiction:
Improvedata management accessVSAvoidinsider threats and data leakage
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the cryptographic key management function from human administrators and transfers it to an automated system. The key is automatically generated and stored in a secure key vault, eliminating human access to the key while maintaining data management capabilities through automated key rotation and access control mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a key vault as an intermediary component between data storage and access systems. This key vault automatically manages cryptographic keys without human intervention, serving as a mediator that enables data operations while preventing insider threats by eliminating human key access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If cryptographic keys are made accessible to human users for data management, then ease of operation is improved, but reliability and security of the system deteriorate

Engineering Contradiction:
Improvekey managementVSAvoidkey security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements self-service key management where the system automatically generates, stores, rotates, and manages cryptographic keys without human intervention. The key vault autonomously performs all key management operations, eliminating human errors and security risks associated with manual key handling.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical system of human key management with an automated computational system. The key vault uses cryptographic algorithms and automated processes to manage keys, substituting human operations with reliable machine-based key management that eliminates insider threats.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Device complexity

If a single centralized data storage is used, then device complexity is reduced, but the risk of single point of failure and data loss increases

Engineering Contradiction:
Improvestorage architectureVSAvoiddata availability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the centralized data storage into multiple distributed storage nodes. Data is partitioned and stored across multiple locations, eliminating the single point of failure while maintaining manageable complexity through standardized storage interfaces and automated data distribution mechanisms.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11057361B2Cluster of secure execution platforms
Publication Date: 2021.07.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11057361B2 patent drawing
  • US11057361B2 patent drawing
  • US11057361B2 patent drawing

AI summary

A computer program product and a system comprising: a cluster of Secure Execution Platforms (SEPs) having connectivity to a data storage, each SEP of said cluster is configured to maintain, using a key, confidentiality of data while processing thereof; the key is shared among the SEPs of said cluster, the key is automatically generated by the cluster or portion thereof and is unavailable to any non-cluster entity; the data storage retains encrypted data that is encrypted using the key; a first SEP of the cluster is configured to encrypt client data using the key to obtain encrypted client data and store the encrypted client data in the data storage; and a second SEP of the cluster is configured to retrieve encrypted stored data from the data storage, decrypt the encrypted stored data using the key to obtain non-encrypted form of the encrypted stored data.