256-Bit Key Update Protocol for Quantum-Resistant Transport Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic key update protocols, such as the AUTomotive Open System Architecture (AUTOSAR) secure hardware extension, are inadequate for updating cryptographic keys to 256-bit lengths, which are necessary for post-quantum security, as they do not provide sufficient transport security and are vulnerable to quantum computers.

Innovation Solution

A cryptographic key update system that employs a series of transmissions using advanced encryption standard (AES) and hash functions to securely update cryptographic keys to 256-bits, including symmetric key encryption, message authentication codes, and cryptographic validation operations, ensuring compatibility with existing systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the current AUTOSAR secure hardware extension key update protocol is used, then the system maintains compatibility with existing protocols and networks, but the transport security is weaker than required for 256-bit key updates

Engineering Contradiction:
Improvetransport securityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key update protocol is divided into multiple distinct transmission stages (first transmission for parameters, second transmission for encrypted key, third transmission for authentication). Each transmission serves a specific security function, allowing the system to achieve 256-bit security requirements while maintaining modularity and manageable complexity in each individual protocol step.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cryptographic keys are updated to 256-bit length for post-quantum security, then resistance against quantum and classical attacks is enhanced, but the current protocol infrastructure becomes insufficient

Engineering Contradiction:
Improvequantum resistanceVSAvoidprotocol compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The protocol transitions from 128-bit key parameters to 256-bit key parameters across multiple transmission stages. The first transmission carries 256-bit parameters, the second transmission encrypts 256-bit keys, and the third transmission provides 256-bit authentication, systematically upgrading the cryptographic parameter strength to achieve quantum resistance while adapting the existing protocol framework.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If simple updates of the current secure hardware extension key update protocol are implemented, then the system maintains ease of implementation, but the transport security remains insufficient for 256-bit keys

Engineering Contradiction:
Improvetransport securityVSAvoidimplementation simplicity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The first transmission pre-establishes security parameters and authentication mechanisms before the actual key update occurs. By preparing the cryptographic context, parameters, and authentication keys in advance through the first transmission, the protocol ensures that subsequent key transmissions are protected with adequate 256-bit security without requiring complex real-time cryptographic operations during the key update itself.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12562899B1Cryptographic key update system for updating 256-bit cryptographic keys
Publication Date: 2026.02.24 GM GLOBAL TECHNOLOGY OPERATIONS LLC
  • US12562899B1 patent drawing
  • US12562899B1 patent drawing
  • US12562899B1 patent drawing

AI summary

Methods for updating 256-bit cryptographic keys by a cryptographic key update system include transmitting a first transmission, a second transmission, and a third transmission. The second transmission is a symmetric key encryption under a key encryption key of a concatenation of a plurality of parameters and a new cryptographic key. The sender derives the key encryption key by transforming an authentication key and a bit string of constant values based on a one-way compression function that is one of the following: a modification detection code 2 (MDC-2) cryptographic hash function with a 128-bit advanced encryption standard (AES-128) as the underlying block cipher, a modification detection code 4 (MDC-4) cryptographic hash function with the 128-bit advanced encryption standard (AES-128) as the underlying block cipher, the Hirose compression function with the 256-bit advanced encryption standard (AES-256) as the underlying block cipher, and a 256-bit hash function.