Access Control Management System for Secure Cryptographic Data Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional digital rights management systems fail to secure data objects once they are shared externally or created outside the system, and standard cryptographic techniques require technical sophistication, limiting their usability for secure data sharing.
Innovation Solution
The system distributes cryptographic data to authenticated recipients through an access control management system that verifies and authenticates users, allowing secure data sharing via unsecured channels by decoupling access control from data storage and distribution, using identity providers for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If standard cryptographic techniques are used for securing data objects, then security is improved, but technical sophistication is required which limits usability
Solution Approach 1:
The patent introduces a digital rights management system as an intermediary that handles cryptographic operations automatically. The system includes a key management service that generates, distributes, and manages cryptographic keys without requiring users to understand cryptographic principles. This mediator layer shields users from technical complexity while maintaining strong security through automated key management and encryption/decryption operations.
2Reliability
If digital rights management systems are used for securing data, then access control is improved, but the systems do not extend to securing data shared externally or created outside the system
Solution Approach 1:
The patent implements a universal digital rights management system that can secure data objects regardless of their origin or destination. The system provides unified key management and access control for data created inside or outside the system, and for data shared within or externally. The key management service generates cryptographic keys and manages access rights universally across all data objects and users, enabling consistent protection throughout the entire data lifecycle.
3Reliability
If asymmetric key cryptography is used for securing data objects, then security is improved, but users must be able to access public keys which is not mainstream
Solution Approach 1:
The patent implements a self-service key management system where the digital rights management infrastructure automatically handles public key distribution and management. Users do not need to manually obtain or manage public keys; instead, the system automatically provides the necessary cryptographic information through its services. The key management service stores and distributes public keys as needed, eliminating the need for users to perform mainstream-unfriendly key management tasks.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
A method for distributing cryptographic data to authenticated recipients includes receiving, by an access control management system, from a first client device, information associated with an encrypted data object. The method includes receiving, by the access control management system, from a second client device, a request for the information associated with the encrypted data object. The method includes verifying, by the access control management system, that a user of the second client device is identified in the received information associated with the encrypted data object. The method includes authenticating, by the access control management system, with an identity provider, the user of the second client device. The method includes sending, by the access control management system, to the second client device, the received information associated with the encrypted data object.