Certificate Authority System for Granular Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing certificate-based access controls lack granularity, becoming an 'all or none' proposition when a device uses the same cryptographic certificate across multiple contexts or enforces multiple access factors, such as biometric factors, leading to inadequate access control precision.

Innovation Solution

A certificate authority system that generates and manages certificates signed by a keymaster, capable of distinguishing between applications and processes, indicating specific access privileges and determining approved accessors based on contextual factors, allowing for more granular access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a device uses the same cryptographic certificate across multiple contexts, then certificate-based authentication is simplified, but access control granularity is lost becoming an all or none proposition

Engineering Contradiction:
Improvecertificate-based authentication simplicityVSAvoidaccess control granularity
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent segments access control by creating separate accessor certificates for different applications and contexts. Each certificate contains specific access privileges tailored to particular apps, allowing fine-grained control where different apps receive different levels of access to device resources, thereby resolving the contradiction between authentication simplicity and access control granularity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple access factors such as biometric factors are enforced, then security is improved, but access control precision becomes inadequate due to lack of granularity

Engineering Contradiction:
Improvesecurity strengthVSAvoidaccess control precision
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The patent applies local quality by embedding context-specific access privileges within each accessor certificate. Each certificate is tailored to specific applications, resources, and conditions, allowing different security requirements to be applied locally to different access scenarios rather than using a uniform security approach, thus achieving both strong security and precise access control.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If a cryptographic certificate shows possession of a private key associated with a full set of access privileges, then authentication is straightforward, but the certificate lacks granularity for specific access contexts

Engineering Contradiction:
Improveauthentication straightforwardnessVSAvoidcertificate access control granularity
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent introduces dynamics by making access privileges contextual and application-specific within each certificate. Instead of static full-access certificates, the system dynamically assigns appropriate access levels to different apps based on their specific needs, allowing the same device to provide different access rights to different applications while maintaining straightforward certificate-based authentication.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3566162B1Apparatus and method for certificate authority for certifying accessors
Publication Date: 2021.01.27 SAMSUNG ELECTRONICS CO LTD
  • EP3566162B1 patent drawingFigure 1
  • EP3566162B1 patent drawingFigure 2~3
  • EP3566162B1 patent drawingFigure 4

AI summary

A method for access control on an electronic device includes the step of generating, by the electronic device, a certificate signed by a keymaster, the electronic device running an operating system, the operating system capable of distinguishing between applications and application processes and providing an execution environment. The method also includes the steps of indicating, by the certificate, an access privilege for an approved accessor and receiving from an application, a request subject to the access privilege indicated by the certificate. The method further includes the steps of identifying the application from which the request subject to the access privilege was received and determining, using the certificate, whether the application is an approved accessor.