Security Service Provider for Cloud Data Encryption Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers lack trust in cloud-based services due to inadequate data security measures, creating an adoption barrier for new Software as a Service (SaaS) platforms, as they must rely on service providers to protect their data without assurance of security protocols.

Innovation Solution

Implementing a Security Service Provider (SSP) that allows users to manage security-related functions such as encryption, decryption, and key management, using a hybrid approach where customers retain control over data storage and encryption policies, ensuring data is stored securely within a customer-controlled environment, even when using cloud-based services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If customers use cloud-based services, then service accessibility and functionality are improved, but data security trust is worsened due to lack of control over data storage

Engineering Contradiction:
Improveservice accessibilityVSAvoiddata security trust
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a Security Service Provider (SSP) as an intermediary between the cloud service provider and the customer. The SSP manages cryptographic keys and encryption operations, allowing customers to maintain control over their data security while using cloud-based services. This mediator resolves the trust issue by ensuring that even though data is stored in the cloud, the customer retains cryptographic control through the SSP.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security function from the storage function. Instead of relying on the cloud provider to secure data, the system separates encryption key management (handled by the SSP) from data storage (handled by the cloud provider). This segmentation allows customers to trust the cloud for storage while maintaining independent security control through the SSP.

Inventive Principle:
Principle #1Segmentation

2Productivity

If customers trust the service provider to protect data, then service adoption is improved, but customer control over security protocols is worsened

Engineering Contradiction:
Improveservice adoptionVSAvoidcustomer control over security
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The SSP enables customers to perform security operations independently through self-service mechanisms. Customers can generate, manage, and control their own cryptographic keys via the SSP without requiring deep technical expertise. The system provides user-friendly interfaces for security management, allowing customers to maintain control over their data protection while simplifying the operational complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If encryption keys are stored with cloud service, then data protection is improved, but security vulnerability is worsened in case of cloud service failure

Engineering Contradiction:
Improvedata protectionVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts cryptographic key management from the cloud service provider's control. The SSP stores and manages encryption keys separately from the cloud storage system, ensuring that even if the cloud service experiences a security incident or failure, the customer's data remains protected. This extraction of key management functionality eliminates the single point of failure that would exist if keys were stored with the cloud service.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUSRE49904E1Systems and methods for cloud data security
Publication Date: 2024.04.02 DOCUSIGN INC
  • USRE49904E1 patent drawing
  • USRE49904E1 patent drawing
  • USRE49904E1 patent drawing

AI summary

Techniques for providing data security services with respect to cloud-based services are described. Examples include a security service provider (“SSP”) configured to perform or provide one or more security-related services or functions with respect to or on behalf of some other system or service. The other system or service may be, for example, a cloud-based system that provides network-accessible services. The SSP allows a user of the cloud-based service to provide and manage one or more security-related services, such as data storage, encryption, decryption, key management, and the like. By using and controlling the SSP, the user can be confident that his or her data is being securely represented and stored, even though it is being operated upon by a cloud-based service that is not under the user's control.