Boolean Expression Access Control for Cryptographic Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cryptographic key management techniques are cumbersome due to the need for large numbers of access control keys, especially when dealing with valuable data that requires encryption and decryption, often resulting in complex storage and communication processes.
Innovation Solution
Implementing a data protection system that uses a monotonic Boolean expression-based access control rule to manage cryptographic keys, where each atom in the rule corresponds to a protector key, allowing only authorized entities to decrypt the data by generating and using fractional keys through efficient key derivation schemes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional cryptographic key management techniques are used to protect valuable data, then data security is improved, but device complexity and key management burden increase significantly
Solution Approach 1:
The patent segments the access control rule into multiple atoms, where each atom corresponds to a specific cryptographic key. This segmentation allows the system to manage access control by dividing the complex rule into manageable components, each handled by a dedicated key, thereby reducing overall key management complexity while maintaining security.
Solution Approach 2:
The patent implements a universal access control rule format that can be applied across different data items and scenarios. The Boolean expression-based rule system provides multi-functionality, allowing a single framework to handle various access control needs without requiring separate key management procedures for each case, thus reducing complexity.
2Adaptability or versatility
If a large number of cryptographic keys are used to support access control for multiple data items, then access control flexibility is improved, but storage requirements and communication overhead increase
Solution Approach 1:
The patent merges multiple access control requirements into a single Boolean expression that evaluates to true or false. This combining approach allows the system to determine access rights for multiple data items using a unified rule set, reducing the number of separate keys needed while maintaining the flexibility to handle different access control scenarios.
Solution Approach 2:
The patent changes the parameter representation from individual keys to a Boolean expression format. By representing access control rules as logical expressions that can be evaluated dynamically, the system reduces the quantity of keys needed while maintaining adaptability through parameter evaluation rather than key multiplication.
3Reliability
If each data item is encrypted and decrypted separately with independent access control, then data security is improved, but processing time and operational complexity increase
Solution Approach 1:
The patent implements preliminary action by pre-defining access control rules as Boolean expressions before data access is needed. These rules are established in advance and can be evaluated quickly during data access operations, avoiding the need for complex real-time key selection and reducing processing time while maintaining security through pre-established access control frameworks.
Data Source
AI summary
Cryptographic key management techniques are described. In one or more implementations, an access control rule is read that includes a Boolean expression having a plurality of atoms. The cryptographic keys that corresponds each of the plurality of atoms in the access control rule are requested. One or more cryptographic operations are then performed on data using one or more of the cryptographic keys.


