Centralized Key Management via Intermediary Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for secure key management in digital communication are cumbersome, requiring users to independently manage and protect secret keys, which can lead to loss or unauthorized access, and often necessitate multiple contractual relationships with service providers and trust centers.
Innovation Solution
A method where a first device stores key identifiers associated with users and a second device stores secret keys, allowing users to authenticate and retrieve secret keys via a temporary identifier, enabling secure and centralized key management without the need for users to store or protect the keys themselves.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users independently manage and protect secret keys, then security control is maintained, but complexity of operation and risk of key loss increase
Solution Approach 1:
The patent introduces a trust center as an intermediary that manages secret keys on behalf of users. The trust center generates, stores, and distributes secret keys to authorized parties without requiring users to directly handle or protect these sensitive cryptographic materials, thereby reducing operational complexity while maintaining security through centralized professional management
Solution Approach 2:
The system enables automated key management where the trust center and message deliverer automatically handle key distribution, storage, and retrieval processes. Users benefit from self-service capabilities through automated authentication and key provisioning without manual intervention, reducing the burden of key protection while maintaining security controls
2Reliability
If multiple contractual relationships are established with service providers and trust centers, then comprehensive security coverage is achieved, but device complexity and setup requirements increase
Solution Approach 1:
The patent combines multiple security functions into integrated service relationships. The message deliverer acts as a full-service provider that coordinates with the trust center to handle both message delivery and key management, allowing users to establish fewer contractual relationships while achieving comprehensive security coverage through merged functionalities
Solution Approach 2:
The trust center and message deliverer are designed as multi-functional entities that provide both key management and message delivery services. This universal approach allows a single service provider to fulfill multiple security and communication needs, reducing the number of separate systems and contracts users must manage
3Reliability
If secret keys are stored centrally in a trust center, then risk of key loss is reduced, but ease of retrieval and access may be compromised
Solution Approach 1:
The message deliverer serves as an intermediary that facilitates efficient key retrieval from the trust center. When users need secret keys for message decryption or encryption operations, the message deliverer automatically requests and retrieves the appropriate keys from the trust center, providing users with easy access while maintaining centralized secure storage
Solution Approach 2:
The system performs preliminary key retrieval and preparation actions before users need them. The trust center maintains ready-to-use secret keys for registered users, and the message deliverer can proactively obtain necessary keys in advance, ensuring immediate availability when needed without requiring users to manually retrieve or manage key storage
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention relates to a first device (200) that stores key designations assigned to a respective user, and to a second device (300) that stores secret keys, which can each be found by means of a key designation. The first device (200) authenticates a user who logs in to the first device (200) via a user device (100), generates a temporary identifier, assigns the identifier to the user and transmits the identifier to the user device (100). The second device (300) receives a request for a secret key from the user device (100) together with the identifier, and requests a key designation from the first device (200), the identifier received being transmitted. The first device (200) determines a user assigned to the identifier obtained, determines a key designation stored for the user determined and transmits the key designation to the second device (300). The latter determines a secret key on the basis of the key designation received and transmits the secret key to the user device (100).