Complex Policy Encryption Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption key management systems face challenges due to unsynchronized procedural controls, loose key management, and the inability of simple Boolean operations to effectively evaluate complex encryption key attributes, leading to potential breakdowns in communication security.

Innovation Solution

Implementing complex policies such as EQUAL, ONE-OF, MEMBER OF, NULL, NOT-NULL, GREATER-THAN, GREATER-OR-EQUAL-TO, LESS-THAN, and LESS-OR-EQUAL-TO policies to evaluate encryption key attributes, allowing for more sophisticated management and distribution of encryption keys within a hierarchical structure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If simple Boolean operations are used to evaluate encryption key attributes, then the evaluation process is simple and fast, but the ability to flexibly and completely evaluate descriptive string attributes is insufficient

Engineering Contradiction:
Improveevaluation process simplicityVSAvoidattribute evaluation flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent transforms the evaluation parameters from simple Boolean operations to complex policy operations that include string matching, pattern recognition, and hierarchical evaluation. This allows the system to evaluate descriptive string attributes (such as key names, passwords, and metadata) with greater flexibility while maintaining a structured evaluation framework through the hierarchical policy structure.

Inventive Principle:
Principle #35Parameter changes

2Extent of automation

If device-level encryption key management is implemented, then device autonomy is improved, but procedural synchronization with centralized communication management deteriorates

Engineering Contradiction:
Improvedevice autonomyVSAvoidprocedural synchronization
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where device-level key management operations are evaluated against centralized policies. The hierarchical policy structure allows centralized communication management to define evaluation criteria, while device-level operations provide feedback on key attributes. This synchronization ensures that autonomous device operations align with centralized security requirements through continuous policy evaluation and enforcement.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If loose controls of encryption keys are implemented, then key management flexibility is improved, but communication security deteriorates

Engineering Contradiction:
Improvekey management flexibilityVSAvoidcommunication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic control of encryption keys through hierarchical policies that can adapt to different contexts and requirements. The system allows flexible key management operations (generation, distribution, evaluation, revocation) while enforcing security constraints through policy evaluation. The dynamic nature of the policy structure enables security controls to adjust based on key attributes, operational context, and hierarchical relationships, maintaining both flexibility and security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11537195B2Policy-enabled encryption keys having complex logical operations
Publication Date: 2022.12.27 FORNETIX LLC
  • US11537195B2 patent drawing
  • US11537195B2 patent drawing
  • US11537195B2 patent drawing

AI summary

Examples described herein relate to a system for orchestrating a security object, including a memory and processor configured to define a plurality of complex policies in a database, wherein the complex policies comprises one or more of EQUAL policy, ONE-OF policy, MEMBER OF policy, NULL policy, NOT-NULL policy, GREATER-THAN policy, GREATER-THAN-OR-EQUAL-TO policy, LESS-THAN policy, or LESS-THAN-OR-EQUAL-TO policy, receive the security object and at least one object attribute associated with the security object, determine acceptability of the security object based, at least in part, on the at least one object attribute and at least one of the plurality of complex policies corresponding to the at least one object attribute, and distribute the security object to at least one communication device associated with the processor when the security object is determined to be acceptable, wherein the at least one communication device establishes communication based, at least in part, on the security object.