Proof-of-Work Key Wrapping for Attribute-Based Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic systems for controlling access to data rely solely on key possession, which is insufficient for sophisticated access control mechanisms that require considerations of time, computing resources, and device attributes, and often necessitate a separate trusted third party for verification, making the system complex and vulnerable.

Innovation Solution

Integration of a proof-of-work key wrapping mechanism that encrypts cryptographic keys, allowing recipient devices to derive the unwrap key by completing a computational puzzle that consumes specific computing resources, thereby eliminating the need for a third-party verification and enhancing access control with attributes-based access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional cryptographic key possession is used for access control, then access can be granted simply, but the system lacks sophistication and requires separate trusted third party verification

Engineering Contradiction:
Improveaccess control sophisticationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines proof-of-work computational requirements directly into the key wrapping mechanism. The wrapped key now embeds both cryptographic protection and proof-of-work verification, eliminating the need for separate trusted third party verification systems while maintaining sophisticated access control capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The wrapped key structure serves multiple functions simultaneously: it provides cryptographic encryption protection, embeds device attribute requirements, specifies computing resource consumption rules, and enables self-verification without external trustees. This multi-functionality resolves the contradiction by making the access control system both sophisticated and self-contained.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If proof-of-work key wrapping is implemented, then access control includes device capabilities and resource consumption, but the key derivation process requires significant computing resources

Engineering Contradiction:
Improveaccess control securityVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies different computational requirements to different devices based on their capabilities. The proof-of-work parameters embedded in the wrapped key are tailored to match specific device attributes, ensuring that each device performs computations appropriate to its processing power and resource availability, thus balancing security with energy efficiency.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The proof-of-work difficulty and resource requirements are dynamically adjusted based on device capabilities rather than being static. The wrapped key contains adaptive parameters that allow the computational puzzle to scale with the device's processing power, ensuring reliable security verification while preventing excessive energy consumption on resource-constrained devices.

Inventive Principle:
Principle #15Dynamics

3Reliability

If third-party verification is used for proof-of-work, then access control is verified, but the system becomes more complex and vulnerable

Engineering Contradiction:
Improveverification accuracyVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The wrapped key contains all necessary verification information and parameters embedded within its structure, allowing the receiving device to independently verify the proof-of-work without contacting external verification services. This self-contained approach maintains verification reliability while eliminating the complexity and vulnerability introduced by third-party verification infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11424920B2Proof-of-work key wrapping for cryptographically controlling data access
Publication Date: 2022.08.23 RED HAT INC
  • US11424920B2 patent drawing
  • US11424920B2 patent drawing
  • US11424920B2 patent drawing

AI summary

The technology disclosed herein provides a proof-of-work key wrapping system that cryptographically controls access to data. An example method may include: selecting a set of cryptographic attributes in view of a characteristic of a computing device; obtaining, by a processing device, a cryptographic key; encrypting, by the processing device, the cryptographic key in view of the set of cryptographic attributes to produce a wrapped key; and providing the wrapped key and at least one of the cryptographic attributes to the computing device, wherein the at least one cryptographic attribute facilitates deriving the cryptographic key from the wrapped key.