Key Management Threshold Mechanism for Communication Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key management systems in communication networks face inefficiencies and increased computational load when users switch between service groups, leading to reduced quality of service and increased overhead, especially in large public environments.

Innovation Solution

A method and apparatus for key management that determines a time-dependent quantity during user switching between service groups, resetting this quantity with each switch, and only updates keys when the user decides to join a new group by exceeding a predetermined threshold, minimizing re-keying and maintaining service quality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If key updates are performed every time a user switches between service groups, then security is maintained, but computational load and signaling overhead increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by updating keys only when necessary (when a user definitively joins a new service group) rather than performing full key updates on every service switch. This reduces the frequency of key management operations while maintaining security, directly addressing the contradiction between security and computational load.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent uses preliminary action by introducing a threshold mechanism that monitors service switching behavior before triggering a key update. The system accumulates switching events and only performs key management when the threshold is exceeded, allowing the system to prepare and execute key updates less frequently while still maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If key updates are performed for all users when one user leaves or joins a service group, then security is maintained, but service quality deteriorates due to interruptions

Engineering Contradiction:
ImprovesecurityVSAvoidservice quality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the user base by introducing the concept of service switching groups that are separate from service groups. This allows key management to be performed on a segmented basis - only affecting users in the switching group rather than all users in the service group - thereby maintaining security while minimizing service interruptions for the majority of users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces service switching groups as an intermediary layer between individual users and service groups. This intermediary structure allows the system to manage key updates more efficiently by containing the impact to only those users actively switching services, rather than forcing all service group members to undergo key management operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If re-keying is performed frequently to maintain security, then security is improved, but signaling overhead and network traffic increase

Engineering Contradiction:
ImprovesecurityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements periodic action through the threshold-based mechanism that monitors service switching over time. Instead of continuous or event-driven key updates, the system periodically evaluates whether the accumulated switching activity warrants a key update, reducing signaling overhead while maintaining security through time-based monitoring.

Inventive Principle:
Principle #19Periodic action

4Device complexity

If all services are encrypted with the same key for simplicity, then device complexity is reduced, but access control flexibility is lost

Engineering Contradiction:
Improvekey management complexityVSAvoidaccess control flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent applies universality by creating service switching groups that can serve multiple functions: they enable fine-grained access control for users switching between services, reduce key management overhead, and maintain compatibility with existing service group structures. This multi-functional approach simplifies the overall system while providing flexible access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8515064B2Method and an apparatus for key management in a communication network
Publication Date: 2013.08.20 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US8515064B2 patent drawing
  • US8515064B2 patent drawing
  • US8515064B2 patent drawing

AI summary

A method of key management in a communication network that includes a plurality of groups with each group including one or several members authorized to have access to key-protected services is provided by an apparatus. The method includes determining when a member starts a switching action from one service to another. A time dependent quantity starting from the switching action is determined. The method includes determining that the member is a member of a switching group when the quantity is less than a threshold value is made, and when the quantity is larger than the threshold, determining that the member has decided to join a new group, and changing the appropriate access key(s).