Key Management Infrastructure for Secure Mobile Radio Key Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for secure and efficient methods to provide cryptographic keys to mobile radios, as existing encryption methods are vulnerable to interception due to the potential exposure of cryptographic keys to unauthorized parties.
Innovation Solution
A key-management infrastructure (KMI) is implemented to securely provide disassembly products of a high-security cryptographic key (HS-K) to mobile radios, using a combination of local connections and air interfaces, with encryption and decryption processes managed through medium-security cryptographic keys, ensuring only authorized devices can reassemble and use the key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cryptographic keys are transmitted over air interface to mobile radios, then key distribution is enabled, but security is compromised due to potential interception
Solution Approach 1:
The high-security cryptographic key is divided into multiple disassembly products that cannot individually reconstruct the original key. Each disassembly product is distributed through different channels (local connection and air interface), making interception of a single channel insufficient for key recovery.
Solution Approach 2:
A key-management infrastructure acts as an intermediary between the key generation authority and mobile radios. This infrastructure securely manages the disassembly products and controls their distribution, adding a layer of security management and authorization verification.
2Reliability
If cryptographic keys are stored in mobile radios, then encryption capability is enabled, but exposure to unauthorized parties increases
Solution Approach 1:
The cryptographic key is segmented into multiple disassembly products stored in the mobile radio. None of these products alone can decrypt encrypted communications, reducing the impact of potential compromise of individual stored elements.
Solution Approach 2:
Different disassembly products have different security requirements and are handled differently within the system. The first disassembly product is provided through a restricted-access local connection with higher security controls, while the second is provided over the air interface with appropriate encryption, matching the security level to the distribution channel.
3Adaptability or versatility
If high-security keys are distributed to multiple mobile radios, then communication coverage is improved, but security management complexity increases
Solution Approach 1:
The key-management infrastructure serves as a centralized intermediary that automates the distribution and management of disassembly products to multiple mobile radios. This centralized control simplifies the overall system by providing a single point of management rather than requiring complex peer-to-peer key management between multiple radios.
Solution Approach 2:
The cryptographic key is disassembled into multiple products in advance before distribution to mobile radios. This preliminary processing at the key-generation stage simplifies subsequent distribution operations, as the disassembly products can be independently managed and distributed without requiring complex coordination during operational deployment.
Data Source
AI summary
At least one embodiment takes the form of a process carried out by a key-management infrastructure (KMI). The KMI receives first and second disassembly products of a high-security cryptographic key and provides the first and second disassembly products to a mobile radio for reassembly of the high-security cryptographic key. Providing the first disassembly product to the mobile radio includes providing the first disassembly product to the mobile radio over a local connection via a restricted-access key variable loader. Providing the second disassembly product to the mobile radio includes (i) generating a medium-security-encrypted second disassembly product at least in part by encrypting the second disassembly product based on at least one medium-security cryptographic key, and (ii) providing the medium-security-encrypted second disassembly product to the mobile radio over an air interface.


