Cryptographic Key Distribution with Security Status Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing key management schemes in communication devices do not have mechanisms to prevent compromised devices from receiving new cryptographic keys during scheduled key renewal, leading to potential security breaches.
Innovation Solution
A method and system where a server distributes cryptographic keys only to communication devices that are not compromised, by determining the security status of each device and issuing new keys or taking corrective actions to ensure security, and distributing updated group keys to non-compromised devices within the same talk group.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If periodic key renewal is implemented to enhance security, then security level is improved, but compromised devices may receive new keys during renewal periods
Solution Approach 1:
The server performs preliminary security assessments before distributing new cryptographic keys during periodic renewal. Security assessment messages are sent in advance to communication devices, and devices report their security status before receiving key updates, preventing compromised devices from obtaining new keys
Solution Approach 2:
A feedback mechanism is established where communication devices report their security status to the server in response to security assessment messages. The server uses this feedback information to determine whether to distribute new cryptographic keys, creating a closed-loop control system that prevents key distribution to compromised devices
2Reliability
If security status verification is performed before key distribution, then security integrity is improved, but system complexity increases
Solution Approach 1:
Communication devices perform self-assessment of their security status and autonomously report this information to the server. The security assessment functionality is built into the devices themselves, eliminating the need for complex external verification infrastructure and reducing overall system complexity
Data Source
AI summary
Method and server for issuing a cryptographic key. One method includes distributing a first group key to a first communication device and a second communication device. The method also includes distributing a security request to the first communication device. The method further includes receiving a security status from the first communication device responsive to transmitting the security request. The method also includes determining when security of the first communication device is compromised based on the security status. The method further includes distributing, via a server, the cryptographic key to the first communication device when the security of the first communication device is not compromised. The method also includes distributing, via the server, a second group key to the second communication device when the security of the first communication device is compromised and the first communication device cannot be fixed or deactivated.


