Geospatial Key Derivation for Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cryptographic access control mechanisms rely solely on key possession, which is insufficient for sophisticated access control and can be circumvented by compromised executable rules, lacking the security and precision needed for modern access management.

Innovation Solution

Integrating location data and other contextual factors into the cryptographic key creation process, using conversion data to transform location data into cryptographic values that determine access permissions, thereby enhancing access control by embedding access criteria within the cryptographic technique.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cryptographic access control mechanisms are used that rely solely on key possession, then the system is simple to implement, but the security and precision of access control is insufficient and can be circumvented by compromised executable rules

Engineering Contradiction:
Improveaccess control securityVSAvoidcryptographic system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transitions from traditional one-dimensional key possession verification to multi-dimensional access control by incorporating location data, temporal data, and other contextual parameters. The cryptographic key is now derived from multiple independent dimensions (geographic location, time, device identity) rather than a single key, creating a higher-dimensional security space that is significantly harder to compromise.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent changes the parameters used for cryptographic key generation from static key material to dynamic contextual parameters including location coordinates, timestamps, and environmental data. This parameter transformation allows the system to adapt access control requirements dynamically while maintaining cryptographic security, resolving the contradiction between simplicity and security.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If executable rules are used to control access based on additional criteria, then access control precision is improved, but the system becomes vulnerable to circumvention by compromised rules

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent merges executable access control rules with cryptographic key derivation into a unified system. Instead of having separate rule evaluation and key verification layers that can be circumvented, the access criteria (location, time, etc.) are directly embedded in the cryptographic key generation process. This merging ensures that rule compliance is mathematically guaranteed by the cryptography itself, not just enforced by potentially compromised software rules.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces cryptographic key derivation as an intermediary mechanism between access criteria evaluation and resource access. Rather than directly executing access rules that can be bypassed, the system uses cryptographic key derivation as a trusted mediator that transforms contextual parameters into cryptographic proofs of compliance. This intermediary layer provides mathematical assurance that access rules are properly enforced.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If location data and contextual factors are integrated into cryptographic key creation, then access control precision and security are enhanced, but the device complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidcryptographic system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling devices to autonomously generate cryptographic keys from their own contextual data (location, time, device identifiers) without requiring complex centralized key management infrastructure. Each device independently performs the cryptographic derivation using locally available sensors and data, reducing system complexity while enhancing security through distributed key generation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11387997B2Constrained key derivation in geographical space
Publication Date: 2022.07.12 RED HAT INC
  • US11387997B2 patent drawing
  • US11387997B2 patent drawing
  • US11387997B2 patent drawing

AI summary

The technology disclosed herein provides an enhanced cryptographic access control mechanism that uses a cryptographic keys that are based on location data. An example method may include: determining location data of a computing device; transforming the location data in view of conversion data associated with the computing device, wherein the conversion data causes a set of alternate location data values to transform to a specific cryptographic value; creating, by a processing device, a cryptographic key in view of the transformed location data; and using the cryptographic key to enable access to a protected resource.