Certificate-Based Distributed Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information rights management systems are limited in their ability to manage objects that cross security boundaries and enforce policies uniformly across different security domains, failing to effectively manage attributes of objects within a single security boundary.
Innovation Solution
A certificate-based distributed policy system where a policy server generates and validates object certificates using public key cryptography, incorporating a data structure with serialized public properties, hashes, and signatures, allowing for secure policy enforcement across communication boundaries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing information rights management systems are used to enforce policies within a single security boundary, then policy enforcement is effective for that specific boundary, but the system cannot manage objects that cross multiple security boundaries or provide unified policy management across different domains
Solution Approach 1:
The patent introduces a certificate as an intermediary object that mediates between the object and multiple security boundaries. The certificate contains the object's identity and associated policy information, allowing the object to be recognized and managed across different security domains without requiring each domain to understand the object's internal structure. This intermediary enables unified policy management while maintaining the independence of each security boundary.
Solution Approach 2:
The patent creates a universal certificate structure that can be used across multiple security boundaries and different types of objects. The certificate serves multiple functions: it identifies the object, carries policy information, enables verification of object integrity, and facilitates cross-boundary recognition. This multi-functional design allows a single system architecture to handle diverse objects across different security domains without requiring domain-specific customization.
2Reliability
If persistent usage policies are applied to protect information after access, then information security is maintained for authorized users, but the system lacks flexibility to manage attributes and enforce policies uniformly across different security domains
Solution Approach 1:
The patent applies preliminary action by embedding policy information and object attributes into the certificate before the object crosses security boundaries. The certificate is generated in advance with all necessary policy constraints and object metadata, allowing receiving systems to enforce policies immediately upon receipt without needing to query the original system. This preliminary preparation enables both secure information protection and uniform policy management across distributed security domains.
3Adaptability or versatility
If a unified framework is created to manage objects across security boundaries, then adaptability and unified policy management are improved, but the complexity of certificate generation, validation, and management increases
Solution Approach 1:
The patent uses copying by creating a certificate that contains a serialized representation of the object's public properties and policy information. Rather than managing the actual object across security boundaries, the system manages copies of the object's essential attributes and policy constraints in the certificate. This copying approach simplifies management because the certificate is a self-contained data structure that can be independently validated and processed without requiring access to the original object or complex inter-system coordination.
Data Source
AI summary
An apparatus and a method for a certificate-based distributed policy system is described. A policy server receives over a communication channel a data structure associated with an object to be managed across a communication boundary between a client and the policy server. The policy server generates an object certificate upon validation of the object and validation of an initiator of the object. The data structure includes a serialized representation of public properties of the object, a hash of the object in a canonical serialized form, and a signature of the public properties and hash using the initiator's private key.


