Hierarchical Encryption Key Policy Evaluation Structure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption key management systems face synchronization issues between device-level encryption management and communication management, leading to loose controls and potential breakdowns in communication security, especially in structured and ad-hoc organizations.

Innovation Solution

A hierarchical structure-based approach for encryption key management, where policies are defined and evaluated within nodes, groups, and users, allowing for priority-based aggregation and temporary exceptions through an evaluation structure, enabling centralized control and synchronization of encryption key operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If device-level encryption management is implemented, then encryption key control is decentralized and flexible, but synchronization with communication management breaks down and security control becomes loose

Engineering Contradiction:
Improveencryption key management flexibilityVSAvoidcommunication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a key management server as an intermediary between devices and communication management systems. This server receives encryption key generation requests from devices, manages the keys centrally, and provides them back to devices. This intermediary structure maintains the flexibility of device-level operations while ensuring centralized control and synchronization with communication management, thereby resolving the contradiction between adaptability and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Stability of the object's composition

If centralized communication management is implemented, then communication control is coordinated, but encryption key management becomes procedurally unsynchronized and loose controls occur

Engineering Contradiction:
Improvecommunication management coordinationVSAvoidencryption key control
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The patent merges communication management and encryption key management into a unified system. The key management server is integrated with the communication management infrastructure, allowing both functions to operate under coordinated control. This merging ensures that communication management coordination is maintained while encryption key control remains synchronized and secure, eliminating the procedural unsynchronization issue.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If hierarchical policy structure is implemented, then encryption key evaluation is comprehensive and secure, but system complexity increases

Engineering Contradiction:
Improveencryption key securityVSAvoidpolicy management structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the policy management structure into hierarchical levels (e.g., organizational policies, departmental policies, device-specific policies). Each level handles specific aspects of encryption key evaluation, allowing comprehensive security checks to be performed in a structured manner. This segmentation makes the complex policy management more manageable by dividing it into smaller, organized components that can be processed systematically.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11700244B2Structure of policies for evaluating key attributes of encryption keys
Publication Date: 2023.07.11 FORNETIX LLC
  • US11700244B2 patent drawing
  • US11700244B2 patent drawing
  • US11700244B2 patent drawing

AI summary

Examples described herein relate to apparatuses and methods for evaluating an encryption key based on policies for a policy operation, including, but not limited to, receiving user request for the policy operation, determining one or more of a node, group, client, or user associated with the user request, determining the policies associated with the one or more of the node, group, client, or user based on priority, and evaluating at least one key attribute of an encryption key based, at least in part, on the policies.