Distributed Group Membership Certificates for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing role-based access control systems, such as Akenti, do not accommodate security requirements of non-resource stakeholders, leading to potential unauthorized access to resources as resource stakeholders may allow access despite prohibitions from non-resource stakeholders, and Kerberos systems have a single point of failure due to reliance on a central key distribution center.

Innovation Solution

The system issues cryptographic Group Membership Certificates (GMCs) that describe prerequisite conditions for membership in groups, allowing entities to be added to target groups based on approvals from prerequisite group stakeholders, eliminating the need for a central server and accommodating non-resource stakeholders' security requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a central key distribution center is used (Kerberos system), then authentication and key distribution can be centralized and managed, but the system has a single point of failure and reduced reliability

Engineering Contradiction:
Improvecentralized key distributionVSAvoidsingle point of failure
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the central key distribution center from the authentication system and replaces it with distributed cryptographic certificates. Each entity independently possesses its own public-private key pair and certificate, eliminating the central authority that caused the single point of failure while maintaining authentication functionality through public key infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The centralized authentication function is segmented into distributed components where each entity manages its own cryptographic keys and certificates. The system divides the authentication responsibility from a single central authority to multiple independent entities, each capable of self-authentication through their cryptographic credentials.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If resource stakeholders alone manage access control, then resource access can be simplified, but non-resource stakeholders cannot enforce security requirements leading to potential unauthorized access

Engineering Contradiction:
Improveaccess control managementVSAvoidsecurity enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The cryptographic certificate system serves multiple functions simultaneously: it enables resource stakeholders to control access to their resources while also allowing non-resource stakeholders to enforce security requirements on groups. The same certificate infrastructure supports both resource-based access control and group-based security policies without requiring separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces cryptographic certificates and digital signatures as intermediaries between stakeholders and entities. These cryptographic mechanisms mediate the access control decisions, allowing multiple stakeholders to impose security requirements that are cryptographically verified without direct intervention, thus enabling both resource and non-resource stakeholders to enforce security reliably.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cryptographic certificates include multiple stakeholder approvals, then security requirements from non-resource stakeholders can be enforced, but the certificate issuance process becomes more complex

Engineering Contradiction:
Improvesecurity requirement enforcementVSAvoidcertificate issuance process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having stakeholders pre-approve group definitions and membership criteria before certificates are issued. The group stakeholder approvals are obtained in advance and embedded in the certificate structure, so that during actual certificate issuance, the system only needs to verify pre-established security requirements rather than coordinating multiple approvals in real-time, reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8868928B2System and method that uses cryptographic certificates to define groups of entities
Publication Date: 2014.10.21 OBJECTIVE INTERFACE SYSTEMS
  • US8868928B2 patent drawing
  • US8868928B2 patent drawing
  • US8868928B2 patent drawing

AI summary

A system and method for issuing a cryptographic certificate comprises describing prerequisite condition on the cryptographic certificate. The prerequisite conditions comprise membership in prerequisite group of entities. An entity may be a participant, a resource or a privilege, etc. One or more target groups of entities may be named on the cryptographic certificate. One or more prerequisite group stakeholder that authorizes an entity in the prerequisite group of entities to be added as members in another group of entities sign the cryptographic certificate. The cryptographic certificate may also be signed by target group stakeholders that authorizes an entity to be added as a member of the one or more target groups. Exemplary prerequisite conditions relate to one or more of a membership in another group of entities, a physical characteristic, a temporal characteristic, a location characteristic or a position characteristic, among others.