Hybrid Hierarchical Cryptographic System for IoT Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hierarchical identity-based encryption (HIBE) schemes face challenges in key revocation, particularly in IoT networks, where regenerating keys for all nodes is necessary, and existing post-quantum solutions are either resource-intensive or unsuitable for networks with constrained computing resources.
Innovation Solution
A hybrid hierarchical cryptographic system is introduced, where a first subset of nodes with greater computing resources runs a post-quantum RHIBE scheme, and a second subset with limited resources runs a simpler IBE scheme, connected through a one-way function-based connection primitive, allowing for hierarchical dependency and secure key management without regenerating keys across subsets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a post-quantum RHIBE scheme is deployed on all nodes, then security level is improved, but computing resource consumption increases
Solution Approach 1:
The patent applies local quality by deploying different cryptographic schemes on different subsets of nodes based on their computing resources. High-resource nodes (first subset) run the post-quantum RHIBE scheme for maximum security, while low-resource nodes (second subset) run a simpler IBE scheme. This resolves the contradiction by allowing each node to operate at its optimal security-resource balance point rather than forcing uniform deployment across all nodes.
Solution Approach 2:
The patent segments the network into two distinct subsets of nodes based on computing resource availability. This segmentation allows the system to apply different cryptographic schemes to different segments, enabling high-security operations where resources permit while maintaining functionality in resource-constrained areas, thus resolving the universal security-resource contradiction.
2Reliability
If key revocation is implemented in HIBE systems, then security is improved, but system complexity increases due to key regeneration requirements
Solution Approach 1:
The patent segments the key management system into hierarchical levels corresponding to different node subsets. When key revocation is needed, only the affected subset's keys need to be regenerated, not the entire system's keys. This segmentation dramatically reduces the complexity of key revocation operations while maintaining security, as the scope of regeneration is limited to the minimal necessary subset.
Solution Approach 2:
The patent extracts the key regeneration operation from a system-wide operation and confines it to only the necessary subset of nodes. By taking out the regeneration requirement from the entire HIBE system and limiting it to specific subsets, the patent reduces overall system complexity while preserving security through targeted key management.
3Ease of manufacture
If a unified cryptographic scheme is used across all nodes, then implementation simplicity is improved, but adaptability to different resource constraints deteriorates
Solution Approach 1:
The patent creates a universal cryptographic framework that can accommodate multiple schemes (post-quantum RHIBE and simpler IBE) within a single system. The framework is designed to be multi-functional, supporting both high-security and low-resource operational modes. This universality allows the system to adapt to different resource constraints while maintaining a unified architectural approach, resolving the contradiction between simplicity and adaptability.
Solution Approach 2:
The patent applies local quality by allowing different cryptographic schemes to be deployed in different locations (node subsets) based on local resource characteristics. This enables the system to maintain implementation simplicity through a unified framework while achieving adaptability through localized scheme selection, resolving the contradiction between uniformity and customization.
Data Source
AI summary
A hybrid cryptographic scheme for a network of nodes, in particular an IoT network, composed of a first subset and a second subset of separate nodes, the computing resources of the nodes of the first subset being greater than the computing resources of the nodes of the second subset, the scheme comprising a first functional cryptographic scheme deployed on the first subset of nodes and a second functional cryptographic scheme deployed on the second subset of nodes, a cryptographic primitive at the root of the second cryptographic scheme generating a pair of private and public master keys from a seed, the seed being obtained by a connection cryptographic primitive from at least the private key of an end node of the first subset, the connection cryptographic primitive being a one-way function.


