Hub-Mediated Key Negotiation for Non-Sensitive Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Home devices lacking key negotiation capabilities, particularly non-sensitive devices, expose information transmission to security risks and cloud tampering, compromising user control accuracy and experience.
Innovation Solution
A hub device performs key negotiation on behalf of non-sensitive devices, generating shared keys with other devices to encrypt information, ensuring secure transmission and user control accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If key negotiation capability is integrated on non-sensitive devices, then information transmission security is improved, but device complexity and memory requirements increase
Solution Approach 1:
The patent introduces a hub device as an intermediary component that performs key negotiation on behalf of non-sensitive devices. The hub device generates public key information and private key information for the non-sensitive device, and performs key negotiation with terminal devices through the cloud. This allows non-sensitive devices to achieve secure information transmission without integrating complex key negotiation capabilities themselves, thus resolving the contradiction between security improvement and device complexity increase.
2Reliability
If key negotiation capability is integrated on non-sensitive devices, then information transmission security is improved, but memory requirements increase
Solution Approach 1:
The hub device serves as a memory externalization solution. Instead of storing key negotiation components and cryptographic operations within the limited memory of non-sensitive devices, the system outsources these functions to the hub device which has sufficient memory resources. The non-sensitive device only stores minimal identification information, while the hub device handles all key generation and negotiation operations, thereby resolving the memory constraint.
3Ease of operation
If cloud-based control is used for non-sensitive devices, then ease of operation is improved, but information security deteriorates due to cloud access
Solution Approach 1:
The hub device acts as a security intermediary between the terminal device and the non-sensitive device via the cloud. All information transmission is encrypted using keys generated through key negotiation between the terminal device and hub device. The cloud only transmits encrypted data without being able to access or tamper with the content, thus maintaining ease of cloud-based operation while preventing cloud security risks.
Solution Approach 2:
The patent replaces the traditional mechanical trust model (where the cloud server itself needs to be trusted) with a cryptographic substitution model. Instead of relying on the cloud server's security, the system uses public key infrastructure and shared secret keys to ensure security. The cloud becomes just a transmission medium, and security is achieved through mathematical cryptography rather than physical or organizational trust.
4Reliability
If key negotiation is performed by hub device for non-sensitive devices, then information security is improved, but device complexity of hub increases
Solution Approach 1:
The hub device is designed with multi-functionality, serving both sensitive devices and non-sensitive devices. For sensitive devices, the hub provides key negotiation and secure communication. For non-sensitive devices, the hub also performs key negotiation to enable cloud-based control. This universal design allows the hub to handle diverse security requirements without requiring separate specialized systems, managing complexity through unified architecture.
Data Source
AI summary
Example key negotiation methods and apparatus are described. One example method includes generating, by a first hub device, public key information and private key information of a first electronic device, where the first electronic device accesses a network by using the first hub device. The first hub device reports a first mode of the first electronic device to a cloud device, and obtains public key information of a second electronic device. The first hub device performs key negotiation with the second electronic device based on the private key information of the first electronic device and the public key information of the second electronic device, to generate a first shared key.


