Authenticated Group Key Agreement in Ad-Hoc Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Establishing a secure communication session among multiple devices without a prior context or experienced security administrator is challenging, especially in ad-hoc networks, as existing methods are not user-friendly for non-expert users.

Innovation Solution

A multi-party data integrity protocol is introduced, where devices share and verify a common data commitment using non-secret checksums, enabling authenticated group Diffie-Hellman key agreement, allowing secure formation of a security association among devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional key agreement methods are used in multi-party scenarios, then security can be established, but the process becomes complex and difficult for non-expert users to operate

Engineering Contradiction:
ImprovesecurityVSAvoiduser-friendliness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a trusted third party (TTP) that acts as an intermediary to facilitate key agreement among multiple parties. The TTP generates and distributes secret shares to each participant, enabling them to collaboratively derive a shared secret without directly interacting with each other. This mediator approach simplifies the user experience while maintaining cryptographic security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the secret key into multiple shares using secret sharing schemes (such as Shamir's Secret Sharing). Each participant receives a portion of the secret (a share) rather than the complete key. The secret can only be reconstructed when a sufficient number of shares are combined, providing both security and simplified operation for non-expert users.

Inventive Principle:
Principle #1Segmentation

2Reliability

If prior context or central authority certificates are required for secure communication, then authentication is strengthened, but the setup process becomes more complex and requires experienced security administrators

Engineering Contradiction:
ImproveauthenticationVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables participants to autonomously generate their own key pairs and receive secret shares directly from the trusted third party without requiring manual configuration or intervention from security administrators. Each device performs self-registration and automatically receives its cryptographic credentials, eliminating the need for complex manual setup.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The trusted third party serves as an intermediary that issues cryptographic credentials (secret shares and public keys) to participants. This mediator approach replaces the need for complex certificate authorities and manual trust establishment, allowing non-expert users to securely authenticate while maintaining simplified operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multi-party key agreement is implemented without a trusted third party, then system autonomy is improved, but security reliability decreases in ad-hoc scenarios

Engineering Contradiction:
Improvesystem autonomyVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a trusted third party as a lightweight mediator that provides essential security functions (key share distribution and verification) without requiring continuous involvement or complex infrastructure. This approach maintains system autonomy for actual communication operations while providing reliable security through the intermediary's initial setup and verification roles.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8386782B2Authenticated group key agreement in groups such as ad-hoc scenarios
Publication Date: 2013.02.26 NOKIA TECHNOLOGIES OY

AI summary

The invention provides a method, system, device and computer program product for setting up a secure session among three or more devices or parties of a communication group, including authenticating a key agreement between the devices or parties of the communication group, wherein the devices of the group start, preferably after a key is computed or agreed, a protocol, preferably a multi-party data integrity protocol, for authenticating the key agreement.