Centralized Key Management via Intermediary Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for secure key management in digital communication are cumbersome, requiring users to independently manage and protect secret keys, which can lead to loss or unauthorized access, and often necessitate multiple contractual relationships with service providers and trust centers.

Innovation Solution

A method where a first device stores key identifiers associated with users and a second device stores secret keys, allowing users to authenticate and retrieve secret keys via a temporary identifier, enabling secure and centralized key management without the need for users to store or protect the keys themselves.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users independently manage and protect secret keys, then security control is maintained, but complexity of operation and risk of key loss increase

Engineering Contradiction:
Improvesecurity controlVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a trust center as an intermediary that manages secret keys on behalf of users. The trust center generates, stores, and distributes secret keys to authorized parties without requiring users to directly handle or protect these sensitive cryptographic materials, thereby reducing operational complexity while maintaining security through centralized professional management

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables automated key management where the trust center and message deliverer automatically handle key distribution, storage, and retrieval processes. Users benefit from self-service capabilities through automated authentication and key provisioning without manual intervention, reducing the burden of key protection while maintaining security controls

Inventive Principle:
Principle #25Self-service

2Reliability

If multiple contractual relationships are established with service providers and trust centers, then comprehensive security coverage is achieved, but device complexity and setup requirements increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem setup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security functions into integrated service relationships. The message deliverer acts as a full-service provider that coordinates with the trust center to handle both message delivery and key management, allowing users to establish fewer contractual relationships while achieving comprehensive security coverage through merged functionalities

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The trust center and message deliverer are designed as multi-functional entities that provide both key management and message delivery services. This universal approach allows a single service provider to fulfill multiple security and communication needs, reducing the number of separate systems and contracts users must manage

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secret keys are stored centrally in a trust center, then risk of key loss is reduced, but ease of retrieval and access may be compromised

Engineering Contradiction:
Improvekey protectionVSAvoidkey retrieval ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The message deliverer serves as an intermediary that facilitates efficient key retrieval from the trust center. When users need secret keys for message decryption or encryption operations, the message deliverer automatically requests and retrieves the appropriate keys from the trust center, providing users with easy access while maintaining centralized secure storage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary key retrieval and preparation actions before users need them. The trust center maintains ready-to-use secret keys for registered users, and the message deliverer can proactively obtain necessary keys in advance, ensuring immediate availability when needed without requiring users to manually retrieve or manage key storage

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3031226B1Supporting the use of a secret key
Publication Date: 2016.12.28 DEUT POST AG
  • EP3031226B1 patent drawingFigure 1
  • EP3031226B1 patent drawingFigure 2
  • EP3031226B1 patent drawingFigure 3

AI summary

The invention relates to a first device (200) that stores key designations assigned to a respective user, and to a second device (300) that stores secret keys, which can each be found by means of a key designation. The first device (200) authenticates a user who logs in to the first device (200) via a user device (100), generates a temporary identifier, assigns the identifier to the user and transmits the identifier to the user device (100). The second device (300) receives a request for a secret key from the user device (100) together with the identifier, and requests a key designation from the first device (200), the identifier received being transmitted. The first device (200) determines a user assigned to the identifier obtained, determines a key designation stored for the user determined and transmits the key designation to the second device (300). The latter determines a secret key on the basis of the key designation received and transmits the secret key to the user device (100).