Temporal Key Derivation for Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cryptographic access control mechanisms rely solely on key possession, which is insufficient for sophisticated access control and can be circumvented by compromised executable rules, lacking the security and precision needed for modern computer systems.

Innovation Solution

Integrating temporal, location, and contextual data into the cryptographic key creation process, using conversion data from a trusted source to transform contextual data into cryptographic values, thereby enhancing access control criteria and reducing the risk of rule-based access layer compromise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cryptographic access control mechanisms are used that rely solely on key possession, then the system is simple to operate, but the security is insufficient and can be circumvented by compromised executable rules

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms access control from a single-dimensional key possession model to a multi-dimensional model by incorporating temporal data (time, date, duration) as additional dimensions. The cryptographic key is derived not just from a secret password but from the combination of the password with temporal context, creating a higher-dimensional security space that is resistant to traditional compromise methods

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent changes the parameters of key derivation by introducing temporal parameters (current time, date, duration since last access) into the cryptographic function. Instead of using a static key, the system dynamically generates keys based on temporal state, making the key space vastly larger and more secure while maintaining operational simplicity through automated temporal tracking

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If executable rules are layered above cryptographic techniques to provide additional access control criteria, then the access control precision is improved, but the system becomes vulnerable to rule circumvention and compromise

Engineering Contradiction:
Improveaccess control precisionVSAvoidsecurity against compromise
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent merges the cryptographic layer and the access control rule layer into a single unified operation. Instead of having executable rules sit above cryptography that can be circumvented, the temporal access control criteria are embedded directly into the cryptographic key derivation process itself, making the rules inseparable from the cryptographic verification and eliminating the vulnerability of rule-layer compromise

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent uses temporal data as an intermediary that bridges the gap between simple key possession and complex rule-based access control. The temporal context (time, date, duration) acts as a mediator that is automatically verified through the cryptographic function, providing precise access control without requiring vulnerable executable rule layers

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If temporal data is integrated into the cryptographic key creation process, then the security and precision of access control are enhanced, but the computational complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by having the system automatically track and manage temporal data without requiring additional computational overhead for manual intervention. The temporal context (current time, date, duration since last access) is automatically captured by the system's operating components, and this self-generated temporal data is fed into the cryptographic function, enhancing security while minimizing added complexity through automated self-management

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11784809B2Constrained key derivation in temporal space
Publication Date: 2023.10.10 RED HAT INC
  • US11784809B2 patent drawing
  • US11784809B2 patent drawing
  • US11784809B2 patent drawing

AI summary

The technology disclosed herein provides an enhanced cryptographic access control mechanism that uses cryptographic keys that are based on temporal data. An example method may include: determining temporal data of a computing device; transforming the temporal data in view of conversion data associated with the computing device, wherein the conversion data causes a set of alternate temporal data values to transform to a specific cryptographic value; creating, by a processing device, a cryptographic key in view of the transformed temporal data; and using the cryptographic key to enable access to a protected resource.