Hybrid Hierarchical Cryptographic System for IoT Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hierarchical identity-based encryption (HIBE) schemes face challenges in key revocation, particularly in IoT networks, where regenerating keys for all nodes is necessary, and existing post-quantum solutions are either resource-intensive or unsuitable for networks with constrained computing resources.

Innovation Solution

A hybrid hierarchical cryptographic system is introduced, where a first subset of nodes with greater computing resources runs a post-quantum RHIBE scheme, and a second subset with limited resources runs a simpler IBE scheme, connected through a one-way function-based connection primitive, allowing for hierarchical dependency and secure key management without regenerating keys across subsets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a post-quantum RHIBE scheme is deployed on all nodes, then security level is improved, but computing resource consumption increases

Engineering Contradiction:
Improvesecurity levelVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by deploying different cryptographic schemes on different subsets of nodes based on their computing resources. High-resource nodes (first subset) run the post-quantum RHIBE scheme for maximum security, while low-resource nodes (second subset) run a simpler IBE scheme. This resolves the contradiction by allowing each node to operate at its optimal security-resource balance point rather than forcing uniform deployment across all nodes.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the network into two distinct subsets of nodes based on computing resource availability. This segmentation allows the system to apply different cryptographic schemes to different segments, enabling high-security operations where resources permit while maintaining functionality in resource-constrained areas, thus resolving the universal security-resource contradiction.

Inventive Principle:
Principle #1Segmentation

2Reliability

If key revocation is implemented in HIBE systems, then security is improved, but system complexity increases due to key regeneration requirements

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key management system into hierarchical levels corresponding to different node subsets. When key revocation is needed, only the affected subset's keys need to be regenerated, not the entire system's keys. This segmentation dramatically reduces the complexity of key revocation operations while maintaining security, as the scope of regeneration is limited to the minimal necessary subset.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the key regeneration operation from a system-wide operation and confines it to only the necessary subset of nodes. By taking out the regeneration requirement from the entire HIBE system and limiting it to specific subsets, the patent reduces overall system complexity while preserving security through targeted key management.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of manufacture

If a unified cryptographic scheme is used across all nodes, then implementation simplicity is improved, but adaptability to different resource constraints deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidadaptability to resource constraints
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal cryptographic framework that can accommodate multiple schemes (post-quantum RHIBE and simpler IBE) within a single system. The framework is designed to be multi-functional, supporting both high-security and low-resource operational modes. This universality allows the system to adapt to different resource constraints while maintaining a unified architectural approach, resolving the contradiction between simplicity and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies local quality by allowing different cryptographic schemes to be deployed in different locations (node subsets) based on local resource characteristics. This enables the system to maintain implementation simplicity through a unified framework while achieving adaptability through localized scheme selection, resolving the contradiction between uniformity and customization.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240178998A1SystÈme de chiffrement hiÉrarchique hybride
Publication Date: 2024.05.30 COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
  • US20240178998A1 patent drawing
  • US20240178998A1 patent drawing
  • US20240178998A1 patent drawing

AI summary

A hybrid cryptographic scheme for a network of nodes, in particular an IoT network, composed of a first subset and a second subset of separate nodes, the computing resources of the nodes of the first subset being greater than the computing resources of the nodes of the second subset, the scheme comprising a first functional cryptographic scheme deployed on the first subset of nodes and a second functional cryptographic scheme deployed on the second subset of nodes, a cryptographic primitive at the root of the second cryptographic scheme generating a pair of private and public master keys from a seed, the seed being obtained by a connection cryptographic primitive from at least the private key of an end node of the first subset, the connection cryptographic primitive being a one-way function.