Key Management Server Proactive Decryption Key Supply

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In existing communication systems, the decryption key for decrypting encrypted packets cannot be acquired from the key management server device until the encrypted packet is received, leading to delays in the decryption process.

Innovation Solution

The communication system includes a key management server device that generates and supplies decryption keys proactively based on control signals, allowing routers to decrypt packets without waiting for the encrypted packet to be received, using quantum key distribution for secure key sharing and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the decryption key is acquired from the key management server device only after the encrypted packet is received, then the system maintains simple key management procedures, but the decryption process experiences delays reducing communication throughput

Engineering Contradiction:
Improvedecryption throughputVSAvoidkey acquisition delay
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The key management server device proactively transmits decryption keys to routers before encrypted packets arrive. The server generates decryption keys based on control signals and sends them in advance, allowing routers to have keys ready when packets need decryption, thereby eliminating waiting time and improving throughput

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The key management server device acts as an intermediary that pre-distributes decryption keys to multiple routers. This intermediary function allows keys to be available at multiple points in the network before encrypted data arrives, enabling parallel preparation and reducing overall decryption latency

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If decryption keys are pre-generated and stored in the key management server device, then decryption speed is improved, but the key management system becomes more complex

Engineering Contradiction:
Improvedecryption speedVSAvoidkey management complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The key management server device automatically generates decryption keys based on control signals and transmits them proactively to routers without manual intervention. This self-service mechanism simplifies operations while enabling speed improvements, as the system autonomously manages key lifecycle including generation, distribution, and updates

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The key management system dynamically generates and distributes decryption keys based on real-time control signals and network conditions. Rather than static pre-stored keys, the system adapts key generation and distribution timing to actual decryption needs, balancing speed improvement with manageable complexity

Inventive Principle:
Principle #15Dynamics

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach enables rapid decryption of packets by ensuring that decryption keys are available before the encrypted data is processed, improving forward throughput and reducing delays in the communication system.

Implementation Method 1

quantum key distribution for secure key sharing and management

Methodology Applied
Scientific EffectQuantum key distribution:

Data Source

PatentEP3944555B1Communication system, key management server device, router, and computer-readable medium
Publication Date: 2023.09.06 KK TOSHIBA
  • EP3944555B1 patent drawingFigure 1
  • EP3944555B1 patent drawingFigure 2
  • EP3944555B1 patent drawingFigure 3

AI summary

According to an arrangement, a communication system (100) includes a key management server device (20a, 20b) and a router (10a, 10b). A key distribution processing module (21) shares a bit string by quantum key distribution. A control signal processing module (23) receives a control signal including key identification information identifying an encryption key generated from the bit string and a key length indicating a length of the encryption key. A decryption key generation module (26) generates a decryption key corresponding to the encryption key from the bit string based on the key identification information and the key length upon receiving the control signal without waiting for a request to generate the decryption key from the router. A supply module (25) supplies the decryption key to the router. A packet reception processing module (11) receives a packet encrypted with the encryption key. A decryption processing module (17) decrypts the packet using the decryption key supplied from the key management server device without requesting the key management server device to generate the decryption key.