Site-Specific Master Key Generation for Secure Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information handling systems face challenges in securely accessing and transmitting sensitive data, such as protected health information (PHI), due to limitations in encryption and access control, which can lead to data breaches and non-compliance with regulations like HIPAA.
Innovation Solution
A resilient, site-specific master key is generated using site-specific characteristics, which are then used to create layered encryption systems involving symmetrical and public/private key encryption, ensuring secure data protection and transmission by regenerating the master key as needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional encryption methods are used to protect sensitive data, then data security is improved, but access control becomes complex and manual intervention is required
Solution Approach 1:
The system automatically generates and manages encryption keys using site-specific characteristics without requiring manual intervention. The key generation process is self-service, where the system uses readily available site identifiers (MAC addresses, serial numbers, UUIDs) to automatically create unique encryption keys for each site, eliminating the need for manual key distribution and management
Solution Approach 2:
The system changes the parameters of key generation by using site-specific characteristics (MAC addresses, serial numbers, UUIDs) as input parameters instead of traditional manual key creation. This parameter change automates the process and ensures each site has a unique, securely generated encryption key based on its own identifying features
2Reliability
If manual key management is used, then security control is maintained, but productivity and automation are reduced
Solution Approach 1:
The system performs self-service by automatically generating encryption keys using site-specific characteristics stored in the information handling system. This eliminates the need for external key management services or manual intervention, thereby maintaining security control while significantly improving automation efficiency and productivity
Solution Approach 2:
The system performs preliminary action by pre-generating encryption keys using site-specific characteristics before data transmission occurs. The keys are created in advance based on site identifiers, ensuring security control is established beforehand while enabling automatic, high-speed data encryption and transmission without manual delays
3Reliability
If third-party key management solutions are used, then security is enhanced, but system independence and resilience are reduced
Solution Approach 1:
The system achieves self-service by generating encryption keys internally using site-specific characteristics such as MAC addresses, serial numbers, and UUIDs. This eliminates dependence on third-party key management solutions, enhancing system independence and resilience while maintaining strong security through locally-generated unique keys for each site
Solution Approach 2:
The system applies universality by using multiple site-specific characteristics (MAC addresses, serial numbers, UUIDs) that are already present in the information handling system for a single purpose: key generation. This multi-functional use of existing site identifiers enhances security through diverse input parameters while maintaining system independence without requiring external solutions
Data Source
AI summary
A system encrypts a private key with a master key and includes a storage device for storing a protected private key at a site location, a processor that determines a plurality of derivatives by selecting an order of site characteristics from a plurality of disjoint sets of site characteristics unique to a software installation or site location, wherein the processor applies a hash algorithm to each site characteristic. The system further includes a buffer storage device for storing an order of random selections of the site characteristics for the derivatives. The system encrypts the master key with the derivatives and additionally stores the encrypted form of the master key in a storage device.


