Key Management Device Security Key Renewal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication systems, simultaneous renewal of security keys across multiple devices is challenging, especially in large-scale systems with distributed devices, as it risks invalidating data packets en route due to the use of expired keys.

Innovation Solution

A method involving a key management device that transmits a new security key, activation messages for both transmission and reception, and deactivation messages for the old key, ensuring all devices switch to the new key before revoking the old one, allowing for seamless key renewal without data packet loss.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If simultaneous key renewal is performed across all devices, then security level is maintained, but data packets may be invalidated during transmission

Engineering Contradiction:
Improvesecurity levelVSAvoiddata packet validity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary key distribution and activation before the old key is deactivated. The new key is distributed to all devices and activated for reception before transmission, ensuring a smooth transition without invalidating data packets in transit.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system allows dynamic key usage where devices can use both old and new keys during a transition period. The key server manages the temporal dynamics of key activation and deactivation, allowing flexible key rotation without rigid simultaneity constraints.

Inventive Principle:
Principle #15Dynamics

2Loss of information

If key renewal is delayed to avoid packet invalidation, then data packet continuity is maintained, but security level deteriorates

Engineering Contradiction:
Improvedata packet continuityVSAvoidsecurity level
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The new key is distributed and activated before the old key is deactivated, allowing continuous operation with the new key while maintaining security. This preliminary action ensures both security and continuity are achieved.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system ensures continuous communication capability by allowing devices to receive with the new key before the old key is deactivated. This maintains the useful action of data transmission without interruption while upgrading security.

Inventive Principle:
Principle #20Continuity of useful action

3Adaptability or versatility

If separate key servers are used for distributed devices, then system scalability is improved, but key renewal coordination becomes more complex

Engineering Contradiction:
Improvesystem scalabilityVSAvoidkey renewal coordination
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Each key server can independently perform the complete key renewal function for its assigned devices. The universal key renewal mechanism works across multiple key servers, allowing scalable deployment without increasing coordination complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments the communication network into multiple key server zones, each managing a subset of devices. This segmentation allows independent key renewal operations in each zone, reducing overall coordination complexity while maintaining scalability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2873188B1Methods and devices for security key renewal in a communication system
Publication Date: 2016.09.14 ABB RES LTD
  • EP2873188B1 patent drawingFigure 1~2
  • EP2873188B1 patent drawingFigure 3~4
  • EP2873188B1 patent drawingFigure 5~6

AI summary

The present disclosure relates to a method (20) for security key renewal performed in a key management device (2) of a communication system (1). The communication system (1) comprises two or more communication devices (3, 4, 5, 6) communicating data packets by using a first security key for transmission and reception. The method (20) comprises: transmitting (21), to the two or more communication devices (3, 4, 5, 6), a second security key for transmission and reception of the data packets; transmitting (22), to the two or more communication devices (3, 4, 5, 6), an activation message for activating use of the second security key for reception of the data packets; transmitting (23), to the two or more communication devices (3, 4, 5, 6), an activation message for activating use of the second security key for transmission of the data packets; transmitting (24), to the two or more communication devices (3, 4, 5, 6); a deactivation message for deactivating use of the first security key for transmission of the data packets; and transmitting (25), to the two or more communication devices (3, 4, 5, 6), a deactivation message for deactivating use of the first security key for reception of the data packets.