Secure Key Distribution via Device Identifier Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network communication systems face challenges in securely distributing and managing cryptographic keys, particularly the master key, during node commissioning, which can lead to security hazards if not handled efficiently.

Innovation Solution

A method where a source node encrypts a cryptographic key using a device key based on a device identifier for the destination node, allowing secure transmission and decryption, with optional acknowledgement and storage for future authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are distributed during node commissioning, then network communication security is enabled, but security hazards increase if key distribution is not handled efficiently

Engineering Contradiction:
Improvenetwork communication securityVSAvoidsecurity hazards during key distribution
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by pre-distributing device keys to destination nodes before master key distribution occurs. This allows the source node to encrypt the master key with the destination node's device key, ensuring secure key distribution without exposing security hazards during the commissioning process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses device keys as an intermediary mechanism to facilitate secure master key distribution. Instead of directly distributing master keys or using insecure channels, the device key acts as a mediator that enables encrypted transmission, resolving the contradiction between enabling security and avoiding security hazards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Duration of action of moving object

If device keys are stored in source node memory for future authentication, then authentication capability over time is enabled, but memory security requirements increase

Engineering Contradiction:
Improveauthentication capability over timeVSAvoidmemory security requirements
Core Design Contradiction:
Duration of action of moving objectVSReliability

Solution Approach 1:

The patent applies self-service by having the destination node generate its own device key based on its device identifier, rather than requiring the source node to securely store and manage all device keys. The source node only needs to store the publicly accessible device identifier, significantly reducing memory security requirements while maintaining long-term authentication capability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10554640B2Method and system for facilitating secure communication
Publication Date: 2020.02.04 NXP BV
  • US10554640B2 patent drawing
  • US10554640B2 patent drawing
  • US10554640B2 patent drawing

AI summary

According to a first aspect of the present disclosure, a method for facilitating secure communication in a network is conceived, comprising: encrypting, by a source node in the network, a cryptographic key using a device key as an encryption key, wherein said device key is based on a device identifier that identifies a destination node in the network; transmitting, by said source node, the encrypted cryptographic key to the destination node. According to a second aspect of the present disclosure, a corresponding non-transitory, tangible computer program product is provided. According to a third aspect of the present disclosure, a corresponding system for facilitating secure communication in a network is provided.