Cryptographic Obsolescence Risk Mitigation in Enterprise Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise systems face challenges in identifying and mitigating the risks associated with cryptographic obsolescence, particularly due to advancements in quantum computing, which can render existing cryptographic techniques insecure, making it difficult for organizations to determine necessary remedial actions and prioritize upgrades.

Innovation Solution

A method involving monitoring and analyzing an enterprise system to identify cryptographic techniques in use, generating profiles to assess their usage, determining the impact of obsolescence, and initiating remedial actions such as configuration modifications to mitigate risks, using a threat detection and remediation system that includes a cryptographic monitoring module, analysis module, profile mapping module, and orchestration module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If enterprise systems continue to grow in scale, then system capacity and functionality improve, but the task of scanning for cryptographic vulnerabilities becomes more challenging and time-consuming

Engineering Contradiction:
Improvesystem capacityVSAvoidtime for vulnerability scanning
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent segments the enterprise system into multiple components and assigns cryptographic monitoring agents to each component. This distributed approach allows parallel scanning of cryptographic vulnerabilities across different system segments, reducing the total time required compared to centralized scanning of the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements continuous background monitoring of cryptographic techniques before obsolescence occurs. By proactively identifying cryptographic vulnerabilities in advance through ongoing surveillance, the system prepares remediation strategies before security threats materialize, reducing emergency response time.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive monitoring of cryptographic techniques is implemented across the entire enterprise system, then security detection capability improves, but system complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a multi-functional cryptographic monitoring system that performs multiple functions: identifying cryptographic techniques, generating usage profiles, determining obsolescence effects, and initiating remedial actions. This universal system consolidates what would otherwise require separate tools and processes, managing complexity through integration rather than proliferation of separate components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces cryptographic monitoring agents as intermediary components that bridge between enterprise system components and the central monitoring system. These agents simplify the architecture by handling local cryptographic data collection and preprocessing, reducing the complexity burden on both the monitored components and the central system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If detailed profiles characterizing cryptographic technique usage are generated, then accuracy in determining obsolescence effects improves, but processing time and computational resources increase

Engineering Contradiction:
Improveaccuracy in determining obsolescence effectsVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent generates cryptographic usage profiles that capture essential characteristics needed to determine obsolescence effects, rather than attempting to record every possible usage detail. This selective profiling approach achieves sufficient accuracy for security assessment while avoiding the computational overhead of comprehensive data collection and processing.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11171995B2Identifying and mitigating risks of cryptographic obsolescence
Publication Date: 2021.11.09 EMC IP HLDG CO LLC
  • US11171995B2 patent drawing
  • US11171995B2 patent drawing
  • US11171995B2 patent drawing

AI summary

A method includes monitoring an enterprise system to identify cryptographic techniques utilized by one or more components of the enterprise system, the one or more components comprising at least one of physical and virtual computing resources. The method also includes generating one or more profiles characterizing usage of at least a given one of the identified cryptographic techniques by at least a given one of the one or more components of the enterprise system and determining an effect of cryptographic obsolescence of the given identified cryptographic technique on the enterprise system utilizing the generated one or more profiles. The method further includes identifying one or more remedial actions for mitigating the effect of cryptographic obsolescence of the given identified cryptographic technique on the enterprise system and initiating one or more of the identified remedial actions to modify a configuration of one or more components of the enterprise system.