Coordinator Selection for Group Key Management in Multi-Controller Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In networks with multiple controllers, selecting a reliable coordinator for managing a group key is challenging due to issues like power-off or network disconnection, which affects communication and key updates, especially for devices with limited resources or storage capacity.
Innovation Solution
An authentication method where one or more controllers in a group select a coordinator based on controller attributes to manage a shared group key, perform mutual authentication, and encrypt data using the group key for secure communication, ensuring the coordinator is always available for key updates and new device participation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a single coordinator is selected to manage the group key in a network with multiple controllers, then key management efficiency is improved, but system reliability deteriorates when the coordinator becomes unavailable due to power-off or network disconnection
Solution Approach 1:
The patent combines multiple controllers into a coordinated system where one controller is designated as the coordinator while others serve as backup coordinators. This merging approach allows the system to maintain key management functionality even when the primary coordinator becomes unavailable, as backup coordinators can take over.
Solution Approach 2:
The system dynamically changes the coordinator parameter based on availability. When the primary coordinator becomes unavailable, the system identifies and designates a backup coordinator from among the other controllers, effectively changing the coordinator parameter to maintain system reliability.
2Reliability
If all controllers and devices share a single group key for encrypted communication, then communication security is improved, but key distribution and update complexity increases
Solution Approach 1:
The patent extracts the key management function from all controllers and concentrates it in a single coordinator controller. This allows the coordinator to centrally manage the group key, handling distribution and updates to all other controllers and devices, thereby reducing overall system complexity while maintaining security.
Solution Approach 2:
The coordinator acts as an intermediary between the key generation process and the distribution to multiple controllers and devices. It receives authentication information, generates the group key, and then distributes it to authorized parties, simplifying the key distribution architecture.
3Speed
If authentication data is generated using only transmission data, then processing speed is improved, but security against header and address falsification deteriorates
Solution Approach 1:
The patent combines multiple message components (header, source address, destination address, and transmission data) into a single authentication data generation process. By hashing all these elements together with the group key, the system ensures comprehensive message integrity verification while maintaining efficient processing through a single cryptographic operation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
At least one controller in a group selects a coordinator that manages a group key to be used In common in the group from among controllers in the group in accordance with an attribute of the controllers. The selected coordinator generates a group key, performs mutual authentication with devices and the controllers In the group, and shares the generated group key with devices and controllers that have been successfully authenticated. The coordinator then generates encrypted data and authentication data by using the group key and simultaneously broadcasts a message including the encrypted data and the authentication data.