Key Management Threshold Mechanism for Communication Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing key management systems in communication networks face inefficiencies and increased computational load when users switch between service groups, leading to reduced quality of service and increased overhead, especially in large public environments.
Innovation Solution
A method and apparatus for key management that determines a time-dependent quantity during user switching between service groups, resetting this quantity with each switch, and only updates keys when the user decides to join a new group by exceeding a predetermined threshold, minimizing re-keying and maintaining service quality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If key updates are performed every time a user switches between service groups, then security is maintained, but computational load and signaling overhead increase significantly
Solution Approach 1:
The patent applies partial action by updating keys only when necessary (when a user definitively joins a new service group) rather than performing full key updates on every service switch. This reduces the frequency of key management operations while maintaining security, directly addressing the contradiction between security and computational load.
Solution Approach 2:
The patent uses preliminary action by introducing a threshold mechanism that monitors service switching behavior before triggering a key update. The system accumulates switching events and only performs key management when the threshold is exceeded, allowing the system to prepare and execute key updates less frequently while still maintaining security.
2Reliability
If key updates are performed for all users when one user leaves or joins a service group, then security is maintained, but service quality deteriorates due to interruptions
Solution Approach 1:
The patent segments the user base by introducing the concept of service switching groups that are separate from service groups. This allows key management to be performed on a segmented basis - only affecting users in the switching group rather than all users in the service group - thereby maintaining security while minimizing service interruptions for the majority of users.
Solution Approach 2:
The patent introduces service switching groups as an intermediary layer between individual users and service groups. This intermediary structure allows the system to manage key updates more efficiently by containing the impact to only those users actively switching services, rather than forcing all service group members to undergo key management operations.
3Reliability
If re-keying is performed frequently to maintain security, then security is improved, but signaling overhead and network traffic increase
Solution Approach 1:
The patent implements periodic action through the threshold-based mechanism that monitors service switching over time. Instead of continuous or event-driven key updates, the system periodically evaluates whether the accumulated switching activity warrants a key update, reducing signaling overhead while maintaining security through time-based monitoring.
4Device complexity
If all services are encrypted with the same key for simplicity, then device complexity is reduced, but access control flexibility is lost
Solution Approach 1:
The patent applies universality by creating service switching groups that can serve multiple functions: they enable fine-grained access control for users switching between services, reduce key management overhead, and maintain compatibility with existing service group structures. This multi-functional approach simplifies the overall system while providing flexible access control.
Data Source
AI summary
A method of key management in a communication network that includes a plurality of groups with each group including one or several members authorized to have access to key-protected services is provided by an apparatus. The method includes determining when a member starts a switching action from one service to another. A time dependent quantity starting from the switching action is determined. The method includes determining that the member is a member of a switching group when the quantity is less than a threshold value is made, and when the quantity is larger than the threshold, determining that the member has decided to join a new group, and changing the appropriate access key(s).


