Multi-file Cryptographic Keystore Concurrent Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer security systems, which rely on a single keystore for encryption keys and certificates, often restrict access to a single application at a time and lack efficient permission management, leading to inefficiencies and potential security vulnerabilities when multiple applications need to access encryption keys simultaneously.

Innovation Solution

A multi-file cryptographic keystore is introduced, featuring non-application specific directories and application-specific subdirectories with secure and non-secure areas, allowing multiple applications to access the keystore simultaneously while ensuring secure permission management through password protection and granular access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single-file keystore is used, then security is maintained through centralized storage, but only one application can access the keystore at a time

Engineering Contradiction:
ImprovesecurityVSAvoidconcurrent access capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the single-file keystore into multiple files organized in a directory structure with application-specific subdirectories. This segmentation allows multiple applications to access different portions of the keystore simultaneously without interfering with each other, while maintaining security through individual file protection mechanisms.

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If the entire keystore is retrieved for each key request, then simple implementation is maintained, but retrieval time increases when multiple applications need keys simultaneously

Engineering Contradiction:
Improveimplementation simplicityVSAvoidkey retrieval time
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The patent extracts only the necessary key information from the keystore files rather than retrieving the entire keystore contents. Applications request specific keys from their designated subdirectories, and the system retrieves only those specific keys, reducing retrieval time and data transfer overhead while maintaining secure access.

Inventive Principle:
Principle #2Taking out (Extraction)

3Quantity of substance

If a single centralized keystore is used, then storage space is minimized, but permission management becomes complex when multiple applications need access

Engineering Contradiction:
Improvestorage spaceVSAvoidpermission management complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent implements application-specific subdirectories within the keystore structure, where each subdirectory contains keys relevant to that specific application. This local organization simplifies permission management by scoping access rights to specific directories rather than managing permissions across a single centralized store, making it easier to control which applications can access which keys.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7549174B1Multi-file cryptographic keystore
Publication Date: 2009.06.16 ORACLE AMERICAN INC
  • US7549174B1 patent drawing
  • US7549174B1 patent drawing
  • US7549174B1 patent drawing

AI summary

A system including an application configured to request a key, a keystore configured to provide the key, wherein the keystore comprises a non-application specific directory, and an application-specific subdirectory.