Cryptographic Key Metadata Access via Unidirectional Link

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic key management systems hinder administrative management and attestation processes for cryptographic key owners due to limited access to secure key data storage systems, making it difficult for them to track key expiries and comply with periodic attestation requirements.

Innovation Solution

Implementing a system that allows cryptographic key owners to access metadata about their keys through a user-accessible metadata database, logically isolated from the key data storage system, enabling proactive notifications for key expiries and attestation requirements without compromising security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access to secure key data storage systems is severely limited to dedicated key management personnel only, then security protection is improved, but administrative management and attestation processes for cryptographic key owners are hindered

Engineering Contradiction:
Improvesecurity protectionVSAvoidadministrative management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments key management functions by creating two distinct interfaces: a secure key data storage system accessible only to key management personnel, and a separate key metadata database accessible to key owners. This segmentation allows security-sensitive operations to remain restricted while enabling administrative management through the metadata interface.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key metadata database acts as an intermediary between key owners and the secure key data storage system. It provides key owners with visibility and management capabilities for their cryptographic keys without requiring direct access to the secure storage system, thus maintaining security while enabling administrative functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic key owners lack access to secure key data storage systems, then security is maintained, but key owners cannot track key expiries or comply with periodic attestation requirements

Engineering Contradiction:
ImprovesecurityVSAvoidvisibility of key status
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system creates a copy of key information in the form of metadata that is stored in a separately accessible database. This metadata copy contains essential key status information including expiry dates and attestation requirements, allowing key owners to monitor their keys without accessing the secure storage system.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The key metadata database serves as an intermediary that provides key owners with the information they need to track key expiries and comply with attestation requirements. It translates secure storage data into accessible metadata that enables key owners to perform administrative tasks while security restrictions remain in place.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manual processes are used for attestation and expiry management, then security restrictions are maintained, but the processes become unwieldy and inefficient

Engineering Contradiction:
Improvesecurity restrictionsVSAvoidattestation process efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The key metadata database enables key owners to perform attestation and expiry management themselves without requiring manual intervention from key management personnel. Key owners can independently review their key status, track expiries, and complete attestation requirements through the accessible metadata interface.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system provides automated feedback to key owners about their cryptographic key status, including expiry warnings and attestation requirements. This feedback mechanism enables key owners to take timely action without manual follow-up, significantly improving the efficiency of attestation processes while maintaining security restrictions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240064013A1Secure cryptographic key management
Publication Date: 2024.02.22 ROYAL BANK OF CANADA
  • US20240064013A1 patent drawing
  • US20240064013A1 patent drawing
  • US20240064013A1 patent drawing

AI summary

A method of making cryptographic key metadata available to key owners while protecting the integrity of the cryptographic key metadata comprises extracting key metadata from a metadata storage on a key data storage system. The metadata storage is logically isolated from a sensitive cryptographic data storage on the key data storage system. The method further comprises transmitting, by unidirectional communication, the extracted key metadata to a user-accessible metadata database that is separate and distinct from the metadata storage on the key data storage system. The method identifies, from the user-accessible metadata database, user-specific metadata for at least one cryptographic key associated with an authorized user associated with the at least one cryptographic key, and communicates the identified user-specific metadata to the authorized user.