IP Security Key Exchange via Intermediary Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IP communications networks lack a secure method to exchange and monitor security keys, particularly in public networks, where security keys are not exposed to the public network and cannot be read even if hardware is tampered with, and existing systems do not support per-session and per-call key changes.
Innovation Solution
A system and method for securely exchanging and monitoring security keys in IP communications networks by using a security device with interfaces, secure data storage, and a processor to receive, store, and decode messages using the security key, ensuring the key is never exposed to the public network and can change per session or call, allowing for anomaly detection and deployment of multiple security products.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If security keys are exchanged over public networks, then key exchange is enabled, but security is compromised as keys may be exposed to eavesdropping
Solution Approach 1:
The patent introduces a key distribution center (KDC) as an intermediary entity that facilitates secure key exchange between users. The KDC generates session keys and distributes them through a controlled process, preventing direct exposure of keys over public networks while enabling key exchange functionality. This mediator approach resolves the contradiction by providing both key exchange capability and security protection.
2Ease of operation
If security keys are stored in accessible memory, then key availability is improved, but vulnerability to hardware tampering increases
Solution Approach 1:
The patent implements key storage in read-only memory (ROM) as a protective copy mechanism. The security keys are stored in a non-volatile, tamper-resistant form that prevents modification while maintaining availability. This copying approach allows the system to access keys for authentication operations while protecting against hardware tampering attempts, resolving the contradiction between availability and vulnerability.
3Device complexity
If fixed security keys are used, then system simplicity is maintained, but adaptability to per-session security requirements is reduced
Solution Approach 1:
The patent implements a dynamic key management system where session keys are generated and distributed on-demand based on authentication results. Instead of using fixed keys, the system creates new session keys for each communication session, providing adaptability to per-session security requirements. The key distribution center dynamically assigns appropriate keys to users based on their authentication status, resolving the contradiction between simplicity and adaptability.
Data Source
AI summary
The present invention provides a system, method and apparatus for securely exchanging security keys and monitoring links in an IP communications network. The apparatus is disposed between the local device and the remote device and receives a security key associated with the secure communication(s) for the local device. The apparatus then uses the security key to decode one or more messages transmitted between the local device and the remote device. The apparatus may initiate one or more security protocols whenever the decoded message(s) satisfy one or more criteria. Note that the present invention can be implemented as a computer program embodied on a computer readable medium wherein each step is performed by one or more code segments.


