Key Encryption Key Segmentation for Secure Wireless Terminal Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The distribution of encryption keys in wireless communications systems is challenging, especially in unidirectional and multicast environments, and when communications nodes are remote or unmanned, as existing methods are insecure and cumbersome, particularly for frequent key changes.

Innovation Solution

A method involving generating a key encryption key that is split into multiple portions, with each portion stored at different security levels, allowing the key encryption key to be reconstituted only from a predefined number of portions, enabling secure key management and operation even in insecure channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If keys are distributed through unsecured channels, then key distribution is simplified, but security is compromised as eavesdroppers can obtain keys

Engineering Contradiction:
Improvekey distribution simplicityVSAvoidkey security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The key encryption key is divided into multiple portions that are distributed through different channels. Each portion is marked with a security level indicator, allowing the system to segment the key distribution process into secure and unsecure channels, thereby achieving both simplicity and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where key portions are wrapped with indicators showing their security levels. This intermediary structure allows unsecured channels to transmit key portions while the wrapping mechanism ensures that only authorized entities can reconstruct the full key, thus mediating between distribution simplicity and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If keys are changed frequently for security, then security is improved, but key distribution complexity increases

Engineering Contradiction:
Improvesecurity levelVSAvoidkey distribution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By segmenting the key encryption key into multiple portions with different security level indicators, the system can perform frequent key changes without proportionally increasing distribution complexity. Each portion can be independently managed and distributed through appropriate channels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of key management by introducing security level indicators to key portions. This parameter change allows the system to maintain frequent key rotation while simplifying distribution, as the indicators provide built-in guidance on how to handle each key portion based on its security level.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If access to remote UAVs/UAGs is restricted for key loading, then security is improved, but operational flexibility is reduced

Engineering Contradiction:
Improvekey securityVSAvoidoperational flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The key encryption key is segmented into multiple portions that can be loaded through different means - some through secure physical access and others through unsecured communication channels. This segmentation allows the system to maintain security while providing operational flexibility for remote UAVs/UAGs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adapts its key loading mechanism based on the operational context. For remote UAVs/UAGs, the system can use communication channels to transmit key portions, while for grounded equipment, physical access can be used. This dynamic approach maintains both security and operational flexibility.

Inventive Principle:
Principle #15Dynamics

4Reliability

If key portions are stored at different security levels, then security is enhanced, but device complexity increases

Engineering Contradiction:
Improvesecurity levelVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces security level indicators as a parameter that is attached to each key portion. This parameter change simplifies the management of different security levels by providing clear identification and handling guidelines, thereby enhancing security without proportionally increasing device complexity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Different key portions are assigned different security level indicators, creating local quality differentiation within the key management system. This allows each key portion to be handled according to its specific security requirements, enhancing overall security while maintaining manageable complexity through standardized handling procedures.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9191200B1System and method for changing the security level of a communications terminal during operation
Publication Date: 2015.11.17 L3 TECHNOLOGIES INC
  • US9191200B1 patent drawing
  • US9191200B1 patent drawing
  • US9191200B1 patent drawing

AI summary

The security level of a communications terminal can be changed during operation. A key loading device can reconstitute a key encryption key from plural split portions. The split portions can be loaded into the key loading device via various interfaces. The reconstituted key encryption key can be used to unwrap wrapped keys stored in the key loading device.