Group Key Management via Trusted Modules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing broadcast encryption schemes rely on a central authority to distribute and manage keys, making them inefficient for group key management and requiring multiple secure authenticated channels for adding or removing devices from a group.
Innovation Solution
Implementing a trusted module within devices that can generate, distribute, and manage keys independently, reducing the number of secure authenticated channels required for adding new devices to one and enabling secure key distribution without external central authority intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a central authority is used to distribute and manage keys in broadcast encryption schemes, then key distribution can be centralized and controlled, but the system complexity increases and efficiency decreases for group key management
Solution Approach 1:
The patent extracts the key management function from the central authority and embeds it directly into the devices themselves. Each device is equipped with a trusted module that can independently generate, store, and manage cryptographic keys, eliminating the need for external key distribution infrastructure and reducing system complexity.
Solution Approach 2:
Devices perform self-service key management through their trusted modules, which autonomously generate keys and manage cryptographic operations without requiring external intervention. This self-contained approach simplifies the overall system architecture while maintaining secure key management capabilities.
2Reliability
If multiple secure authenticated channels are required for adding or removing devices from a group, then security is maintained, but the process complexity and cost increase
Solution Approach 1:
The patent merges multiple secure authenticated channels into a single channel by having the trusted module handle all cryptographic operations and key exchanges through one secure connection. This consolidation maintains security requirements while significantly reducing the complexity of device addition and removal processes.
3Adaptability or versatility
If devices possess keys of all other devices in the group, then secure communication to any subset is enabled, but the number of keys each device must manage increases with group size
Solution Approach 1:
The patent segments the key management approach by having devices store only their own private key in the trusted module rather than all group keys. The trusted module uses these segmented key materials to perform cryptographic operations for communicating with any subset of the group, reducing the key storage burden while maintaining versatility.
Data Source
AI summary
A method of adding a new device (121) to a device group (110), wherein the device group comprises at least one device (111) that hosts a trusted module (151), the method including: generating keys of the trusted modules (151, 153) and devices (111, 112, 113, . . . , 11N) in the device group and a key of the new device (121); distributing the generated keys to the trusted modules (151, 153) in the device group (110); distributing the generated keys to the devices in the device group, such that each device in the device group receives the key of the new device, the keys of the trusted modules and of all other devices in the device group, except for its own key; establishing a secure authenticated channel (130) between the trusted module (151) and the new device (121); and sending to the new device (121) the generated keys except for the key of the new device.


