Distributed Trusted Authority Key Management for Secure Device Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for establishing encrypted communication between independent electronic devices, such as mobile equipment and smart cards, face challenges due to the lack of mutual trust and shared databases among device manufacturers, leading to compromised authentication and security.
Innovation Solution
A method involving two separate Trusted Authorities generates and manages secret keys for each device, ensuring that the keys are kept secret from each other, allowing for secure encrypted communication without relying on a single external supervision authority, using identity-based encryption and symmetrical key methods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single external supervision authority (PKI CA) is used to manage public keys and authentication, then security and authentication reliability are improved, but device complexity and dependency on external authorities increase
Solution Approach 1:
The patent divides the single centralized PKI authority into multiple independent Trusted Authorities (TA), each managing keys and authentication for specific device types or groups. This segmentation reduces dependency on a single authority while maintaining security through distributed trust management.
Solution Approach 2:
The patent introduces mutual authentication protocols where devices authenticate each other directly through shared secret keys and digital signatures, eliminating the need for continuous intervention from external PKI authorities. The TA acts as an intermediary that issues keys but does not continuously monitor or control communication.
2Reliability
If public key infrastructure (PKI) with digital certificates is used, then security and key management are improved, but loss of information and privacy concerns increase due to centralized authority control
Solution Approach 1:
The patent extracts the private key generation and management functions from the centralized PKI authority and transfers them to individual devices. Each device generates its own private key pair independently, with only the public key and certificate shared with the TA. This extraction eliminates the risk of centralized authority accessing private keys.
Solution Approach 2:
Devices perform self-authentication and self-key-management operations using stored secret keys and digital signatures. The mutual authentication protocol allows devices to verify each other's identity independently without requiring continuous verification from external authorities, enabling privacy-preserving communication.
3Productivity
If symmetrical key exchange is used for encrypted communication, then computational simplicity and speed are improved, but security deteriorates due to key exchange vulnerability
Solution Approach 1:
The patent merges symmetrical key encryption for high-speed data transmission with asymmetrical key exchange for secure key distribution. The protocol uses digital signatures and shared secret keys to establish symmetric encryption keys securely, combining the speed advantage of symmetrical encryption with the security advantage of asymmetrical key exchange.
Solution Approach 2:
The patent performs preliminary key exchange and authentication operations before actual data transmission begins. Devices first establish mutual authentication through digital signatures and exchange symmetric keys securely in advance, allowing high-speed symmetric encryption to be used for the bulk of data transmission without compromising security.
Data Source
AI summary
A method of establishing an encrypted communication by using keys between a first electronic device associated with a first trusted authority and a second electronic device, including generating a first secret key associated with the first device for the management of the communication, generating, at least in part by the first authority, a second secret key associated with the second device for the management of the communication. The method includes generating the first key at least in part by a second trusted authority associated with the second device that is distinct and autonomous from the first authority. Alternatively, the generation of the first key is performed, at least in part, by the second device passing through the second trusted authority.


