Rule-Based Cryptographic Key Validity Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems lack the ability to dynamically manage cryptographic key material based on real-time conditions and geographical locations, leading to potential security vulnerabilities and inefficiencies in access control.

Innovation Solution

Implementing a rule-based system that associates cryptographic key material with a set of rules, including time schedules, geo-fences, and quorum requirements, to determine its validity and usage in authentication processes, allowing for conditional suspension or reinstatement of key material based on compliance with these rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic key material is used for authentication without rule-based restrictions, then authentication speed and ease of operation are improved, but security and access control precision deteriorate

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies dynamics by making cryptographic key material dynamically valid or invalid based on rule compliance rather than being statically valid. The key material's effectiveness changes dynamically according to whether the client system complies with specified rules (geographic location, time schedules, quorum requirements), allowing security constraints to be enforced without requiring continuous re-authentication

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements feedback by continuously monitoring rule compliance status and using this information to determine key material validity. The system evaluates whether the client system complies with applicable rules and adjusts the cryptographic key material's effectiveness accordingly, creating a feedback loop that maintains security while enabling efficient authentication

Inventive Principle:
Principle #23Feedback

2Reliability

If rule-based restrictions are applied to cryptographic key material, then security and access control precision are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by introducing a rule evaluation mechanism that acts as a mediator between the client system and the cryptographic key material validation process. This intermediary evaluates rule compliance and determines key material validity, centralizing the complexity of rule management while keeping the authentication process itself relatively simple

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies universality by creating a rule-based validation system that can handle multiple types of rules (geographic location, time schedules, quorum requirements) through a unified framework. This multi-functional approach allows diverse security requirements to be enforced through a single rule evaluation mechanism, reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If cryptographic key material validity is made dynamic based on rules, then adaptability to different conditions is improved, but measurement and detection difficulty increases

Engineering Contradiction:
Improvedynamic key managementVSAvoidrule compliance verification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements self-service by requiring the client system to autonomously determine its own rule compliance status and use this information to validate its cryptographic key material. The client system evaluates whether it complies with applicable rules and independently determines key material effectiveness, reducing the burden on external systems to verify compliance

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9531533B2Rule-based validity of cryptographic key material
Publication Date: 2016.12.27 CYBERARK SOFTWARE INC
  • US9531533B2 patent drawing
  • US9531533B2 patent drawing
  • US9531533B2 patent drawing

AI summary

In representative embodiments, a rule-based certificate cryptographic key material comprising containing a rule set defining validity conditions is associated with cryptographic key material assigned to an entity for use in authenticated communications. The validity of the cryptographic material changes state based on whether the entity is compliant or non-compliant with the rule set. This is accomplished in a representative embodiment by suspending the validity of the cryptographic key material when the entity is non-compliant with the rules and reinstating the validity of the cryptographic key material when the entity becomes compliant. A rules compliance service determines the validity of the cryptographic material in part using updates sent by the entity. Entities can delegate the update to a delegate device. Encryption can be used to preserve privacy.