Cryptographic Key Logging Properties for Audit Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cryptographic systems lack flexibility in logging properties for cryptographic keys, failing to meet the needs of environments requiring audit logs while preventing sensitive data exposure in lower security storage.

Innovation Solution

The implementation of logging properties for cryptographic keys, including specifications on whether and when data should be logged, with a mutability property to allow changes in logging settings, ensuring that sensitive data is not stored in lower security audit logs while maintaining audit trails.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signing activities are logged for audit purposes, then audit reliability is improved, but sensitive data may be exposed in lower security storage

Engineering Contradiction:
Improveaudit reliabilityVSAvoiddata exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the logging function by creating separate logging properties for different cryptographic keys. Each key can have its own logging configuration, allowing audit logs to be generated for some keys while preventing logging for keys handling sensitive data. This segmentation resolves the contradiction by enabling selective logging based on data sensitivity requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different logging properties to different cryptographic keys based on their specific usage requirements. Keys handling sensitive data are configured with logging disabled, while other keys can have logging enabled for audit purposes. This localized approach allows the system to maintain audit reliability where needed while protecting sensitive data where required.

Inventive Principle:
Principle #3Local quality

2Loss of information

If logging is enabled for cryptographic keys, then audit trail completeness is improved, but security of sensitive data deteriorates

Engineering Contradiction:
Improveaudit trail completenessVSAvoidsecurity risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces dynamic control over logging behavior through key-specific logging properties. The system can dynamically adjust logging based on the cryptographic key being used, enabling comprehensive audit trails for non-sensitive operations while automatically preventing logging when sensitive data is involved. This dynamic approach resolves the contradiction by making logging behavior adaptive to data sensitivity requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the logging parameter (enabled/disabled) based on the cryptographic key and data sensitivity. By making the logging parameter variable rather than fixed, the system can enable logging to ensure audit trail completeness for routine operations while disabling it when sensitive data is processed. This parameter change approach allows the system to maintain security while preserving audit capabilities where appropriate.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If flexible logging control is implemented for different keys, then system adaptability is improved, but system complexity increases

Engineering Contradiction:
Improvelogging flexibilityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent achieves universality by implementing a unified key management system that handles both logging and non-logging cryptographic keys through the same infrastructure. The logging property is integrated into the existing key management framework, allowing the system to provide flexible logging control without requiring separate systems or complex additional components. This universal approach resolves the contradiction by providing adaptability through a streamlined, multi-functional design.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10924286B2Signing key log management
Publication Date: 2021.02.16 AMAZON TECH INC
  • US10924286B2 patent drawing
  • US10924286B2 patent drawing
  • US10924286B2 patent drawing

AI summary

Cryptographic keys can include logging properties that enable those keys to be used only if the properties can be enforced by the cryptographic system requested to perform one or more actions using the keys. The logging property can specify how to log use of a respective key. A key can also include a mutability property for specifying whether the logging property can be changed, and if so under what circumstances or in which way(s). The ability to specify and automatically enforce logging can be important for environments where audit logs are essential. These can include, for example, public certificate authorities that must provide accurate and complete audit trails. In cases where the data is not to be provided outside a determined secure environment, the key can be generated with a property indicating not to log any of the usage.