Isolated Collection Cryptographic Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems require complex key exchange protocols for secure communication and identity verification, which can be cumbersome and insecure due to the need for widespread access to cryptographic keys.

Innovation Solution

The system employs an isolated collection where cryptographic keys are automatically generated or received, with access controlled through a user resource, allowing secure encryption and signature verification by ensuring keys are accessible from a known location, and dynamically manages key distribution during conversation sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional key exchange protocols are used for secure communication, then cryptographic security is maintained, but system complexity and operational difficulty increase

Engineering Contradiction:
Improvecryptographic securityVSAvoidkey exchange protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key distribution server as an intermediary that manages cryptographic keys centrally. Instead of requiring direct key exchange between all user pairs, the server acts as a mediator that distributes keys to authorized users, simplifying the overall system architecture while maintaining security through controlled key access

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables users to automatically obtain their cryptographic keys from the key distribution server without manual intervention. Users can request and receive their keys on-demand through automated processes, eliminating the need for complex manual key exchange protocols between users

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If cryptographic keys are widely distributed for access, then communication capability is improved, but security control deteriorates

Engineering Contradiction:
Improvecommunication capabilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements differential access control where different users receive different cryptographic keys based on their specific authorization levels and roles. Rather than distributing identical keys to all users, the system tailors key distribution to each user's local requirements, enabling versatile communication while maintaining granular security control

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The key distribution server serves as an intermediary that controls key distribution policies. It determines which users receive which keys based on authorization rules, enabling the system to provide broad communication capability to authorized users while maintaining centralized security control over key distribution

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manual key management is used, then key security is maintained, but operational efficiency decreases

Engineering Contradiction:
Improvekey securityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements automated key management where users can automatically request, receive, and manage their cryptographic keys through the key distribution server without manual intervention. This automation maintains security through controlled access while dramatically improving operational efficiency by eliminating manual key distribution processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The key distribution server pre-generates and stores cryptographic keys before they are needed. When users request access, they receive pre-prepared keys immediately rather than waiting for generation or manual distribution, improving operational efficiency while maintaining security through the server's controlled distribution mechanism

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10833870B2Cryptographic operations in an isolated collection
Publication Date: 2020.11.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10833870B2 patent drawing
  • US10833870B2 patent drawing
  • US10833870B2 patent drawing

AI summary

Examples of the present disclosure describe systems and methods for performing cryptographic operations in an isolated collection. In an example, a user may have an associated user resource within the isolated collection, which may be associated with a cryptographic key. Other users may access the user's key from a known location to manually or automatically perform one or more cryptographic operations. In another example, a key may be generated when initiating a group conversation. The key may be encrypted for and provided to each participant using each participant's public key. Each participant may then use the cryptographic key during the conversation. A new participant may receive authorization to join the conversation from an existing participant, wherein the encrypted key of the existing participant may be decrypted and re-encrypted using the new participant's public key. The new participant may then use the re-encrypted key to participate in the conversation.