Distributed Key Management for Mobile Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for distributing cryptographic keys in networks with geographically dispersed and dynamic computing devices face challenges in coordinating key updates, leading to incomplete key distribution and communication disruptions.

Innovation Solution

The system localizes key generation and distribution to communications nodes, where a central authority generates white lists that specify criteria for selecting a master communications node, which generates and distributes cryptographic keys to other nodes, ensuring timely and efficient key updates across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are distributed from a central source in networks with geographically dispersed devices, then key distribution can be coordinated centrally, but key updates cannot reach all devices timely due to geographical restrictions and device mobility

Engineering Contradiction:
Improvekey distribution completenessVSAvoidkey update delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides the centralized key distribution system into distributed key generation units at different network nodes (main datacenter, base stations, and mobile computing devices). Each node can independently generate and distribute cryptographic keys within its coverage area, eliminating the single-point bottleneck and ensuring timely key updates even when devices move between geographical regions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to key distribution by enabling key generation at multiple levels (central datacenter, base stations, and mobile devices). This multi-dimensional approach allows keys to be distributed through alternative paths when devices move out of range of any single authority, ensuring continuous key availability across geographical boundaries.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Productivity

If multiple authorities operate at different administrative levels distributing different cryptographic keys, then localized key distribution can occur, but coordination between authorities becomes logistically difficult

Engineering Contradiction:
Improvekey distribution speedVSAvoidcoordination complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges the key generation and distribution functions across multiple administrative levels into a unified distributed system. Mobile computing devices can receive keys from any authorized authority (main datacenter or base stations) based on their current location, eliminating the need for complex inter-authority coordination while maintaining secure key distribution throughout the network.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If cryptographic keys are frequently generated and distributed to mobile devices, then network security is maintained, but coordination of mobile devices becomes logistically difficult

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice coordination ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables mobile computing devices to autonomously obtain cryptographic keys from available authorities without requiring complex coordination. Devices can independently connect to base stations or the main datacenter within range to receive updated keys, eliminating logistical coordination challenges while maintaining continuous security through frequent key updates.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10356064B1Distributed on-demand key management for rangeless environments
Publication Date: 2019.07.16 ROCKWELL COLLINS INC
  • US10356064B1 patent drawing
  • US10356064B1 patent drawing
  • US10356064B1 patent drawing

AI summary

Disclosed herein are systems and methods for distributed key management. A first communications node may join a network. The first communications node may receive a white list generated by a central authority. The white list may include criteria for selecting a master communications node that may generate and distribute a cryptographic key for the network. The white list may also identify one or more communications nodes authorized to receive the generated cryptographic key. Responsive to detecting a second communications node joining the network, the first communications node may determine whether the second communications node is to be the master communications node for the network.