Attribute-Based Key Management for Granular Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional key management systems lack scalability and granular access control, allowing unauthorized access to data encryption keys when users or applications can access the key encryption key.
Innovation Solution
Implementing a key management system that associates key encryption keys with policies and attributes, where access to data encryption keys is controlled by matching attributes with specific rules, allowing for tailored access based on user or application credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional key management systems use user credentials to access key encryption keys, then access control is simple and straightforward, but the system lacks scalability and granular access control for multiple users and applications
Solution Approach 1:
The patent segments access control by introducing attributes that divide users and applications into distinct groups with different permission levels. Each attribute represents a specific characteristic or role, allowing the system to differentiate between multiple users and applications granularly while maintaining scalability.
Solution Approach 2:
The patent adds a new dimension to access control by incorporating attributes as an additional layer beyond traditional user credentials. This attribute dimension enables the system to handle multiple users and applications simultaneously with fine-grained control, transforming the access control model from flat to multi-dimensional.
2Ease of operation
If the system allows users to access key encryption keys with user credentials, then access is easy to obtain, but unauthorized access to data encryption keys becomes a security risk
Solution Approach 1:
The patent applies local quality by assigning specific attributes to different users and applications, giving each entity customized access rights based on its specific needs and security requirements. This allows easy access for authorized users while restricting access for others, balancing ease of operation with data security.
Solution Approach 2:
The patent introduces attributes as an intermediary layer between user credentials and key encryption keys. This intermediary enables the system to verify not just identity but also authorization context, allowing easy access for legitimate users while preventing unauthorized access to data encryption keys.
3Ease of operation
If the system provides broad access to key encryption keys for simplicity, then ease of operation is improved, but granular access control and fine-tuned security are lost
Solution Approach 1:
The patent makes the access control system dynamic by allowing attributes to be added, removed, or modified based on changing security requirements. This enables the system to maintain simplicity when broad access is needed while providing granular control when specific security conditions arise, adapting to different operational contexts.
Data Source
AI summary
Systems and methods for encrypting and decrypting a data encryption key are provided. A data encryption key used to encrypt data is encrypted using a first asymmetric key and a policy. The policy includes rules that correspond to attributes. A second asymmetric key is associated with the attributes. To decrypt the encrypted data encryption key, the attributes are used to identify the second asymmetric key. The attributes are also used to pass the rules in the policy included in the encrypted data encryption key. If the attributes pass the rules in the policy, the encrypted data encryption key is decrypted. The decrypted data encryption key can then decrypt the encrypted data.


