Rule-Based Cryptographic Key Material Validity Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems lack the ability to dynamically manage cryptographic key material based on real-time conditions and rules, leading to potential security vulnerabilities and inefficiencies in access control.

Innovation Solution

Implementing a rule-based system that associates cryptographic key material with a set of rules, including time schedules, geo-fences, and quorum requirements, to determine its validity and usage in authentication processes, allowing for conditional suspension or reinstatement of key material based on compliance with these rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic key material is used for authentication without rule-based restrictions, then authentication speed and ease of operation are improved, but security and access control precision deteriorate

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic rule sets that are evaluated in real-time during authentication. The rule sets can be modified, added, or removed without regenerating cryptographic key material, allowing the system to adapt security requirements dynamically while maintaining authentication efficiency. This resolves the contradiction by making security constraints flexible rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent separates cryptographic key material from security policy rules. The key material remains unchanged while rule sets are independently managed and evaluated. This segmentation allows security requirements to be modified without affecting the cryptographic foundation, maintaining both security and operational efficiency.

Inventive Principle:
Principle #1Segmentation

2Reliability

If rule-based restrictions are added to cryptographic key material, then security and access control are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal rule evaluation framework that works across different authentication contexts and cryptographic key types. The same rule evaluation service handles diverse rule sets (time-based, location-based, behavior-based) uniformly, reducing the need for multiple specialized systems and minimizing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary rule evaluation service that mediates between the authentication system and security policies. This intermediary layer simplifies the architecture by centralizing rule management and evaluation logic, preventing complexity from propagating through the entire system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If cryptographic key material is suspended or reinstated based on rules, then unauthorized access is reduced, but authentication process time increases

Engineering Contradiction:
Improveunauthorized accessVSAvoidauthentication process time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The patent performs rule evaluation准备工作 in advance by maintaining ready-to-evaluate rule sets and pre-established suspension/reinstatement criteria. When authentication is needed, the system quickly evaluates pre-loaded rules rather than constructing evaluation logic from scratch, significantly reducing authentication process time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements efficient feedback mechanisms where the rule evaluation service provides rapid validity determinations to the authentication system. The feedback loop is optimized to minimize delays, with the system able to quickly determine whether key material is suspended or valid based on current rule evaluations.

Inventive Principle:
Principle #23Feedback

4Measurement precision

If rule sets are evaluated for each authentication attempt, then access control precision is improved, but computational overhead and energy consumption increase

Engineering Contradiction:
Improveaccess control precisionVSAvoidcomputational overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent maintains continuous rule evaluation capability by keeping rule sets actively loaded and ready for evaluation. Rather than periodically refreshing rules or reloading them, the system continuously maintains evaluation readiness, allowing rapid access control decisions without repeated setup overhead, thus reducing energy consumption per authentication attempt.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9577823B2Rule-based validity of cryptographic key material
Publication Date: 2017.02.21 CYBERARK SOFTWARE INC
  • US9577823B2 patent drawing
  • US9577823B2 patent drawing
  • US9577823B2 patent drawing

AI summary

In representative embodiments, a rule-based certificate cryptographic key material comprising containing a rule set defining validity conditions is associated with cryptographic key material assigned to an entity for use in authenticated communications. The validity of the cryptographic material changes state based on whether the entity is compliant or non-compliant with the rule set. This is accomplished in a representative embodiment by suspending the validity of the cryptographic key material when the entity is non-compliant with the rules and reinstating the validity of the cryptographic key material when the entity becomes compliant. A rules compliance service determines the validity of the cryptographic material in part using updates sent by the entity. Entities can delegate the update to a delegate device. Encryption can be used to preserve privacy.