Cryptographic Key Provisioning via Trusted Third Party Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Key provisioning for cryptographic devices is challenging when initial key material is inserted, as it cannot rely on pre-existing material and requires secure delivery within secure premises, while also managing trust issues between owners and installers, especially with sub-owners involved.

Innovation Solution

A multilevel delegation hierarchy for cryptographic key provisioning, where the native key owner can delegate rights through a hierarchical structure, allowing partial or complete key provisioning rights to other parties, with encrypted and signed message portions ensuring secure delivery and usage restrictions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If key material is delivered without encryption to simplify the provisioning process, then the provisioning speed and ease of operation improve, but security and reliability deteriorate due to exposure to compromise by Installer

Engineering Contradiction:
Improveprovisioning process simplicityVSAvoidkey material security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a Trusted Third Party (TTP) as an intermediary that holds the root key and issues encrypted provisioning messages to the Installer. The TTP acts as a mediator between the key owner and the Installer, enabling secure key delivery without requiring the Installer to have direct access to unencrypted key material. The provisioning message is encrypted using a key pair where the public key is known to the TTP and the private key is held by the TTP, ensuring that only the TTP can decrypt and verify the key material.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If the Installer is trusted to receive and install key material, then the device complexity and provisioning process simplify, but security deteriorates due to risk of key material exposure to Installer

Engineering Contradiction:
Improveprovisioning system complexityVSAvoidkey material exposure to Installer
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The Trusted Third Party serves as a mediator that receives key material from the key owner, encrypts it with the Installer's public key, and delivers it to the Installer. This intermediary approach allows the system to maintain low complexity from the Installer's perspective while preventing direct exposure of key material to the Installer, as the TTP handles all cryptographic operations securely.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the key provisioning process into distinct phases: key pair generation by the TTP, encryption of key material by the TTP, delivery of encrypted message to the Installer, and decryption/verification by the Installer. This segmentation allows each component to have limited responsibilities, reducing overall system complexity while maintaining security through distributed cryptographic operations.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If multiple Sub-owners are allowed to provision keys independently, then the system versatility and adaptability improve, but device complexity increases due to multiple trust relationships and delegation hierarchies

Engineering Contradiction:
Improvemulti-sub-owner provisioning capabilityVSAvoiddelegation hierarchy complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments key provisioning rights into a hierarchical delegation structure where the TTP can delegate to multiple Sub-owners, who can in turn delegate to Installers. Each delegation level is independent and can be configured separately, allowing the system to support multiple Sub-owners without creating complex inter-dependencies. The TTP maintains central control while enabling distributed provisioning capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The TTP is designed as a universal provisioning platform that can serve multiple Sub-owners and handle various types of key material (symmetric keys, asymmetric key pairs, hash values). The same cryptographic infrastructure and message format are used across all delegation levels, simplifying the system architecture while enabling versatile multi-sub-owner provisioning capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If the Owner retains possession of all key material to control Sub-owners, then security and trust improve, but the Owner's ability to delegate and system versatility deteriorate

Engineering Contradiction:
ImproveOwner trust controlVSAvoidkey delegation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The TTP acts as an intermediary that holds the master key material and can issue encrypted provisioning messages to Sub-owners and Installers. This allows the Owner to maintain centralized control through the TTP while enabling Sub-owners to receive and use key material without direct possession by the Owner. The TTP mediates between the Owner's control requirements and the Sub-owners' operational needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary key pair generation and encryption of key material by the TTP before delivery to Sub-owners or Installers. This preliminary action ensures that key material is always encrypted and controlled by the TTP, maintaining Owner trust while enabling delegation. The TTP prepares and seals the key material in advance, allowing Sub-owners to receive and use it without compromising Owner control.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8687813B2Methods circuits devices and systems for provisioning of cryptographic data to one or more electronic devices
Publication Date: 2014.04.01 ARM LTD
  • US8687813B2 patent drawing
  • US8687813B2 patent drawing
  • US8687813B2 patent drawing

AI summary

Disclosed are methods, circuit, devices and systems for provisioning cryptographic material to a target device. According to embodiments, a cryptographic material provisioning (CMP) module may be adapted to process a provisioning message with a first message portion which is encrypted with a native key of the target device and which includes first cryptographic material along with a first permissions data vector, wherein the CMP may be further adapted to process data bits of a second portion of the provisioning message using the first cryptographic material and in accordance with usage limitations defined in the first permissions data vector.