Dynamic Working Key Generation for Secure Terminal Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data encryption methods using fixed keys in terminal devices are insecure and limit the application scope due to the risk of key leakage, leading to reduced security and limited functionality.
Innovation Solution
A method and apparatus for generating a working key that involves receiving an operating instruction, acquiring a master key value and algorithm, processing the counter value to generate a unique working key through a shift register and iterative computation, ensuring the working key is unique in each operation, and adapting the algorithm and usage based on the host's instructions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a fixed key is imported to the terminal device for encryption, then the encryption process is simple and easy to implement, but the security is reduced due to key leakage risk
Solution Approach 1:
The patent divides the encryption key into two parts: a fixed master key stored in the terminal device and a variable working key generated dynamically. This segmentation allows the master key to remain simple and secure while the working key provides variability and security for each encryption operation, resolving the contradiction between ease of implementation and security.
Solution Approach 2:
The patent introduces a dynamic working key generation mechanism that creates a unique working key for each encryption operation based on the master key and operation-specific parameters. This dynamic approach maintains simplicity in key storage while enhancing security through variability in key usage, eliminating the fixed key vulnerability.
2Ease of manufacture
If a fixed key is used to derive a working key, then the key derivation process is simple, but the application scope is limited due to algorithm constraints
Solution Approach 1:
The patent creates a universal working key generation mechanism that can derive working keys for multiple encryption algorithms (AES-128, AES-192, AES-256, 3DES) using a single master key and standardized derivation process. This multi-functionality allows the same master key infrastructure to support various encryption operations, expanding application scope while maintaining derivation simplicity.
Solution Approach 2:
The patent employs parameter changes by varying the working key generation parameters (such as operation type, data length, algorithm type) while using the same master key and derivation algorithm. This allows simple key derivation logic to produce different working keys for different application scenarios, achieving versatility without complicating the derivation process.
3Reliability
If a unique working key is generated for each operation, then security is enhanced, but the key generation process becomes complex
Solution Approach 1:
The patent performs preliminary action by pre-storing the master key and derivation algorithm in the terminal device, and by preparing standardized parameter sets for different operation types. This preliminary setup simplifies the actual key generation process during operation, as the system only needs to combine the master key with operation-specific parameters through a standardized derivation function, achieving unique keys without excessive complexity.
4Adaptability or versatility
If the working key is generated dynamically, then the application scope is widened, but the processing time increases
Solution Approach 1:
The patent replaces complex mechanical key generation processes with efficient cryptographic functions and standardized algorithms. By using well-optimized encryption primitives and parallel processing capabilities, the system achieves fast working key generation that does not significantly impact overall processing time, while still providing dynamic and versatile key generation for multiple application scenarios.
Data Source
AI summary
The invention provides a working key generation method and device and a computer readable storage medium, and belongs to the technical field of information security. The method comprises the following steps: the terminal receiving an operation instruction sent by an upper computer, obtaining a working key purpose and a working key algorithm according to the operation instruction, setting the working key purpose as a first purpose by the terminal, generating derived data according to the first purpose, a master key identifier, a first numerical value and a master key algorithm, determining the length of a working key according to the working key algorithm, obtaining data in a working key buffer area as a key, generating the working key according with the length of the working key according to the key and the derived data, executing corresponding operation according to the operation instruction and the working key, and returning an operation result to the upper computer. Compared with an encryption scheme in the prior art, the method provided by the invention is safer and wider in application range.


