Integrated Key Revocation with OTP Checks for Asset Field Loading

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security techniques for digital assets are inadequate in addressing cyberattacks, leading to compromised private keys, increased downtime, and decreased performance due to the need for physical reprogramming of hardware units at factories for key revocation.

Innovation Solution

A key revocation computing system that enables secure and real-time revocation of compromised keys, utilizing a cryptographic service component, OTP memory programming, and a key revocation list to authenticate and update keys without physical transportation, ensuring secure boot processes and integrated safety checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical reprogramming of hardware units at factories is performed for key revocation, then security of digital assets is improved, but downtime and maintenance overhead increase

Engineering Contradiction:
Improvesecurity of digital assetsVSAvoiddowntime for key revocation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical/physical process of transporting hardware units to factories for reprogramming with an electronic/digital process. The key revocation is performed remotely by transmitting revocation data to the hardware unit, eliminating the need for physical transportation and on-site reprogramming operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a key management system as an intermediary between the security compromise detection and the hardware unit reprogramming. This system manages the revocation process, generates updated cryptographic keys, and coordinates the secure transmission of revocation data to the affected hardware units.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If conventional security techniques are used, then implementation simplicity is maintained, but vulnerability to cyberattacks increases

Engineering Contradiction:
Improvesecurity system complexityVSAvoidvulnerability to cyberattacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security measures by pre-establishing a key revocation mechanism and maintaining a database of compromised keys before attacks occur. When a security breach is detected, the system can immediately revoke compromised keys and distribute updated credentials, preventing further unauthorized access rather than reacting after damage occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes a feedback loop where the system continuously monitors for security compromises, detects compromised keys through the key management system, and automatically responds by revoking those keys and distributing updated ones. This closed-loop approach allows the security system to adapt and respond to new threats dynamically.

Inventive Principle:
Principle #23Feedback

3Speed

If real-time key revocation is implemented, then system security response time is improved, but processing complexity increases

Engineering Contradiction:
Improvekey revocation speedVSAvoidprocessing complexity for key management
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements self-service capabilities where the key management system automatically performs key generation, revocation, and distribution without requiring manual intervention. The hardware units themselves can autonomously receive and apply the revoked key data, reducing the need for complex coordinated processing across multiple systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12417191B2Integrated key revocation with a field loading process and/or related safety checks related to an asset system
Publication Date: 2025.09.16 HONEYWELL INTERNATIONAL INC
  • US12417191B2 patent drawing
  • US12417191B2 patent drawing
  • US12417191B2 patent drawing

AI summary

Various embodiments relate to integrated key revocation with a field loading process and/or related safety and security checks related to an asset system. In an implementation, a data loading request to store a data file via a target storage device of an asset is received. The data file can be signed based on a first key. In response to the data loading request, a key identifier for the first key associated with the data file is compared against (i) a list of key identifiers stored in a key revocation list and (ii) a one-time programmable (OTP) memory of the asset. Additionally, in response to a determination that the data file is successfully authenticated against the key revocation list and the OTP memory, a key revocation process is performed with respect to a second key for the data file associated with the data loading request.