Cryptographic Indirection for Selective Digital Credential Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securely sharing digital credentials among multiple entities are inadequate, particularly in scenarios requiring selective and revocable access, as they often involve full disclosure or lack support for many-to-many relationships and do not address the need for transparent and secure credential sharing in network access scenarios.
Innovation Solution
A method and system that utilize cryptographic indirection techniques to securely and selectively share digital credentials among entities by generating a shared secret based on a common secret and entity-specific strings, allowing controlled access and revocation of credentials, incorporating algorithms like hashing, concatenation, and symmetric cryptography for protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is encoded using various techniques to prevent unauthorized access, then security is improved, but the ability to securely share information with another entity becomes more difficult
Solution Approach 1:
The patent introduces a credential sharing mechanism that acts as an intermediary between the data owner and the accessing entity. Instead of directly sharing encoded data or credentials, the system uses a credential store with protection means that mediates access control. The sharing entity can selectively grant access to specific credentials without disclosing the actual credential values, thus maintaining security while enabling controlled information sharing.
2Reliability
If the Microsoft encrypting file system is used to allow an entity to specify which registered entities may access encoded information, then file sharing security is improved, but the mechanism does not support multiple entities sharing a common workspace with selective encoding of discrete files
Solution Approach 1:
The patent creates a universal credential sharing framework that can handle multiple sharing scenarios including one-to-many, many-to-many, and selective credential sharing. The credential store with protection means serves multiple functions: storing credentials, managing access rights, enabling selective sharing, and supporting revocation. This multi-functional system replaces the limited file-level sharing mechanism with a versatile credential-based access control system.
3Ease of operation
If full disclosure of a user's credentials is provided to network administrators for assisting users, then access assistance capability is improved, but security is compromised as unnecessary credentials are disclosed
Solution Approach 1:
The patent implements local quality by enabling selective credential sharing where the data owner can specify exactly which credentials to share and with which entities. Instead of full disclosure, the protection means allows granular control over credential access. Network administrators can receive only the specific credentials needed to assist a user, while other credentials remain protected. This localized access control maintains security while providing necessary assistance capabilities.
4Adaptability or versatility
If partial portion of credentials is disclosed for security purposes, then selective sharing capability is improved, but the disclosure remains undesirable from a security perspective
Solution Approach 1:
The patent introduces a credential sharing mechanism as an intermediary that enables selective sharing without direct credential disclosure. The protection means acts as a secure gateway that allows the sharing entity to control which credentials are accessible to which entities, without the actual credential values being exposed. This intermediary mechanism provides selective sharing capability while maintaining security by never disclosing the actual credential data.
Data Source
AI summary
A secure and transparent digital credential sharing arrangement which utilizes one or more cryptographic levels of indirection to obfuscate a sharing entity's credentials from those entities authorized to share the credentials. A security policy table is provided which allows the sharing entity to selectively authorize or revoke digital credential sharing among a plurality of entities. Various embodiments of the invention provide for secure storage and retrieval of digital credentials from security tokens such as smart cards. The secure sharing arrangement may be implemented in hierarchical or non-hierarchical embodiments as desired.


