Portable Key Variable Loader for Secure Group Reprovisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication systems face inefficiencies in distributing encryption keys to numerous widely-deployed devices, especially in scenarios where devices are remote or numerous, requiring impractical transportation and cumbersome manual rekeying processes.

Innovation Solution

A key variable loader system that automatically populates and manages secure communication group members by physically connecting to devices, uploading encryption algorithms and keys, and enabling wireless rekeying, allowing for efficient key distribution and management without the need for a central key management facility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are transported to the KVL location for reprovisioning, then key distribution security is maintained, but operational efficiency and time consumption deteriorate significantly

Engineering Contradiction:
Improvekey distribution securityVSAvoidreprovisioning efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

A portable key distribution device is introduced as an intermediary between the centralized key management system and field devices. This portable device can be physically connected to individual devices or groups of devices to distribute encryption keys, eliminating the need to transport devices to a fixed location while maintaining secure key distribution through controlled physical connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transitions from a centralized fixed-location key management approach to a portable mobile approach, adding the dimension of mobility. The key distribution function is no longer confined to a single stationary location but can be deployed wherever devices need reprovisioning, fundamentally changing the spatial dimension of key management operations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If individual physical connection is used for each device, then key distribution security is ensured, but time consumption and operational complexity increase

Engineering Contradiction:
Improveencryption key securityVSAvoidreprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The portable key distribution device enables multiple devices to be connected and reprovisioned simultaneously through a single physical connection point. Instead of connecting to each device individually in sequence, the system merges multiple device connections into one operational process, dramatically reducing the total time required for reprovisioning large numbers of devices while maintaining secure key distribution.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If a centralized key management facility is used, then key management control is improved, but device deployment flexibility and accessibility deteriorate

Engineering Contradiction:
Improvekey management controlVSAvoiddeployment flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The portable key distribution device serves multiple functions: it can be used for initial device provisioning, periodic key updates, emergency key rotation, and field deployments. This multi-functional device replaces the need for specialized fixed infrastructure, enabling the same device to adapt to various key management scenarios and deployment environments while maintaining centralized control capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2329663B1Method and system for automatically populating a list of managed secure communications group members
Publication Date: 2018.07.04 MOTOROLA SOLUTIONS INC
  • EP2329663B1 patent drawingFigure 1
  • EP2329663B1 patent drawingFigure 2
  • EP2329663B1 patent drawingFigure 3

AI summary

Methods of automatically populating a secure group list in a key variable loader and of providing keys to a secure group are presented. After a user selects a secure group and encryption algorithm using inputs of the loader, the loader provides a group identifier and corresponding key for the group. The group identifier, encryption algorithm, and key are transmitted to a portable communication device over a physical connection between the two while a device identifier of the communication device is transmitted concurrently to the loader. The key variable loader automatically populates a stored list of subscribers of the group with the device identifier. When it is desired to transmit a new key to all of or fewer than all of the subscribers, one of the subscribers is connected with the loader and used to wirelessly transmit a new key to the remaining subscribers.