Certificate Authority System for Granular Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing certificate-based access controls lack granularity, becoming an 'all or none' proposition when a device uses the same cryptographic certificate across multiple contexts or enforces multiple access factors, such as biometric factors, leading to inadequate access control precision.
Innovation Solution
A certificate authority system that generates and manages certificates signed by a keymaster, capable of distinguishing between applications and processes, indicating specific access privileges and determining approved accessors based on contextual factors, allowing for more granular access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a device uses the same cryptographic certificate across multiple contexts, then certificate-based authentication is simplified, but access control granularity is lost becoming an all or none proposition
Solution Approach 1:
The patent segments access control by creating separate accessor certificates for different applications and contexts. Each certificate contains specific access privileges tailored to particular apps, allowing fine-grained control where different apps receive different levels of access to device resources, thereby resolving the contradiction between authentication simplicity and access control granularity.
2Reliability
If multiple access factors such as biometric factors are enforced, then security is improved, but access control precision becomes inadequate due to lack of granularity
Solution Approach 1:
The patent applies local quality by embedding context-specific access privileges within each accessor certificate. Each certificate is tailored to specific applications, resources, and conditions, allowing different security requirements to be applied locally to different access scenarios rather than using a uniform security approach, thus achieving both strong security and precise access control.
3Ease of operation
If a cryptographic certificate shows possession of a private key associated with a full set of access privileges, then authentication is straightforward, but the certificate lacks granularity for specific access contexts
Solution Approach 1:
The patent introduces dynamics by making access privileges contextual and application-specific within each certificate. Instead of static full-access certificates, the system dynamically assigns appropriate access levels to different apps based on their specific needs, allowing the same device to provide different access rights to different applications while maintaining straightforward certificate-based authentication.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A method for access control on an electronic device includes the step of generating, by the electronic device, a certificate signed by a keymaster, the electronic device running an operating system, the operating system capable of distinguishing between applications and application processes and providing an execution environment. The method also includes the steps of indicating, by the certificate, an access privilege for an approved accessor and receiving from an application, a request subject to the access privilege indicated by the certificate. The method further includes the steps of identifying the application from which the request subject to the access privilege was received and determining, using the certificate, whether the application is an approved accessor.