Attribute-Based Key Management for Granular Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional key management systems lack scalability and granular access control, allowing unauthorized access to data encryption keys when users or applications can access the key encryption key.

Innovation Solution

Implementing a key management system that associates key encryption keys with policies and attributes, where access to data encryption keys is controlled by matching attributes with specific rules, allowing for tailored access based on user or application credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional key management systems use user credentials to access key encryption keys, then access control is simple and straightforward, but the system lacks scalability and granular access control for multiple users and applications

Engineering Contradiction:
Improvescalability to multiple users and applicationsVSAvoidaccess control mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments access control by introducing attributes that divide users and applications into distinct groups with different permission levels. Each attribute represents a specific characteristic or role, allowing the system to differentiate between multiple users and applications granularly while maintaining scalability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to access control by incorporating attributes as an additional layer beyond traditional user credentials. This attribute dimension enables the system to handle multiple users and applications simultaneously with fine-grained control, transforming the access control model from flat to multi-dimensional.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If the system allows users to access key encryption keys with user credentials, then access is easy to obtain, but unauthorized access to data encryption keys becomes a security risk

Engineering Contradiction:
Improveease of accessing key encryption keysVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by assigning specific attributes to different users and applications, giving each entity customized access rights based on its specific needs and security requirements. This allows easy access for authorized users while restricting access for others, balancing ease of operation with data security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces attributes as an intermediary layer between user credentials and key encryption keys. This intermediary enables the system to verify not just identity but also authorization context, allowing easy access for legitimate users while preventing unauthorized access to data encryption keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the system provides broad access to key encryption keys for simplicity, then ease of operation is improved, but granular access control and fine-tuned security are lost

Engineering Contradiction:
Improvesimplicity of access controlVSAvoidgranularity of access control
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent makes the access control system dynamic by allowing attributes to be added, removed, or modified based on changing security requirements. This enables the system to maintain simplicity when broad access is needed while providing granular control when specific security conditions arise, adapting to different operational contexts.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11133926B2Attribute-based key management system
Publication Date: 2021.09.28 PAYPAL INC
  • US11133926B2 patent drawing
  • US11133926B2 patent drawing
  • US11133926B2 patent drawing

AI summary

Systems and methods for encrypting and decrypting a data encryption key are provided. A data encryption key used to encrypt data is encrypted using a first asymmetric key and a policy. The policy includes rules that correspond to attributes. A second asymmetric key is associated with the attributes. To decrypt the encrypted data encryption key, the attributes are used to identify the second asymmetric key. The attributes are also used to pass the rules in the policy included in the encrypted data encryption key. If the attributes pass the rules in the policy, the encrypted data encryption key is decrypted. The decrypted data encryption key can then decrypt the encrypted data.