Key Management Center Token Distribution for End-to-End Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In existing mobile communications security architectures, the decryption of communication data on intermediate devices increases the risk of data theft, necessitating a secure key configuration method for end-to-end communication between network elements.

Innovation Solution

A key configuration method involving a key management center that obtains and generates service keys and tokens for network elements, enabling secure encryption and integrity protection of data transmitted between them, ensuring secure key distribution and laying the foundation for end-to-end security communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is decrypted on intermediate devices for forwarding, then data can be transmitted through the network, but the risk of data theft increases

Engineering Contradiction:
Improvedata transmission capabilityVSAvoiddata theft risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the decryption function from intermediate network devices and relocates it to end devices. Intermediate devices only perform encryption forwarding without decryption capabilities, eliminating the security vulnerability while maintaining network transmission functionality

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an encryption forwarding mechanism where intermediate devices act as mediators that forward encrypted data without accessing plaintext. This intermediary approach allows data transmission while preventing data theft at intermediate nodes

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If end-to-end security communication is implemented, then data security is improved, but key configuration complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidkey configuration complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements self-service key configuration where end devices automatically obtain and manage their own encryption keys through standardized protocols. This eliminates the need for manual key distribution and reduces configuration complexity while maintaining strong security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a universal key management mechanism that can serve multiple functions: key generation, key distribution, key update, and key revocation. This multi-functional approach simplifies the overall system architecture while providing comprehensive security support

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10903987B2Key configuration method, key management center, and network element
Publication Date: 2021.01.26 HUAWEI TECH CO LTD
  • US10903987B2 patent drawing
  • US10903987B2 patent drawing
  • US10903987B2 patent drawing

AI summary

This application provides a key configuration method and an apparatus. A key management center obtains a service key, and performs encryption and/or integrity protection on the service key to obtain a token. The key management center sends the token to a first network element, the first network element forwards the token to a second network element, and the second network element obtains the service key based on the token. The service key is used to perform encryption and/or integrity protection on data transmitted between the first network element and the second network element. Therefore, security key configuration can be implemented through interaction between the key management center and the network elements, thereby laying a foundation for end-to-end security communication between the first network element and the second network element.