AI Camera Encryption Key Generation Through Hierarchical Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing AI camera systems face challenges in efficiently updating encryption keys due to the management of multiple types of keys by system administrators and customers, making it difficult to respond to key leakage and maintain security.

Innovation Solution

An information processing apparatus that creates a combination encryption key using a master key, customer management key, and key generation information, allowing for easy updates by customers through a system administrator interface, ensuring secure deployment and transmission of AI software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple types of keys are managed separately by system administrators and customers, then security is maintained through key distribution, but key update complexity increases and labor requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey update complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption key is segmented into multiple components: a first type key stored in the imaging apparatus, a second type key managed by the customer, and a third type key managed by the system administrator. This segmentation allows each party to manage only their portion, reducing overall complexity while maintaining security through distributed key management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary key combination mechanism where the decryption key is formed by combining the first type key (from imaging apparatus) and the second type key (from customer). The third type key serves as a mediator that can regenerate the combination key, enabling secure updates without requiring direct access to all original key components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are updated in response to key leakage, then security is maintained, but the labor required for key updates increases when multiple key types are managed

Engineering Contradiction:
ImprovesecurityVSAvoidkey update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system extracts the update capability to a specific component (the third type key managed by the system administrator) that can independently regenerate the combination key. When key leakage occurs, only the third type key needs to be updated, and the new combination key can be automatically generated without requiring updates to the first or second type keys, significantly reducing update time and labor.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary setup by establishing the key combination structure and storage locations before any security incidents occur. The first type key is pre-stored in the imaging apparatus, the second type key is pre-distributed to customers, and the third type key is pre-managed by administrators. This preliminary configuration enables rapid response to key leakage events without requiring complex real-time coordination.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If AI software is encrypted and transmitted to AI cameras, then security against third-party abuse is improved, but key management complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The encryption system is segmented into multiple key components with different management responsibilities. The first type key remains in the imaging apparatus, the second type key is managed by customers for their AI cameras, and the third type key is managed by system administrators. This segmentation makes key management easier by distributing responsibilities according to each party's capabilities and needs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each party in the system serves themselves with their assigned key component. Customers can independently manage their second type keys and decrypt AI software for their own cameras without requiring system administrator intervention. The imaging apparatus automatically uses its first type key for decryption operations. This self-service approach simplifies key management operations for all parties involved.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250286702A1Information processing apparatus, information processing method, and recording medium
Publication Date: 2025.09.11 SONY SEMICON SOLUTIONS CORP
  • US20250286702A1 patent drawing
  • US20250286702A1 patent drawing
  • US20250286702A1 patent drawing

AI summary

To reduce labor related to an update of an encryption key in response to an encryption request for the AI software specifying the third type key, encryption key leakage or the like.An information processing apparatus according to the present technology includes an encryption key creation part that creates an encryption key on a basis of a first type key stored in advance in an imaging apparatus, a second type key different from the first type key, and a third type key that is different from the first type key and the second type key and is a key multiplied with the second type key to create a combination key stored in the imaging apparatus, or is a key stored in the imaging apparatus together with the second type key, as an encryption key used by the imaging apparatus for encryption of artificial intelligence (AI) software including at least software of an artificial intelligence model, the imaging apparatus performing image recognition processing using the artificial intelligence model on a captured image obtained by capturing an image of a subject, the encryption key creation part creating, in response to specification of a key derived from new information different from original information as the third type key, a new encryption key based on the third type key derived from the new information, the first type key, and the second type key on a basis of the new information.