Cryptographic Half-Key Pair Generation for Secure Equipment Initialization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for initializing cryptographic half-keys in secure equipment are cumbersome and error-prone, especially when the equipment lacks an ergonomic human-machine interface, requiring multiple connections and configurations, which is impractical and increases the risk of errors.
Innovation Solution
A method for generating n pairs of cryptographic half-keys, where one series is stored on a removable medium and the other series is generated on the equipment using a command file, allowing for initialization without the need for an ergonomic interface, by dissociating the creation of the two half-keys and using a management center with a graphical interface to define access rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple connection/configuration cycles are performed to initialize several CIK plugs, then multiple users can access the equipment, but the initialization process becomes long, repetitive, and error-prone
Solution Approach 1:
The patent applies preliminary action by pre-generating all n pairs of half-keys at the management center before the actual initialization process. The command file containing all half-key pairs is prepared in advance, allowing the equipment to receive and process all initialization data in a single connection cycle, thereby reducing initialization time while maintaining multi-user access capability
Solution Approach 2:
The patent uses copying by creating a command file that contains copies of all n half-key pairs generated at the management center. This command file serves as a replicated data structure that can be transferred to the equipment and processed to initialize multiple CIK plugs simultaneously, eliminating the need for repeated connection cycles
2Adaptability or versatility
If multiple connection/configuration cycles are performed to initialize several CIK plugs, then multiple users can access the equipment, but the complexity of operations increases and errors become more likely
Solution Approach 1:
By pre-generating and validating all half-key pairs at the management center before transfer, the system ensures initialization accuracy is improved. The command file contains pre-processed data that reduces the risk of errors during the initialization process itself
Solution Approach 2:
The command file serves as an accurate copy of all half-key pairs that can be processed simultaneously at the equipment. This copying approach ensures that all initialization data is consistent and complete, reducing operational errors while maintaining multi-user access
3Ease of operation
If an ergonomic interface with keyboard and screen is installed on the equipment, then the initialization process becomes easier to operate, but the equipment complexity and cost increase
Solution Approach 1:
The patent introduces an intermediary approach by using a management center with a graphical interface as a mediator between the operator and the equipment. The management center generates and transfers initialization data via a standardized interface, eliminating the need for complex ergonomic interfaces on the equipment itself while maintaining ease of operation
Solution Approach 2:
The patent extracts the ergonomic interface requirements from the equipment by moving the complex user interaction to the management center. The equipment only needs a simple standardized interface to receive command files, while the management center handles all complex operations including graphical user interface interactions
4Ease of operation
If a generic keying system is used to simplify CIK plug initialization, then the initialization process is simplified, but the system complexity and implementation cost increase significantly
Solution Approach 1:
The patent applies segmentation by dividing the key generation and management functions into separate modules: the management center handles high-level key pair generation and command file creation, while the equipment handles local storage and processing of individual half-keys. This segmentation simplifies the overall system architecture compared to a generic keying system while maintaining initialization simplicity
Data Source
Figure 1~2
AI summary
The present invention relates to a method for generating cryptographic half-keys. The method enables the generation of n pairs (Ki 1, Ki 2), wherein 1=i=n, of cryptographic half-keys, each of said pairs enabling the reconstruction of an access key KPL specific to a secure apparatus, said method including at least the following steps: from a separate management center for said apparatus, generating (202) and recording a first series (217) of n half-keys Ki 1 on a recording medium (213); supplying (203) the apparatus with said recording medium (213) in order to generate, from said local key KPL and the n half-keys Ki 1 stored on said medium, a second series of n half-keys Ki 2 so as to form said n pairs (Ki 1, Ki 2). The invention can be used in particular for creating a plurality of access keys to a secure apparatus.