Proof-of-Work Key Wrapping for Attribute-Based Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptographic systems for controlling access to data rely solely on key possession, which is insufficient for sophisticated access control mechanisms that require considerations of time, computing resources, and device attributes, and often necessitate a separate trusted third party for verification, making the system complex and vulnerable.
Innovation Solution
Integration of a proof-of-work key wrapping mechanism that encrypts cryptographic keys, allowing recipient devices to derive the unwrap key by completing a computational puzzle that consumes specific computing resources, thereby eliminating the need for a third-party verification and enhancing access control with attributes-based access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional cryptographic key possession is used for access control, then access can be granted simply, but the system lacks sophistication and requires separate trusted third party verification
Solution Approach 1:
The patent combines proof-of-work computational requirements directly into the key wrapping mechanism. The wrapped key now embeds both cryptographic protection and proof-of-work verification, eliminating the need for separate trusted third party verification systems while maintaining sophisticated access control capabilities.
Solution Approach 2:
The wrapped key structure serves multiple functions simultaneously: it provides cryptographic encryption protection, embeds device attribute requirements, specifies computing resource consumption rules, and enables self-verification without external trustees. This multi-functionality resolves the contradiction by making the access control system both sophisticated and self-contained.
2Reliability
If proof-of-work key wrapping is implemented, then access control includes device capabilities and resource consumption, but the key derivation process requires significant computing resources
Solution Approach 1:
The patent applies different computational requirements to different devices based on their capabilities. The proof-of-work parameters embedded in the wrapped key are tailored to match specific device attributes, ensuring that each device performs computations appropriate to its processing power and resource availability, thus balancing security with energy efficiency.
Solution Approach 2:
The proof-of-work difficulty and resource requirements are dynamically adjusted based on device capabilities rather than being static. The wrapped key contains adaptive parameters that allow the computational puzzle to scale with the device's processing power, ensuring reliable security verification while preventing excessive energy consumption on resource-constrained devices.
3Reliability
If third-party verification is used for proof-of-work, then access control is verified, but the system becomes more complex and vulnerable
Solution Approach 1:
The wrapped key contains all necessary verification information and parameters embedded within its structure, allowing the receiving device to independently verify the proof-of-work without contacting external verification services. This self-contained approach maintains verification reliability while eliminating the complexity and vulnerability introduced by third-party verification infrastructure.
Data Source
AI summary
The technology disclosed herein provides a proof-of-work key wrapping system that cryptographically controls access to data. An example method may include: selecting a set of cryptographic attributes in view of a characteristic of a computing device; obtaining, by a processing device, a cryptographic key; encrypting, by the processing device, the cryptographic key in view of the set of cryptographic attributes to produce a wrapped key; and providing the wrapped key and at least one of the cryptographic attributes to the computing device, wherein the at least one cryptographic attribute facilitates deriving the cryptographic key from the wrapped key.


