Communication Apparatus Secure Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing key exchange schemes for secure communication, such as SDES, may expose keys to eavesdropping, while schemes like ZRTP or IKE cause delays in starting encrypted communication, leading to insecure initial communication periods across various media types.
Innovation Solution
A communication system that includes a key generation mechanism using common key generation information distributed via a key server, allowing terminals to generate and switch to secure common keys without transmitting keys over the communication path, enabling secure media communication by combining multicast key sharing technology with SIP servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If keys are exchanged over a communication path (e.g., using SDES), then encrypted communication can be started promptly, but keys may be illegally obtained for eavesdropping
Solution Approach 1:
The patent introduces a key distribution server as an intermediary that distributes key generation information to communication terminals. The server generates and distributes key material without transmitting the actual communication keys over the communication path, thus preventing eavesdropping while enabling prompt encrypted communication.
Solution Approach 2:
The patent segments the key exchange process into two parts: (1) distribution of key generation information through a trusted server, and (2) local generation of communication keys by terminals. This segmentation allows the sensitive key material to never traverse the communication path, while still enabling rapid encrypted communication.
2Reliability
If key exchange schemes like ZRTP or IKE are used to avoid sending keys over communication path, then security is improved, but it takes time to complete key exchange causing delay
Solution Approach 1:
The key distribution server performs preliminary key generation and distribution before actual communication begins. By pre-distributing key generation information through a trusted channel, the system eliminates the time-consuming key exchange negotiation that would otherwise be required, enabling immediate encrypted communication while maintaining security.
3Productivity
If communication is started immediately without secure key exchange, then prompt communication is achieved, but the communication until encrypted communication starts is not secure
Solution Approach 1:
The system performs preliminary key distribution through a trusted server before communication begins. This pre-established secure key material allows communication to start immediately with encryption already in place, eliminating the vulnerable period where unencrypted communication would occur during key exchange.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
A communication apparatus for use in a communication system including a call control apparatus and a key information distribution apparatus is provided. The communication apparatus includes a key generation means configured to, when media communication is performed between the communication apparatus and another communication apparatus, request the key information distribution apparatus to provide common key generation information for generating a first common key, a call control means configured to establish a call connection between the communication apparatus and said another communication apparatus by transmitting a call connection request to the call control apparatus, and a communication means configured to transmit and receive an encrypted media packet by using a second common key, wherein the key generation means generates the first common key by using the common key generation information received from the key information distribution apparatus, and after the first common key is generated, the communication means transmits and receives an encrypted media packet by using the first common key.