Joint Private Key Generation via Segmented Sub-Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing symmetric key authentication system is inadequate for the new trilateral relationship between telecom operators, vertical industry customers, and terminal devices, as it requires both parties to prestore the same authentication key, posing a security risk by allowing either party to control the authentication key.

Innovation Solution

A private key generation method and system that generates a joint private key trusted by both telecom operators and vertical industry customers, but not controlled by either, by using a combination of sub-private keys generated by separate network devices and synthesized on the terminal device, ensuring that neither party has access to the entire key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a symmetric key authentication system is used where both telecom operator and terminal device prestore the same authentication key, then authentication can be performed, but the authentication key can be controlled by either party posing a security threat

Engineering Contradiction:
Improveauthentication securityVSAvoidkey control risk
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The authentication key is segmented into two separate sub-keys: a first sub-key generated and held by the telecom operator, and a second sub-key generated and held by the vertical industry customer. Neither party possesses the complete authentication key alone, eliminating the security risk of key control while maintaining authentication capability through combination of both sub-keys.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the authentication key is controlled by the telecom operator, then authentication can be performed, but the vertical industry customer loses control over their digital asset security

Engineering Contradiction:
Improveauthentication operationVSAvoiddigital asset security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication key is segmented into two separate sub-keys: a first sub-key generated and held by the telecom operator, and a second sub-key generated and held by the vertical industry customer. Neither party possesses the complete authentication key alone, eliminating the security risk of key control while maintaining authentication capability through combination of both sub-keys.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the authentication key is controlled by the vertical industry customer, then digital asset security is improved, but the telecom operator cannot perform authentication

Engineering Contradiction:
Improvedigital asset securityVSAvoidauthentication operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication key is segmented into two separate sub-keys: a first sub-key generated and held by the telecom operator, and a second sub-key generated and held by the vertical industry customer. Neither party possesses the complete authentication key alone, eliminating the security risk of key control while maintaining authentication capability through combination of both sub-keys.

Inventive Principle:
Principle #1Segmentation

4Reliability

If a joint private key system is implemented where neither party controls the full key, then security is enhanced, but key generation complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidkey generation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A key generation center acts as an intermediary to coordinate the joint private key generation process. The center receives requests from both the telecom operator and vertical industry customer, manages the generation of respective sub-keys, and facilitates the combination process, thereby reducing the complexity burden on individual parties while maintaining the security benefits of the segmented key system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11212088B2Private key generation method and system, and device
Publication Date: 2021.12.28 HUAWEI TECH CO LTD
  • US11212088B2 patent drawing
  • US11212088B2 patent drawing
  • US11212088B2 patent drawing

AI summary

Embodiments of this application provide a private key generation method and system, and a device. The method includes: receiving, by a terminal device, a first response message sent by a first network device, where the first response message includes at least a first sub-private key, and the first sub-private key is generated based on a first parameter set sent by a second network device; receiving, by the terminal device, a second response message sent by the second network device, where the second response message includes at least a second sub-private key, and the second sub-private key is generated based on a second parameter set sent by the first network device; and synthesizing, by the terminal device, a joint private key based on at least the first sub-private key and the second sub-private key.