Attribute-Based Key Management for Granular Message-Node Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptography and key management methods in message domains have varying assurance levels, necessitating elevated security measures to protect sensitive message elements like PIN, PAN, PHI, and PII, while current encryption techniques often lack granular control and synchronization, leading to potential unauthorized access and data exposure.
Innovation Solution
Implementing Secure Node Exchange Attribute-based Keys (SNEAK) for secure exchange of sensitive message elements between nodes using attribute-based key management, where each node accesses encrypted message components based on its assigned attributes, ensuring secure translation and decryption of Content Encryption Keys (CEKs) through a key management node.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional cryptography and key management methods are used in message domains, then system compartmentalization and autonomous operation are maintained, but security assurance levels vary and need to be elevated
Solution Approach 1:
A key management node is introduced as an intermediary between message nodes to handle key translation and distribution. This mediator receives encrypted message components with CEKs established using its public key, translates them to CEKs established using other nodes' public keys, and enables secure key exchange without requiring direct trust between communicating nodes, thereby elevating security assurance while managing complexity centrally
Solution Approach 2:
The system changes the parameter of key establishment by introducing attribute-based key management where CEKs are established using public keys associated with node attributes. This allows fine-grained control over which nodes can access which message components based on attribute matching, elevating security assurance through more sophisticated key management parameters
2Reliability
If encryption techniques without granular control are used, then implementation simplicity is maintained, but unauthorized access and data exposure become more likely
Solution Approach 1:
The message is segmented into multiple encrypted message components, each protected by a separate CEK. This segmentation enables granular control over which components can be accessed by which nodes based on their attributes, preventing unauthorized access while maintaining manageable implementation through structured encryption of individual components
Solution Approach 2:
Different message components have different accessibility rules based on the attributes of receiving nodes. Each component is encrypted with a CEK that can be decrypted only by nodes with matching attributes, providing local quality control where each part of the message has specific access rights rather than uniform access throughout
3Adaptability or versatility
If attribute-based key management is implemented, then granular control over message access is achieved, but key translation and synchronization complexity increases
Solution Approach 1:
The key management node serves as a centralized intermediary that handles all key translation operations. It receives CEKs encrypted with its public key, translates them to CEKs encrypted with other nodes' public keys based on attribute matching, and distributes them appropriately. This mediator approach provides flexible attribute-based access control while centralizing translation complexity in a dedicated component
Data Source
AI summary
The arrangements disclosed herein relate to systems, apparatus, methods, and non-transitory computer readable media for Secure Node Exchange Attribute-based Keys (SNEAK) including secure exchange of sensitive message elements between sequential message nodes using attribute-based key management. Each message node can access none, one, some, or all encrypted message elements based on assigned attributes of that message node. A key management node provides key exchange for each Content Encryption Key (CEK) used to protect the message elements based on attributes of the message nodes.


