Applied Key Management Server for PKI Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption key management systems face synchronization issues between device-level encryption management and communication management, leading to loose controls and potential breakdowns in communication security, particularly in public key infrastructure (PKI) and symmetric key distribution within enterprises.

Innovation Solution

A client-based applied key management system that enables centralized key management, distribution, and federation, using a policy-based approach to authorize and manage encryption keys, including public key distribution for secure communications, by integrating with Public Key Infrastructure (PKI) and supporting automated key management operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If device-level encryption key management is implemented, then encryption control is decentralized and flexible, but synchronization with communication management breaks down and security control becomes loose

Engineering Contradiction:
Improvedecentralized key management flexibilityVSAvoidcommunication security synchronization
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a key management server as an intermediary between communication management and device-level encryption operations. This server receives communication management instructions, generates corresponding encryption key management instructions, and distributes them to terminal devices. This intermediary layer ensures that device-level key management remains flexible while maintaining synchronization with communication management, resolving the contradiction between operational ease and security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized communication management is implemented, then communication control is coordinated, but encryption key management becomes procedurally unsynchronized and loose controls occur

Engineering Contradiction:
Improvecommunication control coordinationVSAvoidencryption management synchronization
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key management system into distinct functional modules: a communication management module that handles communication coordination, and a key management module that handles encryption operations. These modules operate semi-independently but are linked through defined instruction interfaces. This segmentation allows centralized communication management to maintain coordination while the key management module handles encryption synchronization separately, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If separate key distribution activities are implemented for different applications, then specific application security needs are met, but key management complexity increases

Engineering Contradiction:
Improveapplication-specific security supportVSAvoidkey management operations
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal key management server that can handle multiple application types (messaging, email, communication apps) through a single platform. This server provides unified key generation, distribution, and management capabilities that adapt to different application requirements without requiring separate key management systems for each application. This multi-functional approach maintains application-specific security needs while significantly reducing key management complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10560440B2Server-client PKI for applied key management system and process
Publication Date: 2020.02.11 FORNETIX LLC
  • US10560440B2 patent drawing
  • US10560440B2 patent drawing
  • US10560440B2 patent drawing

AI summary

Embodiments described herein relate to obtaining a public key for an application of a communication device, including, but not limited to, receiving a request from the communication device to obtain the public key, evaluating the request based on at least one policy, requesting the public key from a public key infrastructure (PKI) in response to determining that the request is authorized, receiving the public key from the PKI, and sending the public key to the communication device.