Application-Oriented Encryption Key Identifier Determiner

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for generating encryption keys for applications do not provide a way to distinguish between multiple encryption keys, leading to difficulties in identifying and managing them during network access authentication processes.

Innovation Solution

An authentication device and method that includes a network access authenticating unit, a master key generator, an application-oriented encryption key generator, a master key identifier determiner, and an application-oriented encryption key identifier determiner, which generate and distinguish encryption keys for applications by determining unique identifiers for both master keys and encryption keys, ensuring they are not overlapped.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple encryption keys are generated for different applications, then the ability to support multiple applications is improved, but the ability to distinguish and manage individual keys deteriorates

Engineering Contradiction:
Improveability to support multiple applicationsVSAvoidability to distinguish and manage individual keys
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the key management system by introducing distinct identifier components: application identifiers (APP_ID) for different applications and key identifiers (KEY_ID) for different key versions. This segmentation allows multiple encryption keys to be generated for different applications while maintaining clear distinction and manageability through unique identifier pairs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension to key identification by introducing application-specific identifiers alongside traditional key identifiers. Instead of relying solely on a single key identifier, the system now uses a two-dimensional identification space (APP_ID, KEY_ID), enabling unique identification of each encryption key across multiple applications and key versions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If encryption keys are generated during re-authentication or parallel authentication, then authentication flexibility is improved, but key identification and management complexity increases

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidkey identification and management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining identifier generation rules and formats before authentication occurs. The identifier structure (APP_ID, KEY_ID) is established in advance, and the system follows predetermined rules for assigning unique identifiers during re-authentication or parallel authentication processes, reducing management complexity despite increased flexibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the system tracks and manages identifier assignments across authentication sessions. By maintaining records of assigned APP_ID and KEY_ID pairs and using feedback from authentication outcomes, the system can flexibly handle re-authentication and parallel authentication while preventing identifier conflicts and managing key complexity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9065639B2Device for generating encryption key, method thereof and computer readable medium
Publication Date: 2015.06.23 KK TOSHIBA
  • US9065639B2 patent drawing
  • US9065639B2 patent drawing
  • US9065639B2 patent drawing

AI summary

There is provided an authentication device in which a network access authenticating unit executes a first network access authentication process with a communication device; master key generator generates a first master key shared with the communication device in accordance with a result of the first network access authentication process; an application-oriented encryption key generator generates a first encryption key for an application, which is shared with the communication device, on the basis of the first master key; a master key identifier determiner determines an identifier of the first master key; and an application-oriented encryption key identifier determiner determines an identifier of the first encryption key for the application in accordance with the identifier of the first master key.