Hierarchical Entity Management for Code Signing Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing code signing systems do not provide a framework for different organizations to manage their data signing permission needs flexibly, allowing unauthorized entities to potentially compromise device security by signing malicious data.
Innovation Solution
A hierarchical entity management system for code signing, where administrators define eligibility for users to access and sign data, using owner and participant accounts to control access to configuration entities, ensuring secure data signing across multiple organizations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hierarchical entity management system with multiple account types is implemented, then access control flexibility and security are improved, but system complexity increases
Solution Approach 1:
The system segments access control into multiple hierarchical levels (application platform entity, project entity, model entity, configuration entity) with distinct account types (owner account, participant account). Each level has specific permissions and responsibilities, allowing fine-grained control over who can sign data at each hierarchical level without requiring a single complex access control mechanism.
Solution Approach 2:
The patent introduces a hierarchical dimension to access control, organizing entities in a multi-level structure rather than a flat system. This hierarchical dimension allows access permissions to be managed vertically across levels (from application platform down to configuration entities) and horizontally across different account types, providing structured complexity that improves security while maintaining manageability.
2Adaptability or versatility
If multiple organizations are allowed to sign data for the same device family, then system versatility and collaboration capability are improved, but security risk from unauthorized access increases
Solution Approach 1:
The system introduces participant accounts as intermediaries between multiple organizations and the code signing framework. Participant accounts enable collaborative signing capabilities across organizations while maintaining security boundaries. The intermediary account structure allows verified participants to sign data for device families without exposing private keys or allowing unauthorized access to other organizations' signing capabilities.
Solution Approach 2:
The patent applies local quality by allowing different organizations to have different levels of access and signing permissions tailored to their specific needs and trust levels. Each organization's participant account can be configured with specific permissions for specific device families or project entities, enabling versatile collaboration while maintaining localized security controls appropriate to each organizational relationship.
3Measurement precision
If fine-grained access control permissions are implemented at each hierarchical level, then security control precision is improved, but system complexity and management overhead increase
Solution Approach 1:
The system implements dynamic access control where permissions can be adjusted at different hierarchical levels based on organizational needs. Owner accounts have dynamic control to grant or revoke participant access, and permissions can be modified at project, model, or configuration entity levels without reconfiguring the entire system. This dynamic approach enables precise control while reducing management overhead through localized permission adjustments.
Data Source
AI summary
A method and apparatus is provided for managing the eligibility of data signing in an online code signing system. The method is used by a plurality of data publishers in an online code signing system. The method includes defining, by an administrator of the system, a hierarchy of a plurality of entities, and managing, by an administrator of the system, eligibility to designate at least one of a plurality of users to access the at least one configuration entity to sign the data via a plurality of accounts and eligibility to designate at least one of a plurality of managers via owner account to manage user access to sign data for at least one model entity.


