Cyber-physical Context-dependent Cryptographic Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic key management techniques face challenges in securely managing access keys, especially in enterprise settings where different access rights are required based on physical context, and the sheer number of keys and shares needed increases security risks and complexity.
Innovation Solution
A method and system for cryptographic key management that divides a key into portions based on pre-encryption contextual data from devices, encrypts these portions using cyber-physical context, and distributes them for storage and retrieval, allowing reconstruction of the key with post-encryption contextual data, enhancing security by integrating physical context into digital access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secret sharing is used to protect access keys by splitting them into multiple shares, then key security is improved, but the number of key shares that need to be stored and secured increases, leading to increased complexity and potential security risks
Solution Approach 1:
The access key is divided into multiple shares using secret sharing schemes, where each share is distributed to different devices. This segmentation ensures that no single device holds the complete key, improving security while the systematic distribution manages the complexity of multiple shares.
Solution Approach 2:
The patent introduces a new dimension of physical context (location, device attributes) to the key management system. By binding key shares to specific physical contexts, the system manages the complexity of multiple shares through contextual organization rather than merely increasing the number of secure storage locations.
2Adaptability or versatility
If multiple access keys are created for different situations and devices in enterprise settings, then access control flexibility is improved, but the number of keys and shares that need to be securely stored increases dramatically
Solution Approach 1:
Each key share is bound to specific local qualities or attributes of devices and physical contexts (location, device type, user role). This allows the system to provide different access levels for different situations without creating separate keys for every possible scenario, managing complexity through contextual differentiation rather than quantity.
Solution Approach 2:
The patent creates a universal key management framework where a single set of key shares can serve multiple access control purposes through contextual evaluation. The same key share can be used in different situations by evaluating whether the current physical context matches the conditions under which the share was created, reducing the total number of keys needed.
3Reliability
If key shares are stored in highly secured locations to prevent theft, then key protection is improved, but the system becomes more vulnerable to attacks on these concentrated secure storage points
Solution Approach 1:
By segmenting the key into multiple shares and distributing them across different devices and locations, the system eliminates single points of failure. An attacker would need to compromise multiple distributed locations simultaneously, significantly reducing vulnerability compared to concentrating all key shares in a single secure location.
Solution Approach 2:
The patent introduces physical context (location, device attributes, environmental factors) as an intermediary layer between the key shares and the decryption process. Even if an attacker obtains key shares, the contextual binding acts as a mediator that prevents unauthorized reconstruction of the access key without the proper physical context.
Data Source
AI summary
A method for cryptographic key management for managing access control is provided. A key is divided into a plurality of portions of the key. Pre-encryption contextual data is received for each of a plurality of devices. The pre-encryption contextual data indicates at least one attribute of a respective device of the plurality of devices before an encryption of the plurality of portions of the key is performed. The plurality of portions of the key are encrypted based at least on the pre-encryption contextual data of the plurality of devices to make the plurality of the portions of the key dependent at least on contextual data corresponding pre-encryption contextual data. Each of the plurality of encrypted portions of the key is distributed to a respective device of the plurality of devices for storage and retrieval.


