Distributed Trusted Authority Key Management for Secure Device Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for establishing encrypted communication between independent electronic devices, such as mobile equipment and smart cards, face challenges due to the lack of mutual trust and shared databases among device manufacturers, leading to compromised authentication and security.

Innovation Solution

A method involving two separate Trusted Authorities generates and manages secret keys for each device, ensuring that the keys are kept secret from each other, allowing for secure encrypted communication without relying on a single external supervision authority, using identity-based encryption and symmetrical key methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single external supervision authority (PKI CA) is used to manage public keys and authentication, then security and authentication reliability are improved, but device complexity and dependency on external authorities increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the single centralized PKI authority into multiple independent Trusted Authorities (TA), each managing keys and authentication for specific device types or groups. This segmentation reduces dependency on a single authority while maintaining security through distributed trust management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces mutual authentication protocols where devices authenticate each other directly through shared secret keys and digital signatures, eliminating the need for continuous intervention from external PKI authorities. The TA acts as an intermediary that issues keys but does not continuously monitor or control communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If public key infrastructure (PKI) with digital certificates is used, then security and key management are improved, but loss of information and privacy concerns increase due to centralized authority control

Engineering Contradiction:
Improvekey management securityVSAvoidprivacy loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts the private key generation and management functions from the centralized PKI authority and transfers them to individual devices. Each device generates its own private key pair independently, with only the public key and certificate shared with the TA. This extraction eliminates the risk of centralized authority accessing private keys.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Devices perform self-authentication and self-key-management operations using stored secret keys and digital signatures. The mutual authentication protocol allows devices to verify each other's identity independently without requiring continuous verification from external authorities, enabling privacy-preserving communication.

Inventive Principle:
Principle #25Self-service

3Productivity

If symmetrical key exchange is used for encrypted communication, then computational simplicity and speed are improved, but security deteriorates due to key exchange vulnerability

Engineering Contradiction:
Improvecommunication speedVSAvoidencryption security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent merges symmetrical key encryption for high-speed data transmission with asymmetrical key exchange for secure key distribution. The protocol uses digital signatures and shared secret keys to establish symmetric encryption keys securely, combining the speed advantage of symmetrical encryption with the security advantage of asymmetrical key exchange.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary key exchange and authentication operations before actual data transmission begins. Devices first establish mutual authentication through digital signatures and exchange symmetric keys securely in advance, allowing high-speed symmetric encryption to be used for the bulk of data transmission without compromising security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7620186B2Method for establishing an encrypted communication by means of keys
Publication Date: 2009.11.17 STMICROELECTRONICS SRL
  • US7620186B2 patent drawing
  • US7620186B2 patent drawing
  • US7620186B2 patent drawing

AI summary

A method of establishing an encrypted communication by using keys between a first electronic device associated with a first trusted authority and a second electronic device, including generating a first secret key associated with the first device for the management of the communication, generating, at least in part by the first authority, a second secret key associated with the second device for the management of the communication. The method includes generating the first key at least in part by a second trusted authority associated with the second device that is distinct and autonomous from the first authority. Alternatively, the generation of the first key is performed, at least in part, by the second device passing through the second trusted authority.