Data Processing Device Secure Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data processing devices without input units like floppy disks or CDs face challenges in installing public key/private key pairs and certificates for cryptographic communication, especially during factory shipment or in environments with low security concerns, where generating and managing these keys can be complex and error-prone.

Innovation Solution

Incorporating a storage unit to store initial values of public key/private key pairs and certificates, along with a communication unit to facilitate encryption communication, and a judgment unit to automatically generate new key pairs if necessary, ensuring secure communication without requiring users to perform complex operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic communication is implemented without pre-installed key pairs, then security is improved, but device complexity and user operation difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-installing initial key pairs and certificates in the storage unit during device manufacturing. This allows the device to immediately perform cryptographic communication without requiring users to generate or install key pairs manually, thus maintaining high security while reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device performs self-service by automatically managing the lifecycle of key pairs including generation, installation, and renewal. The control unit monitors key validity and automatically generates new key pairs when needed, eliminating the need for user intervention in complex cryptographic key management tasks.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If key pairs are pre-installed in the device, then ease of operation is improved, but security risks increase due to potential key leakage

Engineering Contradiction:
Improveease of cryptographic communication setupVSAvoidkey leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies parameter changes by implementing automatic key pair renewal mechanisms. The control unit monitors the validity period of installed key pairs and automatically generates and installs new key pairs before the old ones expire. This continuous parameter update reduces the window of vulnerability and minimizes security risks associated with pre-installed keys.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system transitions from static key pairs to dynamic key management. Key pairs are no longer fixed but are continuously renewed and updated based on validity periods. This dynamic approach maintains ease of operation while reducing security risks by limiting the exposure time of any single key pair.

Inventive Principle:
Principle #15Dynamics

3Productivity

If automatic key pair generation is implemented, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improvekey installation speedVSAvoidautomatic key management system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges multiple functions into the control unit: key pair generation, validity period monitoring, automatic installation, and communication management. By combining these functions into a single integrated control mechanism, the system achieves high productivity in key management while minimizing the increase in overall device complexity.

Inventive Principle:
Principle #5Merging (Combining)

4Ease of operation

If initial key pairs are stored in the device, then ease of operation is improved, but loss of information risk increases if keys are damaged or lost

Engineering Contradiction:
Improveimmediate cryptographic capabilityVSAvoidkey pair damage or loss
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system implements beforehand cushioning by maintaining backup mechanisms and automatic renewal capabilities. Before key pairs become invalid or are lost, the control unit proactively generates replacement key pairs. This preparatory measure ensures that cryptographic functionality is never interrupted, cushioning against the potential loss of information.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUSRE48381E1Data processing device, encryption communication method, key generation method, and computer program
Publication Date: 2021.01.05 CANON KK
  • USRE48381E1 patent drawing
  • USRE48381E1 patent drawing
  • USRE48381E1 patent drawing

AI summary

A data processing device comprises a storage unit adapted to store an initial value of a pair of a public key and a private key and a communication unit adapted to execute communication with an external device with use of the initial value of the pair of the public key and the private key stored in the storage unit, thereby enabling encryption communication without generating the pair of the public key and the private key.