Cryptographic Key Metadata Flag for Integrity Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to adequately safeguard cryptographic keys from inadvertent or malicious deletion or modification, particularly for long-term keys that require retention over decades, as usage tracking and key encryption approaches have limitations.

Innovation Solution

A designated storage field is established within the cryptographic key's metadata or resource access control database to indicate whether the key can be deleted or modified, preventing unauthorized changes by setting a flag that ensures the key's integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic keys are stored without special protection mechanisms, then ease of access and operation is improved, but reliability and security against deletion or modification deteriorates

Engineering Contradiction:
Improveease of key accessVSAvoidkey integrity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by setting a deletion indicator flag in the key token metadata before the cryptographic key is created or imported. This pre-configured flag prevents future deletion or modification operations, ensuring key integrity without requiring continuous active protection mechanisms during normal operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses an intermediary approach by introducing a deletion indicator flag as a metadata field within the key token. This flag acts as a mediator between the cryptographic key and deletion operations, allowing the system to distinguish between legitimate key management operations and unauthorized deletion attempts, thus protecting key integrity while maintaining operational ease.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If usage tracking is implemented to monitor key usage, then security monitoring is improved, but device complexity and operational overhead increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security monitoring function from complex continuous usage tracking systems. Instead of implementing comprehensive usage monitoring infrastructure, the solution extracts only the essential protection mechanism - the deletion indicator flag in key token metadata - which provides security monitoring capability with minimal system complexity and overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If key encryption approaches are used to protect keys, then security against unauthorized access is improved, but ease of operation and key management complexity deteriorates

Engineering Contradiction:
Improveunauthorized access protectionVSAvoidkey management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies the inversion principle by instead of encrypting the key to protect it, the solution inverts the approach by embedding a deletion indicator flag directly in the key token metadata. This allows the key to remain accessible and manageable while the flag provides the protection mechanism, eliminating the operational complexity associated with key encryption and management.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS11652626B2Safeguarding cryptographic keys from modification or deletion
Publication Date: 2023.05.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11652626B2 patent drawing
  • US11652626B2 patent drawing
  • US11652626B2 patent drawing

AI summary

Aspects of the invention include generating a cryptographic key to restrict access to a resource. The cryptographic key being defined by a key token. An exemplary method includes designating a storage field in metadata of the key token, in metadata of a cryptographic key data set record that includes the key token, or in a resource access control database that controls use of the cryptographic key for inclusion of an indicator that the cryptographic key may or may not be deleted or modified. The indicator in the designated storage field is set to indicate whether or not the cryptographic key may be deleted or modified.