Context-Based Security System for Dynamic Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data security systems are inadequate in managing keys based on individual users, leading to vulnerabilities such as compromised private keys in asymmetric key-based infrastructures and limited scalability in symmetric key-based systems, especially in multi-party communications and dynamic environments.

Innovation Solution

A Context-Based Security System (CBSS) that uses context-based encryption keys generated based on environmental parameters, such as user ID, application program, and session ID, to secure data, allowing for unique keys for each instance of data and enabling role-based access control, auditing, and flexible key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric key-based infrastructure (public-private key system) is used for data security, then data encryption and decryption capability is provided, but key management complexity increases and private key compromise vulnerability arises

Engineering Contradiction:
Improvedata securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key management service as an intermediary that centralizes the management of cryptographic keys. This service handles key generation, distribution, rotation, and revocation, eliminating the need for individual users to manually manage their own keys. The intermediary abstracts the complexity of asymmetric key infrastructure while maintaining security through centralized control and automated key lifecycle management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements automated key generation and rotation capabilities where keys are automatically created, distributed, and renewed without human intervention. The key management service autonomously handles key lifecycle events, reducing operational complexity and minimizing human error in key management processes.

Inventive Principle:
Principle #25Self-service

2Device complexity

If symmetric key-based infrastructure is used for data security, then key management is simplified, but scalability is limited in multi-party communications and dynamic environments

Engineering Contradiction:
Improvekey management complexityVSAvoidscalability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic key management where cryptographic keys can be automatically created, distributed, rotated, and revoked based on real-time requirements. The system adapts to changing communication patterns and user needs by dynamically provisioning keys for new users or sessions without requiring manual reconfiguration, enabling seamless scaling in multi-party environments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The key management service provides a universal platform that handles both symmetric and asymmetric key operations, supporting multiple communication scenarios including one-to-one, one-to-many, and many-to-many communications. The system universally manages key lifecycles across different cryptographic algorithms and communication protocols, providing scalable support for diverse multi-party communication needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If keys are tied to persons in conventional infrastructure, then individual user security is maintained, but dynamic scaling and key changes become difficult

Engineering Contradiction:
Improveuser-specific securityVSAvoiddynamic scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the relationship between users and cryptographic keys by introducing a hierarchical key management structure. Instead of directly tying keys to persons, the system segments key management into user-specific key pairs managed by a centralized service. This segmentation allows individual user security to be maintained while enabling centralized control for dynamic key rotation and scaling operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic key binding where cryptographic keys are temporarily associated with user sessions rather than permanently tied to user identities. Keys can be dynamically created, assigned, and revoked based on session requirements, allowing users to change keys without affecting their underlying user accounts. This dynamic approach maintains user-specific security while enabling flexible scaling and key management.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10095874B1Systems and methods for providing information security using context-based keys
Publication Date: 2018.10.09 IONIC SECURITY
  • US10095874B1 patent drawing
  • US10095874B1 patent drawing
  • US10095874B1 patent drawing

AI summary

Systems and methods for securing or encrypting data or other information arising from a user's interaction with software and/or hardware, resulting in transformation of original data into ciphertext. Generally, the ciphertext is generated using context-based keys that depend on the environment in which the original data originated and/or accessed. The ciphertext can be stored in a user's storage device or in an enterprise database (e.g., at-rest encryption), or shared with other users (e.g., cryptographic communication). Use of context-based encryption keys enables key association with individual data elements, as opposed to public-private key pairs, or use of conventional user-based or system-based keys. In scenarios wherein data is shared by a sender with other users, the system manages the rights of users who are able to send and/or access the sender's data according to pre-defined policies/roles.