Key Sharing System Terminal-Specific Encryption Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional key sharing systems face excessive information management loads on management devices and require updates across all terminals when a terminal leaves a key sharing group, leading to inefficiencies in invalidating key information.

Innovation Solution

A key sharing system where communication terminals generate and manage terminal-specific information, allowing for encryption and transmission of group shared keys, enabling the management device to store and update encrypted key information efficiently without requiring updates across all terminals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the management device stores encrypted key information for all user terminals, then key sharing functionality is achieved, but information management load becomes excessive

Engineering Contradiction:
Improvekey sharing functionalityVSAvoidinformation management load
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the key management system into multiple components: user terminals store their own key information locally, while the management device stores only group key information. This segmentation reduces the information management load on the management device while maintaining key sharing functionality across the system.

Inventive Principle:
Principle #1Segmentation

2Reliability

If key information is distributed and stored by means of (k, n) threshold secret sharing scheme, then secure storage is achieved, but update load becomes excessive when a terminal departs

Engineering Contradiction:
Improvesecure storageVSAvoidupdate efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the update operation from the management device and relocates it to the user terminals. When a terminal departs, the remaining terminals independently update their own key information without requiring the management device to redistribute updated keys to all terminals, thereby eliminating the excessive update load.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

User terminals are empowered to perform self-updates of their key information when group members depart. Each terminal autonomously recalculates and updates its stored key information based on current group composition, without requiring centralized management device intervention for each update operation.

Inventive Principle:
Principle #25Self-service

3Reliability

If all terminals need to be updated when a terminal departs, then key security is maintained, but time consumption increases

Engineering Contradiction:
Improvekey securityVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Instead of updating all terminals in the group when a member departs, the patent applies partial action by having only the remaining terminals perform local updates. This reduces the time consumption from a group-wide operation to individual terminal operations, while still maintaining key security through the updated key information.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8886931B2Key sharing system, communication terminal, management device, key sharing method, and computer program
Publication Date: 2014.11.11 KDDI CORP
  • US8886931B2 patent drawing
  • US8886931B2 patent drawing
  • US8886931B2 patent drawing

AI summary

In a case where another user's communication terminal (nTE113) departs from a group, user's communication terminal (TEb14) updates encryption information, using the terminal individual information of only the communication terminals (nTE213 and nTE313) which remain in the group (PNy). User's communication terminal (TEb14) encrypts the PN-shared key (KPNy), using the updated encryption information. User's communication terminal (TEb14) transmits the encrypted shared key information obtained from this encryption to a management device (PNSP11), and updates the encrypted shared key information stored in the management device (PNSP11).