Key Management Infrastructure for Secure Mobile Radio Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for secure and efficient methods to provide cryptographic keys to mobile radios, as existing encryption methods are vulnerable to interception due to the potential exposure of cryptographic keys to unauthorized parties.

Innovation Solution

A key-management infrastructure (KMI) is implemented to securely provide disassembly products of a high-security cryptographic key (HS-K) to mobile radios, using a combination of local connections and air interfaces, with encryption and decryption processes managed through medium-security cryptographic keys, ensuring only authorized devices can reassemble and use the key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic keys are transmitted over air interface to mobile radios, then key distribution is enabled, but security is compromised due to potential interception

Engineering Contradiction:
Improvekey distribution capabilityVSAvoidinterception vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The high-security cryptographic key is divided into multiple disassembly products that cannot individually reconstruct the original key. Each disassembly product is distributed through different channels (local connection and air interface), making interception of a single channel insufficient for key recovery.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A key-management infrastructure acts as an intermediary between the key generation authority and mobile radios. This infrastructure securely manages the disassembly products and controls their distribution, adding a layer of security management and authorization verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic keys are stored in mobile radios, then encryption capability is enabled, but exposure to unauthorized parties increases

Engineering Contradiction:
Improveencryption capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The cryptographic key is segmented into multiple disassembly products stored in the mobile radio. None of these products alone can decrypt encrypted communications, reducing the impact of potential compromise of individual stored elements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different disassembly products have different security requirements and are handled differently within the system. The first disassembly product is provided through a restricted-access local connection with higher security controls, while the second is provided over the air interface with appropriate encryption, matching the security level to the distribution channel.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If high-security keys are distributed to multiple mobile radios, then communication coverage is improved, but security management complexity increases

Engineering Contradiction:
Improvecommunication coverageVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The key-management infrastructure serves as a centralized intermediary that automates the distribution and management of disassembly products to multiple mobile radios. This centralized control simplifies the overall system by providing a single point of management rather than requiring complex peer-to-peer key management between multiple radios.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cryptographic key is disassembled into multiple products in advance before distribution to mobile radios. This preliminary processing at the key-generation stage simplifies subsequent distribution operations, as the disassembly products can be independently managed and distributed without requiring complex coordination during operational deployment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9288043B1Methods and systems for providing high-security cryptographic keys to mobile radios
Publication Date: 2016.03.15 MOTOROLA SOLUTIONS INC
  • US9288043B1 patent drawing
  • US9288043B1 patent drawing
  • US9288043B1 patent drawing

AI summary

At least one embodiment takes the form of a process carried out by a key-management infrastructure (KMI). The KMI receives first and second disassembly products of a high-security cryptographic key and provides the first and second disassembly products to a mobile radio for reassembly of the high-security cryptographic key. Providing the first disassembly product to the mobile radio includes providing the first disassembly product to the mobile radio over a local connection via a restricted-access key variable loader. Providing the second disassembly product to the mobile radio includes (i) generating a medium-security-encrypted second disassembly product at least in part by encrypting the second disassembly product based on at least one medium-security cryptographic key, and (ii) providing the medium-security-encrypted second disassembly product to the mobile radio over an air interface.