Key Management Device Security Key Renewal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication systems, simultaneous renewal of security keys across multiple devices is challenging, especially in large-scale systems with distributed devices, as it risks invalidating data packets en route due to the use of expired keys.
Innovation Solution
A method involving a key management device that transmits a new security key, activation messages for both transmission and reception, and deactivation messages for the old key, ensuring all devices switch to the new key before revoking the old one, allowing for seamless key renewal without data packet loss.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If simultaneous key renewal is performed across all devices, then security level is maintained, but data packets may be invalidated during transmission
Solution Approach 1:
The system performs preliminary key distribution and activation before the old key is deactivated. The new key is distributed to all devices and activated for reception before transmission, ensuring a smooth transition without invalidating data packets in transit.
Solution Approach 2:
The system allows dynamic key usage where devices can use both old and new keys during a transition period. The key server manages the temporal dynamics of key activation and deactivation, allowing flexible key rotation without rigid simultaneity constraints.
2Loss of information
If key renewal is delayed to avoid packet invalidation, then data packet continuity is maintained, but security level deteriorates
Solution Approach 1:
The new key is distributed and activated before the old key is deactivated, allowing continuous operation with the new key while maintaining security. This preliminary action ensures both security and continuity are achieved.
Solution Approach 2:
The system ensures continuous communication capability by allowing devices to receive with the new key before the old key is deactivated. This maintains the useful action of data transmission without interruption while upgrading security.
3Adaptability or versatility
If separate key servers are used for distributed devices, then system scalability is improved, but key renewal coordination becomes more complex
Solution Approach 1:
Each key server can independently perform the complete key renewal function for its assigned devices. The universal key renewal mechanism works across multiple key servers, allowing scalable deployment without increasing coordination complexity.
Solution Approach 2:
The system segments the communication network into multiple key server zones, each managing a subset of devices. This segmentation allows independent key renewal operations in each zone, reducing overall coordination complexity while maintaining scalability.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
The present disclosure relates to a method (20) for security key renewal performed in a key management device (2) of a communication system (1). The communication system (1) comprises two or more communication devices (3, 4, 5, 6) communicating data packets by using a first security key for transmission and reception. The method (20) comprises: transmitting (21), to the two or more communication devices (3, 4, 5, 6), a second security key for transmission and reception of the data packets; transmitting (22), to the two or more communication devices (3, 4, 5, 6), an activation message for activating use of the second security key for reception of the data packets; transmitting (23), to the two or more communication devices (3, 4, 5, 6), an activation message for activating use of the second security key for transmission of the data packets; transmitting (24), to the two or more communication devices (3, 4, 5, 6); a deactivation message for deactivating use of the first security key for transmission of the data packets; and transmitting (25), to the two or more communication devices (3, 4, 5, 6), a deactivation message for deactivating use of the first security key for reception of the data packets.