Encryption Key Distribution for Telecommunication Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication networks face challenges in maintaining security and interoperability when transitioning between different encryption key sizes, requiring frequent hardware or software updates and leading to potential vulnerabilities and maintenance costs, especially when cohabiting older and newer terminal sets with varying key sizes.
Innovation Solution
A method for distributing encryption keys through a key management server that identifies terminal sets and processes keys using one-way functions to ensure compatibility between terminals with different key sizes, allowing seamless communication and decryption without requiring updates to existing terminals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the encryption key size is increased to improve network security, then security level is improved, but all existing terminals require hardware or software updates which increases device complexity and maintenance costs
Solution Approach 1:
The patent segments the terminal population into two distinct sets: terminals with older encryption keys (first type) and terminals with newer encryption keys (second type). This segmentation allows each set to operate with its own key type without requiring all terminals to be updated simultaneously, thus improving security for new terminals while maintaining compatibility for existing ones.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of a key management server that distributes different key types to different terminal sets and enables cross-key communication. The server acts as a mediator that facilitates secure communication between terminals with different key sizes without requiring direct updates to existing terminals.
2Adaptability or versatility
If two types of common keys are maintained for different terminal sets, then compatibility is improved, but key management complexity increases and security is weakened
Solution Approach 1:
The patent implements a universal key management server that handles multiple key types and communication scenarios through a single system. The server can distribute both first-type and second-type keys, manage terminal identification, and facilitate communication between any combination of terminals regardless of their key type, thus reducing overall system complexity despite supporting multiple key types.
Solution Approach 2:
The patent performs preliminary identification of terminals by comparing their addresses against known sets when they first connect to the network. This preliminary action allows the system to assign the appropriate key type in advance, avoiding the need for complex real-time key negotiation or conversion during communication.
3Reliability
If all terminals are recalled for updates to maintain security, then network security is improved, but service interruption and maintenance costs increase
Solution Approach 1:
The patent implements a dynamic key management approach where the network can accommodate both old and new key types simultaneously. New terminals receive enhanced security keys without affecting existing terminals, allowing the network to evolve its security posture dynamically over time rather than requiring synchronized updates across all terminals.
Solution Approach 2:
The system performs preliminary identification and key assignment when terminals first connect, rather than requiring updates during operation. This allows new terminals to be onboarded with enhanced security keys without interrupting service for existing terminals, and existing terminals continue operating with their current keys until they are naturally replaced or upgraded.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The method involves receiving a data message from a terminal (TS), where the data message includes an address of the terminal. An identification of the terminal is performed by comparison of the address of the terminal to establish a membership of the terminals. A key is selected when the terminal belongs to an assembly (ENSS) of the terminals. The key is processed by a data server (SERV) by utilizing a specific function. The key or another key is transmitted according to the membership of the terminals. : Independent claims are also included for the following: (1) a method for coding of data (2) a method for deciphering of data (3) a base station. USE : Method for distributing a digital encryption key to a telecommunication terminal. ADVANTAGE : The key or another key is transmitted according to the membership of the terminals, thus increasing total security ratings of communications of terminals of the network, while ensuring an interworking between various generations of operational terminals. The method saves time with regard to maintenance of the terminals of the network. The key is compatible with all terminals. The terminal is easily deployable in the communication network by allowing coding functions with high degree of safety. The method increases security level and confidentiality of the terminals, while ensuring computability of the terminals requiring keys of small size. DESCRIPTION OF DRAWINGS : The drawing shows a block diagram of a communication equipment in a network. CH : Data coding function ENSS : Assembly of terminals F1 : Function SERV : Data server TS : Terminal.