Cryptographic Key Provisioning via Trusted Third Party Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Key provisioning for cryptographic devices is challenging when initial key material is inserted, as it cannot rely on pre-existing material and requires secure delivery within secure premises, while also managing trust issues between owners and installers, especially with sub-owners involved.
Innovation Solution
A multilevel delegation hierarchy for cryptographic key provisioning, where the native key owner can delegate rights through a hierarchical structure, allowing partial or complete key provisioning rights to other parties, with encrypted and signed message portions ensuring secure delivery and usage restrictions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If key material is delivered without encryption to simplify the provisioning process, then the provisioning speed and ease of operation improve, but security and reliability deteriorate due to exposure to compromise by Installer
Solution Approach 1:
The patent introduces a Trusted Third Party (TTP) as an intermediary that holds the root key and issues encrypted provisioning messages to the Installer. The TTP acts as a mediator between the key owner and the Installer, enabling secure key delivery without requiring the Installer to have direct access to unencrypted key material. The provisioning message is encrypted using a key pair where the public key is known to the TTP and the private key is held by the TTP, ensuring that only the TTP can decrypt and verify the key material.
2Device complexity
If the Installer is trusted to receive and install key material, then the device complexity and provisioning process simplify, but security deteriorates due to risk of key material exposure to Installer
Solution Approach 1:
The Trusted Third Party serves as a mediator that receives key material from the key owner, encrypts it with the Installer's public key, and delivers it to the Installer. This intermediary approach allows the system to maintain low complexity from the Installer's perspective while preventing direct exposure of key material to the Installer, as the TTP handles all cryptographic operations securely.
Solution Approach 2:
The patent segments the key provisioning process into distinct phases: key pair generation by the TTP, encryption of key material by the TTP, delivery of encrypted message to the Installer, and decryption/verification by the Installer. This segmentation allows each component to have limited responsibilities, reducing overall system complexity while maintaining security through distributed cryptographic operations.
3Adaptability or versatility
If multiple Sub-owners are allowed to provision keys independently, then the system versatility and adaptability improve, but device complexity increases due to multiple trust relationships and delegation hierarchies
Solution Approach 1:
The patent segments key provisioning rights into a hierarchical delegation structure where the TTP can delegate to multiple Sub-owners, who can in turn delegate to Installers. Each delegation level is independent and can be configured separately, allowing the system to support multiple Sub-owners without creating complex inter-dependencies. The TTP maintains central control while enabling distributed provisioning capabilities.
Solution Approach 2:
The TTP is designed as a universal provisioning platform that can serve multiple Sub-owners and handle various types of key material (symmetric keys, asymmetric key pairs, hash values). The same cryptographic infrastructure and message format are used across all delegation levels, simplifying the system architecture while enabling versatile multi-sub-owner provisioning capabilities.
4Reliability
If the Owner retains possession of all key material to control Sub-owners, then security and trust improve, but the Owner's ability to delegate and system versatility deteriorate
Solution Approach 1:
The TTP acts as an intermediary that holds the master key material and can issue encrypted provisioning messages to Sub-owners and Installers. This allows the Owner to maintain centralized control through the TTP while enabling Sub-owners to receive and use key material without direct possession by the Owner. The TTP mediates between the Owner's control requirements and the Sub-owners' operational needs.
Solution Approach 2:
The patent implements preliminary key pair generation and encryption of key material by the TTP before delivery to Sub-owners or Installers. This preliminary action ensures that key material is always encrypted and controlled by the TTP, maintaining Owner trust while enabling delegation. The TTP prepares and seals the key material in advance, allowing Sub-owners to receive and use it without compromising Owner control.
Data Source
AI summary
Disclosed are methods, circuit, devices and systems for provisioning cryptographic material to a target device. According to embodiments, a cryptographic material provisioning (CMP) module may be adapted to process a provisioning message with a first message portion which is encrypted with a native key of the target device and which includes first cryptographic material along with a first permissions data vector, wherein the CMP may be further adapted to process data bits of a second portion of the provisioning message using the first cryptographic material and in accordance with usage limitations defined in the first permissions data vector.


