Hierarchical Policy Structure for Encryption Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current encryption key management systems face synchronization issues between device-level encryption management and communication management, leading to loose controls and potential breakdowns in communication security due to procedural unsynchronization and loose controls of encryption keys in public key infrastructure (PKI) and enterprise symmetric key management.
Innovation Solution
A method and system for organizing devices in a policy hierarchy, where nodes are created and policies are assigned to inherit from parent nodes, allowing devices to be bound by multiple policies, enabling centralized key management, distribution, and federation through a processor-configured system that evaluates key attributes against policies for acceptability and secure distribution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If device-level encryption management is implemented, then encryption key control is decentralized and flexible, but synchronization with communication management breaks down and security controls become loose
Solution Approach 1:
The patent introduces a policy server as an intermediary between device-level encryption management and communication management. The policy server receives encryption key management requests from devices, evaluates them against stored policies, and returns authorization decisions. This mediator synchronizes the previously unsynchronized processes while maintaining device-level flexibility, resolving the contradiction between adaptability and reliability.
2Ease of operation
If public key infrastructure (PKI) is used for encryption key management, then key distribution is enabled, but controls become loose and security breakdown occurs
Solution Approach 1:
The patent implements a feedback mechanism where the policy server continuously evaluates encryption key management operations against stored policies. When a device requests key distribution or management operations, the policy server checks the request against relevant policies, provides feedback on whether the operation is authorized, and enforces the decision. This feedback loop maintains strict security controls while enabling necessary key distribution operations.
3Productivity
If symmetric keys are generated and distributed in an enterprise, then communication encryption is enabled, but loose controls occur and communication security breaks down
Solution Approach 1:
The patent implements preliminary action by storing encryption policies in advance on the policy server before any key generation or distribution occurs. When symmetric keys need to be generated and distributed for communication encryption, the policy server already has the relevant policies ready and can immediately evaluate the requests against them. This preliminary setup enables rapid key distribution for productivity while maintaining strict security controls through pre-configured policy evaluation.
Data Source
AI summary
In various embodiments, there is provide a method for organizing devices in a policy hierarchy. The method includes creating a first node. The method further includes assigning a first policy to the first node. The method further includes creating a second node, the second node referencing the first node as a parent node such that the second node inherits the first policy of the first node.


