Authorization Server Segments Constrained Devices for Secure Crypto Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Constrained devices in networks face challenges in maintaining secure communication due to the need for simultaneous updates of cryptographic algorithms and keys across all devices, which is impractical and costly, especially as cryptanalytic capabilities advance and obsolete algorithms are no longer secure.

Innovation Solution

An authorization server issues cryptographic communication rights and updates cryptographic code modules in subsets of constrained devices that share compatible algorithms and keys, using asymmetric or symmetric key-based configuration certificates or tickets, ensuring only compatible devices communicate and minimizing memory usage by storing a single cryptographic algorithm code module per function.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic algorithms and keys are updated across all devices simultaneously to maintain security, then network security is improved, but device complexity and operational cost increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidcryptographic algorithm support
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network devices into groups based on their cryptographic algorithm compatibility. Each device is assigned to a segment (group) that shares common cryptographic algorithms and keys. When security updates are needed, only the affected segments are updated rather than all devices simultaneously. This segmentation allows devices to maintain single-algorithm support while the network as a whole maintains security through coordinated segment updates.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If all devices support multiple cryptographic algorithms to enable flexible communication, then adaptability is improved, but memory usage and device cost increase

Engineering Contradiction:
Improvealgorithm compatibilityVSAvoidmemory storage
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by assigning different cryptographic algorithm capabilities to different device segments based on their specific communication requirements. Each device is configured with the specific cryptographic algorithm (symmetric or asymmetric) that matches its communication partners in its segment. This localized configuration ensures that each device has the appropriate cryptographic capability for its specific context without all devices needing to support all possible algorithms, thereby reducing memory usage while maintaining necessary adaptability.

Inventive Principle:
Principle #3Local quality

3Reliability

If cryptographic keys are updated frequently to counter advancing cryptanalytic capabilities, then security is improved, but loss of time and operational disruption increase

Engineering Contradiction:
Improvecryptographic securityVSAvoidupdate coordination time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing cryptographic key pairs (including both symmetric and asymmetric keys) and algorithm configurations for each device segment before security updates are needed. When security updates are required, the system can quickly switch to pre-prepared alternative keys and algorithms within the same segment without requiring time-consuming coordination with all devices. This preliminary preparation significantly reduces the time loss associated with cryptographic updates while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3326321B1Method and apparatus for providing secure communication among constrained devices
Publication Date: 2021.10.27 ENTRUST INC
  • EP3326321B1 patent drawingFigure 1
  • EP3326321B1 patent drawingFigure 2
  • EP3326321B1 patent drawingFigure 3

AI summary

In one example, an apparatus such as an authorization server and method for secure communication between constrained devices issues cryptographic communication rights among a plurality of constrained devices. Each of the plurality of constrained devices comprises no more than one cryptographic algorithm code module per cryptographic function. The method includes receiving a cryptographic communication rights request associated with at least a first of the plurality of constrained devices in response to a cryptographic algorithm update request, and includes providing a response including an identification of a subset of the plurality of constrained devices that have cryptographic communication rights with the identified first of the plurality of constrained devices. A software update server then updates the cryptographic code modules in the sub-set of the plurality of constrained devices.