Distributed Group Membership Certificates for Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing role-based access control systems, such as Akenti, do not accommodate security requirements of non-resource stakeholders, leading to potential unauthorized access to resources as resource stakeholders may allow access despite prohibitions from non-resource stakeholders, and Kerberos systems have a single point of failure due to reliance on a central key distribution center.
Innovation Solution
The system issues cryptographic Group Membership Certificates (GMCs) that describe prerequisite conditions for membership in groups, allowing entities to be added to target groups based on approvals from prerequisite group stakeholders, eliminating the need for a central server and accommodating non-resource stakeholders' security requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a central key distribution center is used (Kerberos system), then authentication and key distribution can be centralized and managed, but the system has a single point of failure and reduced reliability
Solution Approach 1:
The patent extracts the central key distribution center from the authentication system and replaces it with distributed cryptographic certificates. Each entity independently possesses its own public-private key pair and certificate, eliminating the central authority that caused the single point of failure while maintaining authentication functionality through public key infrastructure.
Solution Approach 2:
The centralized authentication function is segmented into distributed components where each entity manages its own cryptographic keys and certificates. The system divides the authentication responsibility from a single central authority to multiple independent entities, each capable of self-authentication through their cryptographic credentials.
2Ease of operation
If resource stakeholders alone manage access control, then resource access can be simplified, but non-resource stakeholders cannot enforce security requirements leading to potential unauthorized access
Solution Approach 1:
The cryptographic certificate system serves multiple functions simultaneously: it enables resource stakeholders to control access to their resources while also allowing non-resource stakeholders to enforce security requirements on groups. The same certificate infrastructure supports both resource-based access control and group-based security policies without requiring separate systems.
Solution Approach 2:
The patent introduces cryptographic certificates and digital signatures as intermediaries between stakeholders and entities. These cryptographic mechanisms mediate the access control decisions, allowing multiple stakeholders to impose security requirements that are cryptographically verified without direct intervention, thus enabling both resource and non-resource stakeholders to enforce security reliably.
3Reliability
If cryptographic certificates include multiple stakeholder approvals, then security requirements from non-resource stakeholders can be enforced, but the certificate issuance process becomes more complex
Solution Approach 1:
The patent implements preliminary action by having stakeholders pre-approve group definitions and membership criteria before certificates are issued. The group stakeholder approvals are obtained in advance and embedded in the certificate structure, so that during actual certificate issuance, the system only needs to verify pre-established security requirements rather than coordinating multiple approvals in real-time, reducing operational complexity.
Data Source
AI summary
A system and method for issuing a cryptographic certificate comprises describing prerequisite condition on the cryptographic certificate. The prerequisite conditions comprise membership in prerequisite group of entities. An entity may be a participant, a resource or a privilege, etc. One or more target groups of entities may be named on the cryptographic certificate. One or more prerequisite group stakeholder that authorizes an entity in the prerequisite group of entities to be added as members in another group of entities sign the cryptographic certificate. The cryptographic certificate may also be signed by target group stakeholders that authorizes an entity to be added as a member of the one or more target groups. Exemplary prerequisite conditions relate to one or more of a membership in another group of entities, a physical characteristic, a temporal characteristic, a location characteristic or a position characteristic, among others.


