Key Encryption Key Segmentation for Secure Wireless Terminal Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The distribution of encryption keys in wireless communications systems is challenging, especially in unidirectional and multicast environments, and when communications nodes are remote or unmanned, as existing methods are insecure and cumbersome, particularly for frequent key changes.
Innovation Solution
A method involving generating a key encryption key that is split into multiple portions, with each portion stored at different security levels, allowing the key encryption key to be reconstituted only from a predefined number of portions, enabling secure key management and operation even in insecure channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If keys are distributed through unsecured channels, then key distribution is simplified, but security is compromised as eavesdroppers can obtain keys
Solution Approach 1:
The key encryption key is divided into multiple portions that are distributed through different channels. Each portion is marked with a security level indicator, allowing the system to segment the key distribution process into secure and unsecure channels, thereby achieving both simplicity and security.
Solution Approach 2:
The patent introduces an intermediary mechanism where key portions are wrapped with indicators showing their security levels. This intermediary structure allows unsecured channels to transmit key portions while the wrapping mechanism ensures that only authorized entities can reconstruct the full key, thus mediating between distribution simplicity and security requirements.
2Reliability
If keys are changed frequently for security, then security is improved, but key distribution complexity increases
Solution Approach 1:
By segmenting the key encryption key into multiple portions with different security level indicators, the system can perform frequent key changes without proportionally increasing distribution complexity. Each portion can be independently managed and distributed through appropriate channels.
Solution Approach 2:
The patent changes the parameter of key management by introducing security level indicators to key portions. This parameter change allows the system to maintain frequent key rotation while simplifying distribution, as the indicators provide built-in guidance on how to handle each key portion based on its security level.
3Reliability
If access to remote UAVs/UAGs is restricted for key loading, then security is improved, but operational flexibility is reduced
Solution Approach 1:
The key encryption key is segmented into multiple portions that can be loaded through different means - some through secure physical access and others through unsecured communication channels. This segmentation allows the system to maintain security while providing operational flexibility for remote UAVs/UAGs.
Solution Approach 2:
The system dynamically adapts its key loading mechanism based on the operational context. For remote UAVs/UAGs, the system can use communication channels to transmit key portions, while for grounded equipment, physical access can be used. This dynamic approach maintains both security and operational flexibility.
4Reliability
If key portions are stored at different security levels, then security is enhanced, but device complexity increases
Solution Approach 1:
The patent introduces security level indicators as a parameter that is attached to each key portion. This parameter change simplifies the management of different security levels by providing clear identification and handling guidelines, thereby enhancing security without proportionally increasing device complexity.
Solution Approach 2:
Different key portions are assigned different security level indicators, creating local quality differentiation within the key management system. This allows each key portion to be handled according to its specific security requirements, enhancing overall security while maintaining manageable complexity through standardized handling procedures.
Data Source
AI summary
The security level of a communications terminal can be changed during operation. A key loading device can reconstitute a key encryption key from plural split portions. The split portions can be loaded into the key loading device via various interfaces. The reconstituted key encryption key can be used to unwrap wrapped keys stored in the key loading device.


