Coordinator Selection for Group Key Management in Multi-Controller Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In networks with multiple controllers, selecting a reliable coordinator for managing a group key is challenging due to issues like power-off or network disconnection, which affects communication and key updates, especially for devices with limited resources or storage capacity.

Innovation Solution

An authentication method where one or more controllers in a group select a coordinator based on controller attributes to manage a shared group key, perform mutual authentication, and encrypt data using the group key for secure communication, ensuring the coordinator is always available for key updates and new device participation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a single coordinator is selected to manage the group key in a network with multiple controllers, then key management efficiency is improved, but system reliability deteriorates when the coordinator becomes unavailable due to power-off or network disconnection

Engineering Contradiction:
Improvekey management efficiencyVSAvoidcoordinator availability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent combines multiple controllers into a coordinated system where one controller is designated as the coordinator while others serve as backup coordinators. This merging approach allows the system to maintain key management functionality even when the primary coordinator becomes unavailable, as backup coordinators can take over.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system dynamically changes the coordinator parameter based on availability. When the primary coordinator becomes unavailable, the system identifies and designates a backup coordinator from among the other controllers, effectively changing the coordinator parameter to maintain system reliability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If all controllers and devices share a single group key for encrypted communication, then communication security is improved, but key distribution and update complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidkey distribution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key management function from all controllers and concentrates it in a single coordinator controller. This allows the coordinator to centrally manage the group key, handling distribution and updates to all other controllers and devices, thereby reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The coordinator acts as an intermediary between the key generation process and the distribution to multiple controllers and devices. It receives authentication information, generates the group key, and then distributes it to authorized parties, simplifying the key distribution architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If authentication data is generated using only transmission data, then processing speed is improved, but security against header and address falsification deteriorates

Engineering Contradiction:
Improveauthentication processing speedVSAvoidmessage integrity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent combines multiple message components (header, source address, destination address, and transmission data) into a single authentication data generation process. By hashing all these elements together with the group key, the system ensures comprehensive message integrity verification while maintaining efficient processing through a single cryptographic operation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3675414B1Authentication method, authentication system, and controller
Publication Date: 2021.08.04 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • EP3675414B1 patent drawingFigure 1
  • EP3675414B1 patent drawingFigure 2
  • EP3675414B1 patent drawingFigure 3

AI summary

At least one controller in a group selects a coordinator that manages a group key to be used In common in the group from among controllers in the group in accordance with an attribute of the controllers. The selected coordinator generates a group key, performs mutual authentication with devices and the controllers In the group, and shares the generated group key with devices and controllers that have been successfully authenticated. The coordinator then generates encrypted data and authentication data by using the group key and simultaneously broadcasts a message including the encrypted data and the authentication data.