Policy-Governed Cryptographic Selection for Dynamic Algorithm Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cryptographic configurations are inflexible and require manual updates, leading to slow adaptation to evolving security threats, especially with the rise of quantum computing, resulting in increased costs and potential system downtime.

Innovation Solution

A policy-governed cryptographic selection system that dynamically adjusts cryptographic libraries and algorithms based on contextual data, using a cryptographic shim, policy manager, and library manager to automate the selection and configuration of cryptographic features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic algorithms are hard-coded into hardware or firmware, then security and reliability are improved, but adaptability and ease of updating are worsened

Engineering Contradiction:
Improvecryptographic securityVSAvoidalgorithm update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system separates cryptographic algorithms from hardware/firmware and segments them into software modules that can be independently selected and updated. The policy controller divides cryptographic functionality into selectable algorithms stored in memory, allowing individual algorithm updates without affecting the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic algorithm selection where cryptographic algorithms can be changed at runtime based on policy updates. The policy controller enables dynamic reconfiguration of cryptographic parameters and algorithm choices without requiring hardware reprogramming or firmware updates.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If cryptographic algorithms are stored in memory rather than hard-coded, then adaptability and ease of updating are improved, but security and reliability are worsened

Engineering Contradiction:
Improvealgorithm update capabilityVSAvoidcryptographic security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary validation of cryptographic algorithms before deployment to memory. The policy controller pre-approves and validates algorithms, then securely loads them into memory with enforced authentication mechanisms, ensuring that only verified algorithms are executable.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The policy controller acts as an intermediary between algorithm storage and execution. It enforces authentication and authorization policies, verifying algorithm integrity and controlling access to cryptographic functions, thereby maintaining security while enabling flexible memory-based algorithm storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication policies are manually configured, then security control is improved, but ease of operation and productivity are worsened

Engineering Contradiction:
Improveauthentication controlVSAvoidpolicy configuration effort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements automated feedback loops where the policy controller continuously monitors authentication attempts, algorithm performance, and security events. It automatically adjusts policies based on detected threats, usage patterns, and compliance requirements, reducing manual configuration while maintaining strong security control.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The policy controller enables self-service authentication policy management where the system automatically configures and enforces policies without requiring manual intervention. Administrators define high-level security requirements, and the system autonomously generates and updates detailed authentication policies, algorithm selections, and access controls.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4413694B1Policy-governed cryptographic selection system
Publication Date: 2026.05.06 VMWARE INC
  • EP4413694B1 patent drawingFigure 1
  • EP4413694B1 patent drawingFigure 2
  • EP4413694B1 patent drawingFigure 3

AI summary

This disclosure relates generally to configuring an application or service with reconfigurable cryptographic features taking the form of cryptographic algorithms, protocols or functions. The application or service can be configured with a cryptographic provider configured to receive abstracted cryptographic API calls and retrieve specific cryptographic features based on established cryptographic policies. This configuration allows for rapid updates to the cryptographic framework and for the cryptographic framework to be managed remotely in enterprise environments.