Cryptographic Attribute-Based Access Control for Dynamic Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Attribute-based Access Control (ABAC) models lack cryptographic implementation, making them insecure in open environments where access policies and attribute assignments can be tampered with or forged, failing to ensure the correctness and security of access authorization.

Innovation Solution

A cryptographic attribute-based access control system that encrypts objects and uses dynamic security tokens to enforce access policies, ensuring only authorized access by matching attribute tokens with cryptographic policies, supporting scalable and real-time attribute assignment and policy generation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If non-cryptographic ABAC models are used for access control, then the system is easier to implement and operate, but the security is compromised as policies and attributes can be tampered with or forged in open environments

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional non-cryptographic access control mechanisms with cryptographic primitives including attribute-based encryption (ABE), digital signatures, and hash functions. This substitution transforms the access control system from a trust-based model to a mathematically secure model, where security is guaranteed by cryptographic proofs rather than administrative controls.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces cryptographic intermediaries such as attribute tokens, policy tokens, and decryption keys that mediate between subjects and objects. These cryptographic intermediaries enable secure attribute verification and policy enforcement without requiring direct trust between system components, thus enhancing security while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If fixed access policies are embedded in ciphertext using Attribute-based Encryption, then security is improved, but the system loses scalability as policies cannot be changed dynamically

Engineering Contradiction:
ImprovesecurityVSAvoidpolicy scalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms static access policies into dynamic structures by introducing policy tokens that can be generated, updated, and revoked independently of the underlying ciphertext. The system uses time-varying parameters and dynamic attribute assignments to enable flexible policy changes while maintaining cryptographic security guarantees.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the access control system into independent modular components: attribute management module, policy management module, and decryption module. This segmentation allows policies to be modified and updated independently without affecting the core encryption scheme, thereby achieving both security and scalability.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If traditional ABAC models are used without cryptographic implementation, then the system is more flexible and easier to operate, but the correctness of access authorization cannot be guaranteed in open environments

Engineering Contradiction:
Improveoperational flexibilityVSAvoidauthorization correctness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces operational trust mechanisms with cryptographic verification mechanisms. Instead of relying on administrative oversight or manual verification, the system uses digital signatures and cryptographic proofs to automatically verify attribute authenticity and policy compliance, ensuring authorization correctness while maintaining operational flexibility.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements cryptographic feedback mechanisms where the system continuously verifies attribute tokens and policy tokens against established cryptographic policies. This feedback loop ensures that any attempted tampering or forgery is detected and rejected, guaranteeing authorization correctness in open environments.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11425171B2Method and system for cryptographic attribute-based access control supporting dynamic rules
Publication Date: 2022.08.23 UNIV OF SCI & TECH BEIJING
  • US11425171B2 patent drawing
  • US11425171B2 patent drawing

AI summary

The present invention mainly relates to the field of information technology, and specifically to a method and system for cryptographic attribute-based access control supporting dynamic rules. In the system, the protected object is stored in an encrypted form, only the access request satisfying the access policy in attribute-based access control can be authorized to decrypt the object, which ensures that the access to data in an unsecure environment can be authorized according to a security policy, and supports dynamic policy and real-time authorization of attributes. The method and system for cryptographic attribute-based access control supporting dynamic rules in this invention have already separated from traditional encryption system framework, are totally new attribute-based access control model, method and system supporting cryptographic determination, can achieve more secure, diversified, dynamic and flexible access authorization, are suitable for large-scale organizations or information systems, and can be applied to the environments such as Cloud computing, grid computing, and distributed computing.