Cryptographic Key Logging Properties for Audit Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cryptographic systems lack flexibility in logging properties for cryptographic keys, failing to meet the needs of environments requiring audit logs while preventing sensitive data exposure in lower security storage.
Innovation Solution
The implementation of logging properties for cryptographic keys, including specifications on whether and when data should be logged, with a mutability property to allow changes in logging settings, ensuring that sensitive data is not stored in lower security audit logs while maintaining audit trails.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If signing activities are logged for audit purposes, then audit reliability is improved, but sensitive data may be exposed in lower security storage
Solution Approach 1:
The patent segments the logging function by creating separate logging properties for different cryptographic keys. Each key can have its own logging configuration, allowing audit logs to be generated for some keys while preventing logging for keys handling sensitive data. This segmentation resolves the contradiction by enabling selective logging based on data sensitivity requirements.
Solution Approach 2:
The patent applies local quality by assigning different logging properties to different cryptographic keys based on their specific usage requirements. Keys handling sensitive data are configured with logging disabled, while other keys can have logging enabled for audit purposes. This localized approach allows the system to maintain audit reliability where needed while protecting sensitive data where required.
2Loss of information
If logging is enabled for cryptographic keys, then audit trail completeness is improved, but security of sensitive data deteriorates
Solution Approach 1:
The patent introduces dynamic control over logging behavior through key-specific logging properties. The system can dynamically adjust logging based on the cryptographic key being used, enabling comprehensive audit trails for non-sensitive operations while automatically preventing logging when sensitive data is involved. This dynamic approach resolves the contradiction by making logging behavior adaptive to data sensitivity requirements.
Solution Approach 2:
The patent changes the logging parameter (enabled/disabled) based on the cryptographic key and data sensitivity. By making the logging parameter variable rather than fixed, the system can enable logging to ensure audit trail completeness for routine operations while disabling it when sensitive data is processed. This parameter change approach allows the system to maintain security while preserving audit capabilities where appropriate.
3Adaptability or versatility
If flexible logging control is implemented for different keys, then system adaptability is improved, but system complexity increases
Solution Approach 1:
The patent achieves universality by implementing a unified key management system that handles both logging and non-logging cryptographic keys through the same infrastructure. The logging property is integrated into the existing key management framework, allowing the system to provide flexible logging control without requiring separate systems or complex additional components. This universal approach resolves the contradiction by providing adaptability through a streamlined, multi-functional design.
Data Source
AI summary
Cryptographic keys can include logging properties that enable those keys to be used only if the properties can be enforced by the cryptographic system requested to perform one or more actions using the keys. The logging property can specify how to log use of a respective key. A key can also include a mutability property for specifying whether the logging property can be changed, and if so under what circumstances or in which way(s). The ability to specify and automatically enforce logging can be important for environments where audit logs are essential. These can include, for example, public certificate authorities that must provide accurate and complete audit trails. In cases where the data is not to be provided outside a determined secure environment, the key can be generated with a property indicating not to log any of the usage.


