Cryptographic Key Distribution with Security Status Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key management schemes in communication devices do not have mechanisms to prevent compromised devices from receiving new cryptographic keys during scheduled key renewal, leading to potential security breaches.

Innovation Solution

A method and system where a server distributes cryptographic keys only to communication devices that are not compromised, by determining the security status of each device and issuing new keys or taking corrective actions to ensure security, and distributing updated group keys to non-compromised devices within the same talk group.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If periodic key renewal is implemented to enhance security, then security level is improved, but compromised devices may receive new keys during renewal periods

Engineering Contradiction:
Improvesecurity levelVSAvoidkey distribution to compromised devices
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The server performs preliminary security assessments before distributing new cryptographic keys during periodic renewal. Security assessment messages are sent in advance to communication devices, and devices report their security status before receiving key updates, preventing compromised devices from obtaining new keys

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A feedback mechanism is established where communication devices report their security status to the server in response to security assessment messages. The server uses this feedback information to determine whether to distribute new cryptographic keys, creating a closed-loop control system that prevents key distribution to compromised devices

Inventive Principle:
Principle #23Feedback

2Reliability

If security status verification is performed before key distribution, then security integrity is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity integrityVSAvoidkey management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Communication devices perform self-assessment of their security status and autonomously report this information to the server. The security assessment functionality is built into the devices themselves, eliminating the need for complex external verification infrastructure and reducing overall system complexity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10277567B2Method and server for issuing cryptographic keys to communication devices
Publication Date: 2019.04.30 MOTOROLA SOLUTIONS INC
  • US10277567B2 patent drawing
  • US10277567B2 patent drawing
  • US10277567B2 patent drawing

AI summary

Method and server for issuing a cryptographic key. One method includes distributing a first group key to a first communication device and a second communication device. The method also includes distributing a security request to the first communication device. The method further includes receiving a security status from the first communication device responsive to transmitting the security request. The method also includes determining when security of the first communication device is compromised based on the security status. The method further includes distributing, via a server, the cryptographic key to the first communication device when the security of the first communication device is not compromised. The method also includes distributing, via the server, a second group key to the second communication device when the security of the first communication device is compromised and the first communication device cannot be fixed or deactivated.