Cloud-Based Key Management for Multi-Device End-to-End Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring secure communication on multiple end devices, particularly mobile devices, is challenging due to the complexity of managing and sharing encryption keys, especially when end-to-end encryption is required, as existing methods are time-consuming and impractical for new devices.

Innovation Solution

A method where a private key is generated on a user's first terminal, encrypted with a cloud password, and then transferred to a second terminal for decryption, using a browser-based process that ensures security and user-friendliness, allowing seamless key configuration across various devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a unique key is assigned to each endpoint for secure communication, then security is improved, but device complexity and key management difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple key management functions into a unified cloud-based system. Instead of managing separate keys for each device, the system combines all key operations (generation, storage, distribution, rotation) into a centralized cloud service that automatically manages keys across multiple endpoints, reducing local device complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a cloud-based key management service as an intermediary between users and their encryption keys. This mediator handles key generation, secure storage, and distribution to multiple devices, eliminating the need for users to directly manage complex key pairs on each endpoint while ensuring cryptographic security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all keys are recorded and shared among communication partners, then secure communication is enabled, but ease of operation deteriorates due to the need to manage multiple keys

Engineering Contradiction:
Improvesecure communicationVSAvoiduser friendliness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service key management where the cloud system automatically performs key generation, distribution, and rotation without requiring user intervention. Users simply authenticate and the system handles all cryptographic operations automatically, making secure communication as easy as logging in while maintaining end-to-end encryption.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal key management system that works across multiple devices and communication channels. A single cloud-based service provides key management for email, messaging, and other communication platforms, allowing users to access secure communication on any device without learning different key management procedures for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional key configuration methods are used on mobile devices, then security can be maintained, but ease of operation significantly deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces manual mechanical key configuration processes with automated cloud-based key distribution. Instead of requiring users to manually import, export, and configure cryptographic keys on mobile devices, the system uses automated cloud services to provision keys remotely, eliminating complex manual operations while maintaining cryptographic security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent performs preliminary key generation and configuration actions in the cloud before the user needs them. Keys are pre-generated and securely stored in the cloud, then automatically made available to mobile devices when needed, eliminating the need for users to perform complex key setup procedures on their devices and enabling secure communication immediately upon authentication.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3241332B1Method for the generation and configuration of keys for a second terminal
Publication Date: 2019.07.10 1&1 INTERNET SE
  • EP3241332B1 patent drawingFigure 1

AI summary

The invention relates to a method for the user-side generation and configuration of keys of a user-side second terminal (EG2), said method having the steps: • generation (50) of a private key, • receipt (100) of a password for the private key, • packaging of the private key and the password for the private key and encryption of the packet using a cloud password (120) on a first terminal (EG1) of the user, • storage (10) of the encrypted packet on a server (CLD), • issue (140) of the cloud password on the first terminal (EG1), • receipt (200) of the encrypted packet from the server (CLD) on a second terminal (EG2) of the user, • entry (210) of the cloud password on the second terminal (EG2), • decryption (220) of the encrypted packet and installation (230) of the private key.