Communication Apparatus Secure Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key exchange schemes for secure communication, such as SDES, may expose keys to eavesdropping, while schemes like ZRTP or IKE cause delays in starting encrypted communication, leading to insecure initial communication periods across various media types.

Innovation Solution

A communication system that includes a key generation mechanism using common key generation information distributed via a key server, allowing terminals to generate and switch to secure common keys without transmitting keys over the communication path, enabling secure media communication by combining multicast key sharing technology with SIP servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If keys are exchanged over a communication path (e.g., using SDES), then encrypted communication can be started promptly, but keys may be illegally obtained for eavesdropping

Engineering Contradiction:
Improvetime to start encrypted communicationVSAvoidsecurity of key exchange
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent introduces a key distribution server as an intermediary that distributes key generation information to communication terminals. The server generates and distributes key material without transmitting the actual communication keys over the communication path, thus preventing eavesdropping while enabling prompt encrypted communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the key exchange process into two parts: (1) distribution of key generation information through a trusted server, and (2) local generation of communication keys by terminals. This segmentation allows the sensitive key material to never traverse the communication path, while still enabling rapid encrypted communication.

Inventive Principle:
Principle #1Segmentation

2Reliability

If key exchange schemes like ZRTP or IKE are used to avoid sending keys over communication path, then security is improved, but it takes time to complete key exchange causing delay

Engineering Contradiction:
Improvesecurity of key exchangeVSAvoidtime to start encrypted communication
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The key distribution server performs preliminary key generation and distribution before actual communication begins. By pre-distributing key generation information through a trusted channel, the system eliminates the time-consuming key exchange negotiation that would otherwise be required, enabling immediate encrypted communication while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If communication is started immediately without secure key exchange, then prompt communication is achieved, but the communication until encrypted communication starts is not secure

Engineering Contradiction:
Improvespeed of communication initiationVSAvoideavesdropping during initial communication
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary key distribution through a trusted server before communication begins. This pre-established secure key material allows communication to start immediately with encryption already in place, eliminating the vulnerable period where unencrypted communication would occur during key exchange.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3522443B1Communication apparatus, communication method, and program
Publication Date: 2021.04.21 NTT COMM CORP
  • EP3522443B1 patent drawingFigure 1
  • EP3522443B1 patent drawingFigure 2~3
  • EP3522443B1 patent drawingFigure 4

AI summary

A communication apparatus for use in a communication system including a call control apparatus and a key information distribution apparatus is provided. The communication apparatus includes a key generation means configured to, when media communication is performed between the communication apparatus and another communication apparatus, request the key information distribution apparatus to provide common key generation information for generating a first common key, a call control means configured to establish a call connection between the communication apparatus and said another communication apparatus by transmitting a call connection request to the call control apparatus, and a communication means configured to transmit and receive an encrypted media packet by using a second common key, wherein the key generation means generates the first common key by using the common key generation information received from the key information distribution apparatus, and after the first common key is generated, the communication means transmits and receives an encrypted media packet by using the first common key.