Dynamic Credential Extension for KMIP Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key management protocols, such as KMIP, are limited in their ability to handle dynamic credential creation and sharing among devices, requiring pre-provisioning by administrators and lacking support for devices that need dynamic credential generation.

Innovation Solution

Extending the KMIP protocol to enable a new credential type that allows an initiating client device to create credentials dynamically, which can then be shared with and used by other devices, eliminating the need for pre-provisioning and enabling on-demand key creation and sharing among devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If KMIP protocol uses predefined credential types with centralized pre-provisioning model, then key management security and control are improved, but flexibility and adaptability for dynamic device credential creation deteriorate

Engineering Contradiction:
Improvekey management securityVSAvoiddynamic credential creation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a new dynamic credential type that allows credentials to be created on-demand rather than pre-defined. The credential structure includes dynamic fields such as device identifiers, cryptographic parameters, and expiration times that are generated at runtime based on device needs, enabling the system to adapt to varying credential requirements while maintaining security through centralized validation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent modifies the KMIP protocol by adding new credential parameters and structures that enable dynamic credential creation. The credential type extension includes adjustable parameters for cryptographic algorithms, key sizes, and validity periods, allowing the system to flexibly adapt credential properties based on specific device requirements while maintaining protocol-wide security standards.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If KMIP protocol requires administrator pre-provisioning of credentials, then centralized control and security policy enforcement are improved, but operational efficiency and automation level deteriorate

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidkey management efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables devices to self-provision credentials by allowing them to dynamically generate credential requests with their own device identifiers and cryptographic parameters. The automated credential creation process eliminates the need for manual administrator intervention for each device, while the centralized key management server maintains security policy enforcement by validating generated credentials against organizational security requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary security policy configuration at the system level, where administrators define security templates and policies in advance. These pre-configured security parameters are then automatically applied during dynamic credential creation, ensuring that security enforcement is built into the automated process without requiring manual intervention for each credential issuance.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If KMIP protocol uses centralized pre-provisioning architecture, then operational control and governance are improved, but device autonomy and peer-to-peer key sharing capability deteriorate

Engineering Contradiction:
Improvecentralized key management controlVSAvoiddevice autonomy
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The patent segments the credential management process into two independent but coordinated functions: centralized security policy management and decentralized credential generation. The key management server handles security policy enforcement and validation, while individual devices autonomously generate their own credentials using the dynamic credential type, enabling both centralized control and device autonomy to coexist.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces the dynamic credential structure as an intermediary mechanism that bridges centralized control and device autonomy. The credential contains both server-validated security parameters and device-generated identifying information, allowing the system to maintain centralized governance while enabling devices to autonomously participate in peer-to-peer key sharing using their self-created credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11477182B2Creating a credential dynamically for a key management protocol
Publication Date: 2022.10.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11477182B2 patent drawing
  • US11477182B2 patent drawing
  • US11477182B2 patent drawing

AI summary

A key management protocol (such as KMIP) is extended to provide an extended credential type that enables an initiating (first) client device to create a credential dynamically and that can then be selectively shared with and used by other (second) client devices. Using a dynamically-created credential of this type, the other (second) devices are able to fetch the same key configured by the initiating (first) device. In this manner, multiple devices are able to create and share one or more keys among themselves dynamically, and on as-needed basis without requiring a human administrator to create a credential for a device group in advance of its usage.