Key Change Management Apparatus for Secure Terminal Registration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online storage services face challenges in securely registering new terminals for encryption key management, as they require a user private key for re-encryption, which is typically stored encrypted with a user public key, making it difficult to add or invalidate terminals without direct access to the key.
Innovation Solution
A key change management apparatus that includes a storage system for re-encryption keys and a process for generating and managing re-encryption keys, allowing a registered terminal to change encryption keys for user private keys from a public key to a device public key, enabling secure registration and management of new terminals and invalidation of unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a user private key is stored encrypted with a user public key, then security is improved, but terminal registration and key management becomes difficult
Solution Approach 1:
The patent introduces a key change management apparatus as an intermediary between the encrypted user private key and the terminals. This apparatus holds re-encryption keys that enable authorized terminals to decrypt the user private key without requiring direct access to the encrypted key itself. The intermediary manages the key distribution and terminal registration process, resolving the contradiction by maintaining security while enabling controlled access.
Solution Approach 2:
The patent segments the key management functionality by separating the user private key encryption (handled by the user's device) from the decryption and re-encryption operations (handled by the key change management apparatus). This segmentation allows the user to maintain security by keeping their private key encrypted, while the apparatus handles the operational aspects of terminal registration and key distribution independently.
2Ease of operation
If direct access to encrypted user private key is required for terminal management, then key management is simplified, but security is compromised
Solution Approach 1:
The key change management apparatus serves as a mediator that simplifies key management operations without compromising security. It holds re-encryption keys that enable it to perform decryption and re-encryption operations on behalf of authorized terminals, eliminating the need for terminals to directly access the encrypted user private key while maintaining security controls.
Solution Approach 2:
The system enables self-service terminal registration where authorized terminals can autonomously register themselves by obtaining re-encryption keys from the key change management apparatus. This self-service mechanism simplifies key management operations while maintaining security through the controlled distribution of re-encryption capabilities.
3Adaptability or versatility
If re-encryption keys are distributed to multiple terminals, then terminal flexibility is improved, but unauthorized access risk increases
Solution Approach 1:
The key change management apparatus implements feedback control by monitoring and managing the distribution of re-encryption keys to terminals. It maintains records of which terminals are authorized to hold re-encryption keys and can revoke or update these authorizations as needed. This feedback mechanism enables flexible terminal registration while controlling unauthorized access risk through centralized management and auditability.
Data Source
AI summary
According to one embodiment, an apparatus includes a permission/inhibition information storage which stores a permission/inhibition information file, a changer which changes a first encryption key of a first private key encrypted with the first public key to the second public key by using the first re-encryption key, a first storage which stores a second private key in a device private key temporary storage, a second storage which stores a second re-encryption key in a re-encryption key storage, a permission/inhibition information registration module which registers second permission/inhibition information in the permission/inhibition information file, and a transmitter which transmits the second private key in the re-encryption key storage to the second terminal.


