AI Camera Encryption Key Generation Through Hierarchical Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing AI camera systems face challenges in efficiently updating encryption keys due to the management of multiple types of keys by system administrators and customers, making it difficult to respond to key leakage and maintain security.
Innovation Solution
An information processing apparatus that creates a combination encryption key using a master key, customer management key, and key generation information, allowing for easy updates by customers through a system administrator interface, ensuring secure deployment and transmission of AI software.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple types of keys are managed separately by system administrators and customers, then security is maintained through key distribution, but key update complexity increases and labor requirements increase
Solution Approach 1:
The encryption key is segmented into multiple components: a first type key stored in the imaging apparatus, a second type key managed by the customer, and a third type key managed by the system administrator. This segmentation allows each party to manage only their portion, reducing overall complexity while maintaining security through distributed key management.
Solution Approach 2:
The system introduces an intermediary key combination mechanism where the decryption key is formed by combining the first type key (from imaging apparatus) and the second type key (from customer). The third type key serves as a mediator that can regenerate the combination key, enabling secure updates without requiring direct access to all original key components.
2Reliability
If encryption keys are updated in response to key leakage, then security is maintained, but the labor required for key updates increases when multiple key types are managed
Solution Approach 1:
The system extracts the update capability to a specific component (the third type key managed by the system administrator) that can independently regenerate the combination key. When key leakage occurs, only the third type key needs to be updated, and the new combination key can be automatically generated without requiring updates to the first or second type keys, significantly reducing update time and labor.
Solution Approach 2:
The system performs preliminary setup by establishing the key combination structure and storage locations before any security incidents occur. The first type key is pre-stored in the imaging apparatus, the second type key is pre-distributed to customers, and the third type key is pre-managed by administrators. This preliminary configuration enables rapid response to key leakage events without requiring complex real-time coordination.
3Reliability
If AI software is encrypted and transmitted to AI cameras, then security against third-party abuse is improved, but key management complexity increases
Solution Approach 1:
The encryption system is segmented into multiple key components with different management responsibilities. The first type key remains in the imaging apparatus, the second type key is managed by customers for their AI cameras, and the third type key is managed by system administrators. This segmentation makes key management easier by distributing responsibilities according to each party's capabilities and needs.
Solution Approach 2:
Each party in the system serves themselves with their assigned key component. Customers can independently manage their second type keys and decrypt AI software for their own cameras without requiring system administrator intervention. The imaging apparatus automatically uses its first type key for decryption operations. This self-service approach simplifies key management operations for all parties involved.
Data Source
AI summary
To reduce labor related to an update of an encryption key in response to an encryption request for the AI software specifying the third type key, encryption key leakage or the like.An information processing apparatus according to the present technology includes an encryption key creation part that creates an encryption key on a basis of a first type key stored in advance in an imaging apparatus, a second type key different from the first type key, and a third type key that is different from the first type key and the second type key and is a key multiplied with the second type key to create a combination key stored in the imaging apparatus, or is a key stored in the imaging apparatus together with the second type key, as an encryption key used by the imaging apparatus for encryption of artificial intelligence (AI) software including at least software of an artificial intelligence model, the imaging apparatus performing image recognition processing using the artificial intelligence model on a captured image obtained by capturing an image of a subject, the encryption key creation part creating, in response to specification of a key derived from new information different from original information as the third type key, a new encryption key based on the third type key derived from the new information, the first type key, and the second type key on a basis of the new information.


