Selective Security Data Refresh Through Distributed Authority

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security frameworks for distributed systems rely on a single certificate authority, making them vulnerable to compromise, which can lead to widespread system compromise if the authority is compromised or unable to timely update security data.

Innovation Solution

Implement a security framework that distributes authority across the distributed system based on a hierarchy established using weighted reputations of data processing systems, allowing for local refreshes of security data to limit the impact of compromised systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single certificate authority is used to manage security data, then the security framework is simpler to implement, but the system becomes vulnerable to widespread compromise if the authority is compromised or unable to timely update security data

Engineering Contradiction:
Improvesecurity framework structureVSAvoidsystem security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the centralized certificate authority into multiple distributed certificate authorities organized in a hierarchical structure. Each CA manages a specific subset of data processing systems, dividing the security management function across multiple independent entities. This segmentation prevents a single point of failure and limits the scope of compromise to specific hierarchical segments rather than the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to the security framework, organizing certificate authorities and data processing systems into multiple levels. This hierarchical structure adds a dimensional layer that enables localized security management while maintaining overall system coherence. The hierarchy allows security updates to propagate through defined paths rather than requiring universal distribution.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If security data is refreshed across the entire distributed system, then all systems receive updated security data, but resource costs increase significantly

Engineering Contradiction:
Improvesecurity data freshnessVSAvoidresource cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements local quality by enabling selective security data refreshes within specific hierarchical segments rather than uniformly across the entire system. When a compromise is detected or security updates are needed, only the affected local segments receive refreshed security data. This localized approach maintains security data freshness where needed while avoiding unnecessary resource consumption in unaffected areas.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial action by performing security data refreshes only on the necessary portions of the system rather than complete system-wide updates. The hierarchical structure enables identification of minimal required segments for refresh, performing exactly the amount of action needed to maintain security without excessive resource expenditure on redundant updates.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If the hierarchy is updated frequently to maintain security, then security postures are accurately reflected, but system performance and stability are impacted

Engineering Contradiction:
Improvesecurity posture accuracyVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements periodic action by updating security data and hierarchy information at controlled intervals rather than continuously or on every security event. The hierarchical structure enables batching of security updates and propagation through defined cycles, allowing the system to maintain accurate security postures while avoiding constant reconfiguration that would degrade performance. Updates occur periodically when security data changes are detected at the source.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12368759B2System and method for selective refresh of security data responsive to compromise event
Publication Date: 2025.07.22 DELL PROD LP
  • US12368759B2 patent drawing
  • US12368759B2 patent drawing
  • US12368759B2 patent drawing

AI summary

Methods and systems for securing distributed systems are disclosed. The distributed systems may include data processing systems subject to compromise by malicious entities. If compromised, the data processing systems may impair the services provided by the distributed system. To secure the distributed systems, the data processing systems may implement a security framework. The security framework may utilize a hierarchy that defines authority for validating trusted entities. The hierarchy may vest authority across the distributed system, and may be based on a reputation (e.g., weighted reputation) of each of the data processing systems within the distributed system. If the reputation of a data processing system meets criteria, the data processing system may be treated as being compromised and a local refresh of security data may be performed. Consequently, the impact of compromise of the data processing system may be limited by the distributed authority.