Authorization Server Segments Constrained Devices for Secure Crypto Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Constrained devices in networks face challenges in maintaining secure communication due to the need for simultaneous updates of cryptographic algorithms and keys across all devices, which is impractical and costly, especially as cryptanalytic capabilities advance and obsolete algorithms are no longer secure.
Innovation Solution
An authorization server issues cryptographic communication rights and updates cryptographic code modules in subsets of constrained devices that share compatible algorithms and keys, using asymmetric or symmetric key-based configuration certificates or tickets, ensuring only compatible devices communicate and minimizing memory usage by storing a single cryptographic algorithm code module per function.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic algorithms and keys are updated across all devices simultaneously to maintain security, then network security is improved, but device complexity and operational cost increase significantly
Solution Approach 1:
The patent segments the network devices into groups based on their cryptographic algorithm compatibility. Each device is assigned to a segment (group) that shares common cryptographic algorithms and keys. When security updates are needed, only the affected segments are updated rather than all devices simultaneously. This segmentation allows devices to maintain single-algorithm support while the network as a whole maintains security through coordinated segment updates.
2Adaptability or versatility
If all devices support multiple cryptographic algorithms to enable flexible communication, then adaptability is improved, but memory usage and device cost increase
Solution Approach 1:
The patent applies local quality by assigning different cryptographic algorithm capabilities to different device segments based on their specific communication requirements. Each device is configured with the specific cryptographic algorithm (symmetric or asymmetric) that matches its communication partners in its segment. This localized configuration ensures that each device has the appropriate cryptographic capability for its specific context without all devices needing to support all possible algorithms, thereby reducing memory usage while maintaining necessary adaptability.
3Reliability
If cryptographic keys are updated frequently to counter advancing cryptanalytic capabilities, then security is improved, but loss of time and operational disruption increase
Solution Approach 1:
The patent implements preliminary action by pre-establishing cryptographic key pairs (including both symmetric and asymmetric keys) and algorithm configurations for each device segment before security updates are needed. When security updates are required, the system can quickly switch to pre-prepared alternative keys and algorithms within the same segment without requiring time-consuming coordination with all devices. This preliminary preparation significantly reduces the time loss associated with cryptographic updates while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In one example, an apparatus such as an authorization server and method for secure communication between constrained devices issues cryptographic communication rights among a plurality of constrained devices. Each of the plurality of constrained devices comprises no more than one cryptographic algorithm code module per cryptographic function. The method includes receiving a cryptographic communication rights request associated with at least a first of the plurality of constrained devices in response to a cryptographic algorithm update request, and includes providing a response including an identification of a subset of the plurality of constrained devices that have cryptographic communication rights with the identified first of the plurality of constrained devices. A software update server then updates the cryptographic code modules in the sub-set of the plurality of constrained devices.