Cryptographic Key Selection for Distributed Access Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access systems, such as data transmission and building access control systems, face challenges in efficiently updating cryptographic keys or access codes, especially in geographically distributed devices without communication means, requiring costly on-site operator intervention.

Innovation Solution

A data processing method that allows a processing device to change cryptographic keys without receiving a new key, by pre-registering multiple keys with varying validity periods based on geographical location and time, enabling secure and automated key updates without operator intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are updated in geographically dispersed devices without communication means, then security is improved, but operator intervention and costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidoperator intervention
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Multiple cryptographic keys are pre-loaded into the device's memory during manufacturing or initial setup, with each key associated with specific validity criteria (time periods, geographical zones). When a key becomes invalid, the device automatically selects the next appropriate key from its stored set without requiring external intervention, thus maintaining security while eliminating the need for operators to travel to remote locations for key updates.

Inventive Principle:
Principle #10Preliminary action

2Extent of automation

If multiple keys are pre-registered with validity criteria, then automated key updates are enabled, but device complexity increases

Engineering Contradiction:
Improveautomated key updatesVSAvoiddevice complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The cryptographic key management is segmented into multiple independent keys, each with specific validity criteria (time periods, geographical zones). The device contains a selection module that evaluates current conditions (time, location) against the stored keys and automatically selects the appropriate key. This segmentation approach enables automation while keeping the selection logic simple and manageable, avoiding the need for complex key generation or communication protocols.

Inventive Principle:
Principle #1Segmentation

3Reliability

If keys are changed regularly to enhance security, then security is improved, but operational costs increase due to on-site visits

Engineering Contradiction:
ImprovesecurityVSAvoidoperational costs
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Multiple cryptographic keys with different validity periods are pre-loaded into the device during manufacturing or initial setup. Each key is associated with specific time windows and/or geographical zones. When the current key's validity period expires or the device moves to a new zone, the system automatically selects the next appropriate key from its stored set without requiring external intervention. This eliminates the need for operators to travel to remote locations for frequent key updates, thereby maintaining high security through regular key changes while eliminating the associated operational costs and time losses.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3123659B1Key selection method for cryptographic data processing
Publication Date: 2021.09.29 ORANGE SA
  • EP3123659B1 patent drawingFigure 1
  • EP3123659B1 patent drawingFigure 2
  • EP3123659B1 patent drawingFigure 3

AI summary

The invention concerns a data processing method suitable for selecting (E8) a key (Kc) from a plurality of previously stored keys (Kcl, Kc2), depending on at least on predefined criterion (CRI) relating to at least one current value of at least one given repository. The invention also relates to a reception method suitable for receiving (E20) second data obtained by applying, to first obtained data, a first cryptographic function (Fl) using a key (Kc) selected from a plurality of previously stored keys, depending on at least on predefined criterion relating to a current value of at least one given repository and for obtaining (E24) the first data by applying, to the second received data, a second cryptographic function (F2) using a second key (Kd) associated with the selected key (Kc). The invention also relates to a processing device and a reception device that respectively implement the processing method and the reception method.