Key Generation Component with Adjustable Entropy Interface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for generating cryptographic keys do not provide sufficient flexibility in entropy levels, which can impact the security and efficiency of key generation depending on the application context, leading to either excessive processing for high-security needs or inadequate security for less sensitive applications.

Innovation Solution

A key generation component that exposes characteristics for input entropy, allowing selection from multiple entropy generation components to generate cryptographic keys, enabling adjustable entropy levels based on application sensitivity, thereby optimizing processing and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If higher degrees of input entropy are used to guard against key discovery, then security is improved, but processing time and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically adjusts the entropy generation process based on application sensitivity. The key generation component connects to different entropy generation components or adjusts entropy characteristics according to the specific application's security requirements, allowing flexible optimization between security and processing time.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention changes the parameters of entropy generation by exposing characteristics for input entropy and allowing selection from multiple entropy generation components. This enables adjustment of entropy levels to match application sensitivity, optimizing the balance between security and processing efficiency.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If higher degrees of input entropy are used to guard against key discovery, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key generation component serves multiple functions by connecting to different entropy generation components based on application requirements. This multi-functional design allows the same component to provide appropriate security levels for different applications without requiring separate systems for each security level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The key generation component acts as an intermediary between entropy generation components and applications. It manages the complexity of selecting and connecting to appropriate entropy sources, shielding applications from the underlying system complexity while providing tailored security levels.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If rigorous processing is applied to generate high entropy, then security is improved, but productivity decreases

Engineering Contradiction:
ImprovesecurityVSAvoidkey generation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adapts the rigor of entropy processing based on application sensitivity. For less sensitive applications, the system uses lighter processing to generate keys quickly, while reserving rigorous processing for high-security applications, thus optimizing overall productivity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention enables changing the parameters of entropy generation and processing based on application requirements. By adjusting entropy characteristics and selection of generation components, the system optimizes the balance between security rigor and key generation speed for different use cases.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3984161B1Cryptographic key generation using external entropy generation
Publication Date: 2024.09.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3984161B1 patent drawingFigure 1
  • EP3984161B1 patent drawingFigure 2
  • EP3984161B1 patent drawingFigure 3

AI summary

Generation of a cryptographic key using one of multiple possible entropy generation components that may provide input entropy. A key generation component provides an interface that exposes one or more characteristics for input entropy to be used to generate a cryptographic key. For applications that are more sensitive to improper key discovery, higher degrees of input entropy may be used to guard against key discovery. During key generation, the key generation component connects with an appropriate entropy generation component via the interface. For instance, the entropy generation component may be selected or adjusted so that it does indeed provide the input entropy meeting the characteristics described by the interface. The key generation component receives the input entropy via the interface, and then uses the input entropy to generate the cryptographic key.