Boolean Expression Access Control for Cryptographic Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cryptographic key management techniques are cumbersome due to the need for large numbers of access control keys, especially when dealing with valuable data that requires encryption and decryption, often resulting in complex storage and communication processes.

Innovation Solution

Implementing a data protection system that uses a monotonic Boolean expression-based access control rule to manage cryptographic keys, where each atom in the rule corresponds to a protector key, allowing only authorized entities to decrypt the data by generating and using fractional keys through efficient key derivation schemes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cryptographic key management techniques are used to protect valuable data, then data security is improved, but device complexity and key management burden increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the access control rule into multiple atoms, where each atom corresponds to a specific cryptographic key. This segmentation allows the system to manage access control by dividing the complex rule into manageable components, each handled by a dedicated key, thereby reducing overall key management complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal access control rule format that can be applied across different data items and scenarios. The Boolean expression-based rule system provides multi-functionality, allowing a single framework to handle various access control needs without requiring separate key management procedures for each case, thus reducing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If a large number of cryptographic keys are used to support access control for multiple data items, then access control flexibility is improved, but storage requirements and communication overhead increase

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidnumber of cryptographic keys
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple access control requirements into a single Boolean expression that evaluates to true or false. This combining approach allows the system to determine access rights for multiple data items using a unified rule set, reducing the number of separate keys needed while maintaining the flexibility to handle different access control scenarios.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the parameter representation from individual keys to a Boolean expression format. By representing access control rules as logical expressions that can be evaluated dynamically, the system reduces the quantity of keys needed while maintaining adaptability through parameter evaluation rather than key multiplication.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If each data item is encrypted and decrypted separately with independent access control, then data security is improved, but processing time and operational complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining access control rules as Boolean expressions before data access is needed. These rules are established in advance and can be evaluated quickly during data access operations, avoiding the need for complex real-time key selection and reducing processing time while maintaining security through pre-established access control frameworks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9058497B2Cryptographic key management
Publication Date: 2015.06.16 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9058497B2 patent drawing
  • US9058497B2 patent drawing
  • US9058497B2 patent drawing

AI summary

Cryptographic key management techniques are described. In one or more implementations, an access control rule is read that includes a Boolean expression having a plurality of atoms. The cryptographic keys that corresponds each of the plurality of atoms in the access control rule are requested. One or more cryptographic operations are then performed on data using one or more of the cryptographic keys.