Hierarchical Key Management for Secure Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multimedia communication systems inadequately support security in the media plane, particularly requiring pre-existing security associations between key management services from different administrative domains, limiting flexibility and resource efficiency in key management solutions.

Innovation Solution

A hierarchical key management methodology is introduced, where key management services at different levels establish security associations with a higher-level service, allowing for flexible deployment and simplifying the provisioning of security associations, eliminating the need for pre-existing one-to-one associations between services from different domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-existing one-to-one security associations are established between key management services from different administrative domains, then secure communication between user equipment can be achieved, but device complexity and resource requirements increase significantly

Engineering Contradiction:
Improvesecure communicationVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key management system into a hierarchical structure with multiple levels. Instead of requiring direct one-to-one security associations between all key management services, the system divides key management functions across hierarchical levels, where each level manages security associations with its immediate children or parents. This segmentation reduces the overall complexity by breaking down the monolithic key management approach into manageable hierarchical units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested hierarchical structure where key management services are organized in parent-child relationships across multiple levels. Each key management service nests within a hierarchical framework, with higher-level services managing security associations for lower-level services. This nesting allows security associations to be established transitively through the hierarchy rather than requiring direct associations between all pairs of services.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If pre-existing one-to-one security associations are established between key management services, then secure key distribution is enabled, but the system loses flexibility in deployment and administrative domain management

Engineering Contradiction:
Improvesecure key distributionVSAvoiddeployment flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The hierarchical segmentation allows different administrative domains to operate independently at various levels of the hierarchy. Each domain can manage its own key management services without requiring pre-configured associations with all other domains, enabling flexible deployment scenarios including multi-domain, cross-administrative, and hierarchical key management configurations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hierarchical key management structure provides universal applicability across different deployment scenarios. The same hierarchical framework can accommodate single-domain, multi-domain, cross-administrative, and federated key management configurations, making the system versatile and adaptable to various organizational and administrative requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If direct security associations are established between all key management services, then secure communication is guaranteed, but resource requirements and provisioning overhead increase

Engineering Contradiction:
Improvesecure communication guaranteeVSAvoidresource requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges security association management at higher hierarchical levels to serve multiple lower-level services. Instead of each key management service maintaining separate direct associations with all other services, the hierarchical structure allows higher-level services to consolidate and manage security associations that benefit multiple downstream services, reducing redundant resource consumption.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

By segmenting security association management into hierarchical levels, the system reduces the total number of required associations. Each service only needs to maintain associations with its immediate hierarchical peers rather than all possible counterparts, significantly reducing provisioning overhead and resource requirements while maintaining security guarantees through transitive trust relationships.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2524469B1Hierarchical key management for secure communications in multimedia communication system
Publication Date: 2019.07.03 ALCATEL LUCENT SA
  • EP2524469B1 patent drawingFigure 1
  • EP2524469B1 patent drawingFigure 1B
  • EP2524469B1 patent drawingFigure 2A

AI summary

In a communication system wherein a first computing device is configured to perform a key management function for first user equipment and a second computing device is configured to perform a key management function for second user equipment, wherein the first user equipment seeks to initiate communication with the second user equipment, wherein the first computing device and the second computing device do not have a pre-existing security association there between, and wherein a third computing device is configured to perform a key management function and has a pre-existing security association with the first computing device and a pre-existing security association with the second computing device, the third computing device performing a method comprising steps of: receiving a request from one of the first computing device and the second computing device; and in response to the request, facilitating establishment of a security association between the first computing device and the second computing device such that the first computing device and the second computing device can then facilitate establishment of a security association between the first user equipment and the second user equipment. The first computing device, the second computing device and the third computing device comprise at least a part of a key management hierarchy wherein the first computing device and the second computing device are on a lower level of the hierarchy and the third computing device is on a higher level of the hierarchy.