Key Release Agent for Dynamic Decryption Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional encryption key distribution methods are limited by fixed access control models, high overhead in managing multiple recipients, and lengthy processes for certificate verification and revocation, especially when dealing with large numbers of recipients.

Innovation Solution

A key release agent and method that controls decryption key distribution by receiving decryptor information and key related information, applying decryptor authorization logic to determine access permissions, and re-encrypting or sending decryption keys securely to authorized decryptors, using a private key repository and authorization logic repository for scalable and flexible access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional encryption key distribution methods are used with fixed access control models, then key distribution can be implemented, but the system cannot dynamically specify decryption permissions post-encryption and requires exhaustive encryption for each recipient

Engineering Contradiction:
Improvedynamic specification of decryption permissionsVSAvoidexhaustive encryption for each recipient
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by encrypting the decryption key once with a key release public key before distribution, rather than encrypting separately for each recipient. This preliminary encryption enables dynamic permission specification through the key release mechanism without requiring exhaustive pre-encryption for all possible recipients.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a key release agent as an intermediary between the encryption system and decryptors. This agent holds the key release private key and controls key distribution dynamically, allowing permission changes post-encryption without requiring direct encryption relationships between all parties.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If traditional key distribution methods are used, then key management can be implemented, but processing overhead increases significantly when dealing with large numbers of recipients

Engineering Contradiction:
Improvekey management efficiencyVSAvoidprocessing overhead
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The system performs preliminary encryption of the key with the key release public key, creating a single encrypted key package that can be distributed to multiple recipients. This eliminates the need to perform separate encryption operations for each recipient, significantly reducing processing overhead in large-scale networks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The key release mechanism serves multiple functions: it enables key distribution to unlimited recipients, provides dynamic permission control, and reduces processing overhead. A single encrypted key package can serve multiple decryptors simultaneously, making the system universally applicable regardless of recipient数量.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If certificate verification and revocation processes are implemented traditionally, then security can be maintained, but the process becomes lengthy and complex

Engineering Contradiction:
Improvecertificate verification securityVSAvoidcertificate verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The key release agent acts as a trusted intermediary that simplifies the verification process. Instead of requiring complex certificate chains and revocation checks between all parties, the key release agent pre- validates decryptor credentials and manages key distribution, significantly reducing verification time while maintaining security through the trusted intermediary mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8161565B1Key release systems, components and methods
Publication Date: 2012.04.17 ENTRUST CORP
  • US8161565B1 patent drawing
  • US8161565B1 patent drawing
  • US8161565B1 patent drawing

AI summary

Systems, methods, components are provided all for the purpose of controlling access to decryption keys needed to decrypt ciphertext. A key release agent is provided which controls decryption key distribution. The key release method starts with receiving an encrypted key, key related information and decryptor information from a decryptor and determining a whether a private key corresponding to the key ciphertext is available. Upon determining the private key corresponding to the key ciphertext is available, a decision is made based on decryptor information of the decryptor and the key related information whether decryption of the key ciphertext is to be permitted. Decryptors adapted to participate with the KRA in the above described key distribution methods are also provided.