Attribute-Based Key Management for Granular Message-Node Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptography and key management methods in message domains have varying assurance levels, necessitating elevated security measures to protect sensitive message elements like PIN, PAN, PHI, and PII, while current encryption techniques often lack granular control and synchronization, leading to potential unauthorized access and data exposure.

Innovation Solution

Implementing Secure Node Exchange Attribute-based Keys (SNEAK) for secure exchange of sensitive message elements between nodes using attribute-based key management, where each node accesses encrypted message components based on its assigned attributes, ensuring secure translation and decryption of Content Encryption Keys (CEKs) through a key management node.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cryptography and key management methods are used in message domains, then system compartmentalization and autonomous operation are maintained, but security assurance levels vary and need to be elevated

Engineering Contradiction:
Improvesecurity assurance levelVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A key management node is introduced as an intermediary between message nodes to handle key translation and distribution. This mediator receives encrypted message components with CEKs established using its public key, translates them to CEKs established using other nodes' public keys, and enables secure key exchange without requiring direct trust between communicating nodes, thereby elevating security assurance while managing complexity centrally

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter of key establishment by introducing attribute-based key management where CEKs are established using public keys associated with node attributes. This allows fine-grained control over which nodes can access which message components based on attribute matching, elevating security assurance through more sophisticated key management parameters

Inventive Principle:
Principle #35Parameter changes

2Reliability

If encryption techniques without granular control are used, then implementation simplicity is maintained, but unauthorized access and data exposure become more likely

Engineering Contradiction:
Improvedata protectionVSAvoidencryption control granularity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The message is segmented into multiple encrypted message components, each protected by a separate CEK. This segmentation enables granular control over which components can be accessed by which nodes based on their attributes, preventing unauthorized access while maintaining manageable implementation through structured encryption of individual components

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different message components have different accessibility rules based on the attributes of receiving nodes. Each component is encrypted with a CEK that can be decrypted only by nodes with matching attributes, providing local quality control where each part of the message has specific access rights rather than uniform access throughout

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If attribute-based key management is implemented, then granular control over message access is achieved, but key translation and synchronization complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidkey translation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The key management node serves as a centralized intermediary that handles all key translation operations. It receives CEKs encrypted with its public key, translates them to CEKs encrypted with other nodes' public keys based on attribute matching, and distributes them appropriately. This mediator approach provides flexible attribute-based access control while centralizing translation complexity in a dedicated component

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250330314A1Secure node exchange attribute-based keys (SNEAK)
Publication Date: 2025.10.23 WELLS FARGO BANK NA
  • US20250330314A1 patent drawing
  • US20250330314A1 patent drawing
  • US20250330314A1 patent drawing

AI summary

The arrangements disclosed herein relate to systems, apparatus, methods, and non-transitory computer readable media for Secure Node Exchange Attribute-based Keys (SNEAK) including secure exchange of sensitive message elements between sequential message nodes using attribute-based key management. Each message node can access none, one, some, or all encrypted message elements based on assigned attributes of that message node. A key management node provides key exchange for each Content Encryption Key (CEK) used to protect the message elements based on attributes of the message nodes.