Graph-Based Cryptographic Function Partitioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cryptographic techniques, such as Identity-Based Encryption (IBE) and self-delegation, fail to provide a general solution for partitioning cryptographic functionality effectively, as they are limited in granularity, require global timing synchronization, and do not support inter-party delegation, leading to inefficiencies and security vulnerabilities.
Innovation Solution
A graph-based partitioning approach that allows delegation of cryptographic functionality by characterizing it as a graph with nodes, enabling the transmission of specific seeds for authorized execution of distinct cryptographic operations, such as authentication and key generation, between devices, thereby overcoming the limitations of existing methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Manufacturing precision
If Identity-Based Encryption (IBE) is used for delegation, then decryption ability can be delegated, but the granularity is limited to time intervals rather than per-computation level
Solution Approach 1:
The patent segments cryptographic functionality into distinct nodes within a graph structure, where each node represents a specific cryptographic operation or key. This allows fine-grained delegation at the per-computation level rather than coarse time-based intervals. The graph is divided into multiple nodes that can be selectively delegated based on specific computational needs.
Solution Approach 2:
The patent transitions from time-based delegation (one-dimensional) to a graph-based delegation model where functionality is organized by computational dependency relationships (multi-dimensional). This dimensional shift enables delegation based on computational context rather than temporal intervals, providing both fine granularity and adaptability.
2Ease of operation
If IBE technique is used, then decryption ability can be delegated, but global timing synchronization is required
Solution Approach 1:
The patent introduces a graph structure as an intermediary that mediates between the delegating authority and recipient devices. The graph captures dependency relationships and allows localized delegation without requiring global timing synchronization. The intermediary structure enables operations to proceed independently based on local graph constraints.
3Adaptability or versatility
If conventional IBE approach is used, then decryption delegation is supported, but it cannot support inter-party delegation
Solution Approach 1:
The patent creates a universal graph-based framework that can support multiple types of delegation (inter-party, intra-party, hierarchical) within a single system. The same graph structure and node-based approach enable both decryption delegation and authentication functionality, making the system versatile and efficient.
4Adaptability or versatility
If self-delegation technique is used, then cryptographic functionality can be delegated, but it is limited to self-delegation context and cannot support inter-party delegation
Solution Approach 1:
The patent makes the delegation system dynamic by allowing any node in the graph to be delegated to any other node, not just self-delegation. The graph structure enables flexible reconfiguration of delegation relationships based on operational requirements, supporting both self-delegation and inter-party delegation dynamically.
Data Source
AI summary
Techniques are disclosed for partitioning of cryptographic functionality, such as authentication code verification or generation ability, so as to permit delegation of at least one of a number of distinct portions of the cryptographic functionality from a delegating device to at least one recipient device. The cryptographic functionality is characterizable as a graph comprising a plurality of nodes, and a given set of the nodes is associated with a corresponding one of the distinct portions of the cryptographic functionality. Information representative of one or more of the nodes is transmitted from the delegating device to the recipient device such that the recipient device is thereby configurable for authorized execution of a corresponding one of the distinct portions of the cryptographic functionality. Advantageously, the invention provides a particularly efficient mechanism for the provision of cryptographic functionality in accordance with a subscription model.


