Distributed Secure Enclave for Enterprise Network Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks face challenges in ensuring secure authorization for document operations and encryption/decryption processes, particularly in the presence of sophisticated adversaries and insider threats, where traditional security models like Zero Trust can be compromised if the systems enforcing these controls are exploited.

Innovation Solution

The implementation of a Distributed Secure Enclave (DSE) using Byzantine Fault Tolerant State Machine Replication (BFT SMR) and proactive threshold cryptography, combined with diversity across space and time, to manage access and encryption/decryption processes, ensuring that no single point of failure can compromise the system, even if some nodes are compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security models like Zero Trust are implemented, then authorization control is improved, but system vulnerability increases if the enforcing systems are exploited

Engineering Contradiction:
Improveauthorization controlVSAvoidsystem vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security enforcement function into multiple independent trust zones, where each zone contains a subset of computing devices. No single trust zone holds complete authorization control, so compromise of one zone does not lead to complete system vulnerability. This segmentation resolves the contradiction by maintaining authorization control through distributed decision-making while reducing system vulnerability through isolation of failure points.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces consensus operations as an intermediary layer between authorization requests and enforcement actions. Multiple trust zones must reach consensus through standardized operations before authorization is granted, creating a mediator that prevents any single compromised system from directly enforcing unauthorized actions. This intermediary mechanism maintains reliable authorization control while protecting against exploitation of individual enforcing systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If distributed consensus operations are implemented across multiple trust zones, then system security is improved, but operational complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent establishes a universal consensus operation framework that can be executed across different trust zones with varying configurations. The same standardized consensus operations work across heterogeneous environments, reducing operational complexity despite distributed security. This universal approach allows the system to achieve improved security through distribution while managing complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent allows trust zones to be configured with different parameters such as the number of computing devices, specific device assignments, and threshold values for consensus. These parameter changes enable each trust zone to be optimized for its specific context while maintaining compatibility with the overall consensus framework. This flexibility reduces operational complexity by allowing localized adjustments without requiring complete system redesign.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If cryptographic keys are distributed across multiple computing devices, then intrusion tolerance is improved, but key management complexity increases

Engineering Contradiction:
Improveintrusion toleranceVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments cryptographic keys into multiple partial decryption key shares, distributing them across different trust zones and computing devices. Each individual device holds only a portion of the complete key, making intrusion tolerance improved since compromising one device does not reveal the complete key. The segmentation principle resolves the contradiction by enhancing security through distribution while managing key management complexity through systematic key fragmentation and reconstruction protocols.

Inventive Principle:
Principle #1Segmentation

4Reliability

If periodic key regeneration is implemented, then exposure time is reduced, but system overhead increases

Engineering Contradiction:
Improveexposure timeVSAvoidsystem overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements periodic regeneration of cryptographic keys at defined intervals, reducing the exposure time of any single key set. By systematically rotating keys across trust zones, the system improves reliability by limiting the window of opportunity for attackers. The periodic action principle resolves the contradiction by reducing exposure time through scheduled regeneration while managing system overhead through predictable, planned key rotation cycles rather than continuous regeneration.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12093404B2Distributed secure enclave for modern enterprise networks and critical information systems
Publication Date: 2024.09.17 CURUVAR LLC
  • US12093404B2 patent drawing
  • US12093404B2 patent drawing
  • US12093404B2 patent drawing

AI summary

In various embodiments a plurality of computing devices may perform methods for providing information security services for a communication network, including performing a consensus operation to determine whether a client device is authorized to request a document operation, wherein each computing device is assigned to one of a plurality of trust zones each including a number of computing devices less than or equal to a threshold number of computing devices, and performing the document operation for the client device in response to determining by the plurality of computing devices that consensus exists among the plurality of trust zones that the client device is authorized to request the document operation.