Key Manufacturing Server for Secure Device Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key management protocols lack standardized solutions for secure key generation, storage, and access control, particularly for multi-party key management, leading to vulnerabilities such as default passwords, weak key reuse, and inflexible storage across different operating systems and hardware.

Innovation Solution

A key management system utilizing a key manufacturing server that generates and manages key packages with meta-information, enabling secure key generation, storage, and access control through a communication link between the server and key managers, supporting multiple devices and operating systems with flexible access controls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing key management protocols are used, then key generation and storage can be implemented, but security vulnerabilities arise due to lack of standardized access control and flexible storage solutions

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The key management system is segmented into multiple components: key generation module, key storage module with multiple storage locations, key access control module, and key distribution module. This segmentation allows each component to be optimized independently for security while maintaining overall system flexibility through standardized interfaces.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The key storage mechanism is made dynamic by allowing keys to be stored in multiple locations (secure element, external storage, cloud-based vault) and enabling dynamic access control policies that can be adjusted based on device type, operating system, and security requirements. This dynamic approach resolves the contradiction between security and flexibility.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multiple cryptographic keys are used for enhanced security, then security is improved, but key management complexity increases making it hard to manage

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A centralized key management server acts as an intermediary between multiple cryptographic keys and the devices that need them. This intermediary automatically handles key generation, distribution, storage, and access control for multiple keys, reducing management complexity while maintaining enhanced security through proper key isolation and access policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Multiple key management functions (generation, storage, distribution, access control, rotation) are merged into a single integrated key management system. This consolidation simplifies management by providing a unified interface and automated workflows, while internal security mechanisms maintain the security benefits of using multiple cryptographic keys.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If key storage is implemented without standardized protocols, then implementation flexibility is maintained, but security vulnerabilities arise from undefined storage mechanisms

Engineering Contradiction:
Improveimplementation flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The key management system implements universal standardized protocols for key storage that work across multiple device types and operating systems. The standardized interfaces maintain implementation flexibility while incorporating proven security mechanisms. The system can adapt to different hardware platforms through standardized abstraction layers that enforce security best practices regardless of the underlying storage mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Device complexity

If rigid key transport protocols are used, then protocol simplicity is maintained, but adaptability to different operating systems and hardware is reduced

Engineering Contradiction:
Improveprotocol simplicityVSAvoidadaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The key transport protocol is designed to be dynamic and adaptive, automatically selecting appropriate transport mechanisms based on the target device type, operating system, and security requirements. The protocol maintains simplicity through standardized high-level interfaces while incorporating flexibility to adapt to different platforms, resolving the contradiction between protocol simplicity and adaptability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10819688B2System and method for generating and managing a key package
Publication Date: 2020.10.27 TALA SECURE INC
  • US10819688B2 patent drawing
  • US10819688B2 patent drawing
  • US10819688B2 patent drawing

AI summary

In view of the foregoing, an embodiment herein provides a method of generating and managing a key package using a key manufacturing server. The key manufacturing server performs the steps of: (i) obtaining a key package from a development signing server; (ii) generating at least one production key that is specific to a device in the key package; (iii) communicating the key package with the at least one production key to a key manager associated with the device using a communication link; and (iv) obtaining the key package with at least one device key that is generated by the key manager.