Key Release Agent for Dynamic Decryption Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional encryption key distribution methods are limited by fixed access control models, high overhead in managing multiple recipients, and lengthy processes for certificate verification and revocation, especially when dealing with large numbers of recipients.
Innovation Solution
A key release agent and method that controls decryption key distribution by receiving decryptor information and key related information, applying decryptor authorization logic to determine access permissions, and re-encrypting or sending decryption keys securely to authorized decryptors, using a private key repository and authorization logic repository for scalable and flexible access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional encryption key distribution methods are used with fixed access control models, then key distribution can be implemented, but the system cannot dynamically specify decryption permissions post-encryption and requires exhaustive encryption for each recipient
Solution Approach 1:
The patent applies preliminary action by encrypting the decryption key once with a key release public key before distribution, rather than encrypting separately for each recipient. This preliminary encryption enables dynamic permission specification through the key release mechanism without requiring exhaustive pre-encryption for all possible recipients.
Solution Approach 2:
The patent introduces a key release agent as an intermediary between the encryption system and decryptors. This agent holds the key release private key and controls key distribution dynamically, allowing permission changes post-encryption without requiring direct encryption relationships between all parties.
2Productivity
If traditional key distribution methods are used, then key management can be implemented, but processing overhead increases significantly when dealing with large numbers of recipients
Solution Approach 1:
The system performs preliminary encryption of the key with the key release public key, creating a single encrypted key package that can be distributed to multiple recipients. This eliminates the need to perform separate encryption operations for each recipient, significantly reducing processing overhead in large-scale networks.
Solution Approach 2:
The key release mechanism serves multiple functions: it enables key distribution to unlimited recipients, provides dynamic permission control, and reduces processing overhead. A single encrypted key package can serve multiple decryptors simultaneously, making the system universally applicable regardless of recipient数量.
3Reliability
If certificate verification and revocation processes are implemented traditionally, then security can be maintained, but the process becomes lengthy and complex
Solution Approach 1:
The key release agent acts as a trusted intermediary that simplifies the verification process. Instead of requiring complex certificate chains and revocation checks between all parties, the key release agent pre- validates decryptor credentials and manages key distribution, significantly reducing verification time while maintaining security through the trusted intermediary mechanism.
Data Source
AI summary
Systems, methods, components are provided all for the purpose of controlling access to decryption keys needed to decrypt ciphertext. A key release agent is provided which controls decryption key distribution. The key release method starts with receiving an encrypted key, key related information and decryptor information from a decryptor and determining a whether a private key corresponding to the key ciphertext is available. Upon determining the private key corresponding to the key ciphertext is available, a decision is made based on decryptor information of the decryptor and the key related information whether decryption of the key ciphertext is to be permitted. Decryptors adapted to participate with the KRA in the above described key distribution methods are also provided.


