Endpoint Key Rotation Rules Using Multi-Entity Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for managing cryptographic key rotation in endpoint devices are unreliable due to the potential compromise of a single entity with authority over key rotation, which can lead to unauthorized key rotation and compromised security.

Innovation Solution

Implementing re-keying rules that require key rotation requests to be multiply signed by at least two different signing systems with distinct security frameworks, ensuring that the keys used for signing are associated with different entities, thereby reducing the likelihood of unauthorized key rotation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single entity is granted authority over key rotation, then key rotation can be performed efficiently and centrally managed, but the system becomes vulnerable to compromise of that single entity leading to unauthorized key rotation

Engineering Contradiction:
Improvekey rotation managementVSAvoidsecurity trustworthiness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the key rotation authority into multiple separate signing systems rather than concentrating it in a single entity. Each signing system independently signs key rotation requests, and the endpoint device requires multiple valid signatures to process the rotation. This segmentation prevents a single point of failure or compromise while maintaining efficient centralized management through coordinated multi-system validation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If key rotation requests are multiply signed by multiple signing systems, then security and trustworthiness are enhanced, but the complexity of the key rotation process increases

Engineering Contradiction:
Improvesecurity trustworthinessVSAvoidkey rotation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent establishes re-keying rules in advance that define the exact requirements for key rotation requests (number of signatures required, which signing systems must sign, validity periods). These pre-defined rules simplify the endpoint device's validation process by providing clear checklists rather than complex dynamic decision logic. The rules are configured beforehand to balance security requirements with operational simplicity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If re-keying rules require multiple distinct signing systems, then unauthorized key rotation is prevented, but the time required for key rotation increases

Engineering Contradiction:
Improveunauthorized rotation preventionVSAvoidkey rotation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent allows flexible configuration of how many signatures are required (partial action) rather than mandating maximum security (excessive action). The re-keying rules can specify requiring signatures from a subset of available signing systems, balancing time requirements with security needs. This partial action approach enables key rotation to proceed with sufficient security while minimizing unnecessary delays from requiring all possible signatures.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12549357B2Managing key rotation for endpoint devices using re-keying rules
Publication Date: 2026.02.10 DELL PROD LP
  • US12549357B2 patent drawing
  • US12549357B2 patent drawing
  • US12549357B2 patent drawing

AI summary

Methods and systems for validating key rotation requests for endpoint devices are disclosed. The key rotation requests may be signed by one or more signing systems according to a set of re-keying rules for the endpoint device. The set of the re-keying rules may indicate that key rotation requests may be valid if signed using at least two different keys. The set of the re-keying rules may also indicate that each of the at least the two different keys be from a different grouping of keys of multiple groupings of keys included in a secure key repository. Each grouping of keys may be associated with a different organization. Therefore, key rotation requests may be serviced if signatures associated with the key rotation requests meet the re-keying rules thereby decreasing a likelihood of compromise of the endpoint devices via compromise of a key.