Hybrid Security Level Cryptographic Object Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication security systems struggle to maintain hybrid security levels for cryptographic secure objects, particularly when network connectivity is intermittent or unavailable, leading to restricted access to high-risk operations.
Innovation Solution
A method involving a security device that generates requests for cryptographic secure objects at different security levels, transmits these requests across multiple communication links, and receives the objects from servers configured at various security levels, allowing for the generation of a chain of cryptographic secure objects to maintain hybrid security levels even during network disruptions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic secure objects are maintained at high security levels, then security protection is improved, but accessibility and operation continuity deteriorate when network connectivity is unavailable
Solution Approach 1:
The cryptographic secure object is segmented into multiple components with different security levels. The system divides the security object into a first cryptographic secure object at a first security level and a second cryptographic secure object at a second security level, allowing different parts to serve different operational needs and enabling continuity when high-security components are unavailable.
Solution Approach 2:
Different portions of the cryptographic secure object are assigned different security levels based on their specific functions and requirements. The first cryptographic secure object maintains high security level for critical operations, while the second cryptographic secure object operates at a lower security level to ensure continuity during network disruptions, creating local quality variations within the overall security structure.
2Adaptability or versatility
If hybrid security levels are implemented, then accessibility under intermittent connectivity is improved, but device complexity increases
Solution Approach 1:
The system dynamically adjusts which cryptographic secure object is used based on network connectivity status. When connected to the high-security server, the system uses the first cryptographic secure object at the higher security level; when connectivity is lost, it automatically transitions to using the second cryptographic secure object at the lower security level, enabling adaptive operation without manual intervention.
Solution Approach 2:
The system introduces an intermediary mechanism that manages multiple cryptographic secure objects and their corresponding servers. This intermediary layer handles the complexity of managing hybrid security levels, different servers, and transition logic, shielding the core security operations from the complexity while enabling versatile accessibility under varying connectivity conditions.
3Adaptability or versatility
If multiple cryptographic secure objects are managed, then security level flexibility is improved, but loss of time for managing multiple objects increases
Solution Approach 1:
The system performs preliminary actions by pre-establishing multiple cryptographic secure objects and their associated servers before network disruptions occur. The first cryptographic secure object is established with the high-security server during connected periods, and the second cryptographic secure object is prepared in advance, allowing immediate transition without time-consuming setup when connectivity is lost.
Solution Approach 2:
The system implements self-service mechanisms that automatically manage the multiple cryptographic secure objects without requiring manual intervention. The system autonomously selects which cryptographic secure object to use based on connectivity status, automatically manages transitions between objects, and handles the coordination with different servers, eliminating the time burden of manual management while maintaining security level flexibility.
Data Source
AI summary
A method includes: generating a first request to generate a first cryptographic secure object protected at a first security level; transmitting the first request to a first server via a first communication link; generating a second request to generate a second cryptographic secure object associated with the first cryptographic secure object and protected at a second security level falling below the first security level; transmitting the second request to a second server via a second communication link; transmitting a third request to generate a third cryptographic secure object based on the second cryptographic secure object to the second server in response to absence of the first communication link; and executing an action based on the third cryptographic secure object, the third cryptographic secure object generated by the second server based on the first and second cryptographic secure objects and protected at a third security level exceeding the second security level.


