Contextual Key Derivation for Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cryptographic access control mechanisms rely solely on key possession, which is insufficient for sophisticated access control, as they can be circumvented by compromised executable rules, lacking the same level of security as underlying cryptographic techniques.

Innovation Solution

An enhanced cryptographic access control mechanism that integrates contextual data, such as location, time, and environmental sensors, to create cryptographic keys, ensuring access is granted only when specific conditions are met, thereby embedding access criteria into the cryptographic technique.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cryptographic access control mechanisms are used that rely solely on key possession, then the system is simple to operate, but the security is insufficient and can be circumvented by compromised executable rules

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transitions from unidimensional key possession checks to multidimensional contextual verification by incorporating spatial location, temporal time windows, and environmental sensor data into the cryptographic access control mechanism, thereby enhancing security through additional verification dimensions

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent creates a composite access control system that integrates multiple types of data (cryptographic keys, location data, time data, sensor data) into a unified contextual key derivation process, where the combination of diverse data sources provides enhanced security compared to individual components alone

Inventive Principle:
Principle #40Composite materials

2Reliability

If contextual data is integrated into cryptographic key creation to embed access criteria, then more precise access controls are achieved, but the device complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidcryptographic system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the access control logic directly into the cryptographic key derivation process by combining contextual data (location, time, sensors) with the key generation algorithm, eliminating the need for separate executable rules and reducing the attack surface while maintaining precise access control

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces contextual data as an intermediary element that mediates between the cryptographic key and the access decision, where the contextual key derivation function acts as a mediator that automatically enforces access policies without requiring separate executable rule sets

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11329812B2Constrained key derivation in miscellaneous dimensions
Publication Date: 2022.05.10 RED HAT INC
  • US11329812B2 patent drawing
  • US11329812B2 patent drawing
  • US11329812B2 patent drawing

AI summary

The technology disclosed herein may enable a client to access a protected resource using cryptographic keys that are based on contextual data of a device. An example method may include: determining contextual data of a computing device; transforming the contextual data in view of conversion data associated with the computing device, wherein the conversion data causes a set of alternate contextual data values to transform to a specific cryptographic value; creating, by a processing device, a cryptographic key in view of the transformed contextual data; and using the cryptographic key to enable access to a protected resource.