Dynamic Key Threat Prediction via Information Entropy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security approaches for special purpose network-connected devices are inadequate in dynamically updating keys, leading to increased threats due to predictability and resource constraints, resulting in insecure key usage and potential breaches.

Innovation Solution

A system and method for dynamically predicting the threat level of keys based on information entropy, which involves computing key usage properties and generating a predicted threat level to determine when to update or replace keys, thereby ensuring timely and secure key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If keys are updated frequently to improve security, then security reliability is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improvekey securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic key update timing based on predicted threat levels rather than fixed periodic updates. The system continuously monitors key usage patterns, computes information entropy, and adjusts key update timing dynamically to match actual security threats, thereby improving security without unnecessary frequent updates that would increase complexity

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where key usage data is collected, threat levels are predicted based on information entropy calculations, and key update decisions are made based on this feedback. This closed-loop approach allows the system to adapt key management to actual security conditions, improving reliability while avoiding unnecessary updates that would increase device complexity

Inventive Principle:
Principle #23Feedback

2Reliability

If keys are updated dynamically based on threat assessment, then security is improved, but use of energy and computational resources increases

Engineering Contradiction:
Improvekey securityVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs partial threat assessment by monitoring only critical key usage patterns and computing information entropy selectively rather than continuously analyzing all device operations. This partial monitoring approach provides sufficient security assessment while significantly reducing energy consumption compared to comprehensive continuous monitoring

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes the parameter of key update timing from fixed periodic intervals to variable intervals based on predicted threat levels. By adjusting update frequency according to actual security needs rather than using constant frequent updates, the system maintains high security reliability while reducing unnecessary energy consumption during low-threat periods

Inventive Principle:
Principle #35Parameter changes

3Difficulty of detecting and measuring

If key usage is monitored continuously to predict threat levels, then security detection capability is improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts only the essential features needed for threat prediction by focusing on key usage pattern monitoring and information entropy calculation, rather than implementing comprehensive continuous monitoring of all device operations. This extraction of critical monitoring elements improves threat detection capability while avoiding the complexity of全方位的 continuous surveillance systems

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10853499B2Key threat prediction
Publication Date: 2020.12.01 CISCO TECHNOLOGY INC
  • US10853499B2 patent drawing
  • US10853499B2 patent drawing
  • US10853499B2 patent drawing

AI summary

In one example embodiment, a network-connected device provides or obtains one or more computer network communications protected by a key. The network-connected device determines a count of the one or more computer network communications according to one or more properties of the one or more computer network communications. Based on the count of the one or more computer network communications, the network-connected device computes an information entropy of the key. Based on the information entropy of the key, the network-connected device dynamically generates a predicted threat level of the key.