Identity-Based Cryptographic Key Management for Distributed Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key management techniques fail to effectively manage cryptographic keys in environments with diverse security requirements and capabilities, particularly in large-scale distributed systems with untrusted connections and varying trust relationships between entities.

Innovation Solution

The proposed method involves a key generation module that generates digital signatures as private keys based on an electronic device's identifiers and attributes, using Schnorr signature methods, allowing for efficient key management and verification across entities with arbitrary security policies, and enabling the use of identity-based, attribute-based, or feature-based keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional key management mechanisms are used, then key protection and life cycle management can be provided, but they fail to effectively manage cryptographic keys in environments with diverse security requirements and capabilities

Engineering Contradiction:
Improveadaptability to diverse security requirementsVSAvoideffectiveness in untrusted environments
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by allowing different entities to have different security policies and key management capabilities. Each entity can operate with its own security requirements and key management approach, while the system as a whole maintains compatibility through the standardized interface. This enables the system to adapt to diverse security requirements without compromising reliability in untrusted environments.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces an intermediary key management interface that mediates between entities with different security requirements and the underlying cryptographic operations. This intermediary layer provides a standardized way to manage keys across diverse security contexts, enabling effective key management in untrusted environments by translating between different security models.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic keys are generated and managed for each entity, then secure interactions can be enabled, but the complexity of managing keys in large-scale distributed systems increases

Engineering Contradiction:
Improvesecurity of interactionsVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a standardized key management interface that can handle multiple key types (asymmetric, symmetric, hybrid) and multiple security policies through a single unified mechanism. This universal interface reduces the complexity of managing keys in large-scale distributed systems by providing consistent key management operations across different security contexts and entity types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments key management into distinct functional components: key generation, key storage, key usage, and key revocation. Each component can be implemented independently and optimized for specific security requirements. This segmentation reduces overall complexity by allowing each part of the key management system to be managed and understood separately.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If identity-based and attribute-based keys are used, then keys can be tightly associated with device identifiers and attributes, but the key generation and verification processes become more complex

Engineering Contradiction:
Improveassociation precision between keys and device attributesVSAvoidkey generation and verification complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by using different key generation parameters based on the type of association required. For identity-based keys, the identity string is used as the parameter; for attribute-based keys, the attribute value serves as the parameter. The standardized interface automatically selects and applies the appropriate parameter type, achieving tight association between keys and device attributes while managing complexity through parameterization.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent enables self-service by allowing entities to generate their own identity-based and attribute-based keys using the standardized interface. Each entity can autonomously create keys associated with their identifiers and attributes without requiring manual intervention or complex centralized key generation processes, thereby reducing overall system complexity while maintaining precise key-attribute associations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10027481B2Management of cryptographic keys
Publication Date: 2018.07.17 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10027481B2 patent drawing
  • US10027481B2 patent drawing
  • US10027481B2 patent drawing

AI summary

An electronic device for management of cryptographic keys, and a corresponding method implemented in a computing device comprising a physical processor, transmit feature data of the device to a key generation module, wherein the feature data comprises information corresponding to an identifier or an attribute of the device, and receive, by the device from the key generation module, a digital signature of the transmitted feature data. The device installs the received digital signature as a cryptographic private key for communication, and performs a cryptographic operation using the installed digital signature as the cryptographic private key.