Secure Asset Management Infrastructure for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic management systems are unable to effectively prevent malicious operators from bypassing security protocols and executing unauthorized use cases on appliance devices, compromising the security of sensitive data assets.

Innovation Solution

Implementing secure access control policies through a root device that generates client credentials and access control policies, which are enforced by a hardware security module to ensure only authorized use cases are executed on appliance devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are stored in one-time programmable memory and loaded in a secured facility, then security is provided, but the system cannot prevent malicious operators from bypassing security protocols on appliance devices

Engineering Contradiction:
ImprovesecurityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the cryptographic management into multiple segments: root device for policy generation, appliance devices for execution, and hardware security modules for key protection. This segmentation isolates the key management functions from the appliance devices, preventing malicious operators from bypassing security protocols on the appliance devices while maintaining security through distributed control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces hardware security modules as intermediaries between the root device and appliance devices. These modules enforce access control policies and manage cryptographic keys securely, acting as a mediator that prevents direct unauthorized access to the appliance devices while allowing authorized operations to proceed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If access control policies are enforced through software on appliance devices, then flexibility is provided, but security protocols can be bypassed by malicious operators

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces software-based access control with hardware-based enforcement through hardware security modules. These modules provide tamper-resistant enforcement of access control policies, maintaining the flexibility of policy definition while eliminating the vulnerability of software protocols that can be bypassed by malicious operators.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system combines software policy definition with hardware enforcement capabilities. The access control policies are defined in software on the root device but enforced through hardware security modules on the appliance devices, creating a composite security architecture that provides both flexibility and reliability.

Inventive Principle:
Principle #40Composite materials

3Reliability

If multiple platforms are used to provision secure data assets, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware security modules are designed to perform multiple functions: key generation, key storage, access control policy enforcement, and secure data asset provisioning. This multi-functionality reduces the need for separate dedicated components for each security function, thereby managing system complexity while maintaining enhanced security through multiple platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250023872A1Secure asset management infrastructure for enforcing access control policies
Publication Date: 2025.01.16 CRYPTOGRAPHY RESEARCH INC
  • US20250023872A1 patent drawing
  • US20250023872A1 patent drawing
  • US20250023872A1 patent drawing

AI summary

An application executing at a first platform receives, from a tester device, a first request to generate a secure data asset. Responsive to authenticating the client, the application sends, to a second platform, a second request to determine whether the client has access to the secure data asset. Responsive to receiving an indication, from the second platform, that the client has access to the secure data asset, the application performs one or more operations to generate the secure data asset. The application sends, to the tester device, the generated secure data asset.