Key Management Facility Multi-Device Key Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing LMR key management architectures face difficulties in managing and distributing security keys across multiple interworking clients in LTE systems, requiring a more efficient method to maintain key management states and update keys seamlessly.

Innovation Solution

A Key Management Facility (KMF) that utilizes a single common identifier, such as the twenty most significant bits of the Source RSI, to manage keys for multiple mobile devices, enabling seamless key management and updates using the Over-The-Air Rekeying (OTAR) standard without modifying existing procedures, and supports up to sixteen unique interworking devices for a single user.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the existing LMR KMF key management architecture is used, then key management for single devices is maintained, but managing and distributing security keys across multiple interworking clients in LTE systems becomes extremely difficult

Engineering Contradiction:
Improvekey management capabilityVSAvoidkey management architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the key management approach by introducing a specific field (e.g., twenty most significant bits of Source RSI) that can uniquely identify multiple devices while maintaining compatibility with existing single-device key management protocols. This segmentation allows the system to handle multiple devices through structured identification rather than requiring complete architectural redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes the key management system universal by designing it to handle both single-device and multi-device scenarios using the same underlying protocol structure. The common identifier field serves multiple functions: it works for single device identification, multi device grouping, and maintains backward compatibility with existing LMR systems, thereby achieving multi-functionality without increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple interworking clients are provisioned with the same set of keys, then encrypted communication is enabled, but maintaining the same key management state across each client becomes extremely difficult

Engineering Contradiction:
Improveencrypted communicationVSAvoidkey management state maintenance
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies copying by provisioning the same key material to multiple clients while using a common identifier to link them. The key management state is copied across clients but associated with a shared identifier, allowing automatic state synchronization without complex manual management. This copying approach enables reliable encrypted communication while simplifying state maintenance through automated processes.

Inventive Principle:
Principle #26Copying

3Ease of manufacture

If the Over-The-Air Rekeying (OTAR) standard is used without modifications, then existing procedures are maintained, but managing keys for multiple devices represented by a single common identifier is not supported

Engineering Contradiction:
Improveprocedure compatibilityVSAvoidmulti-device key management
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamics by making the identifier field configurable and extensible within the existing OTAR framework. The system dynamically adapts to handle both single-device and multi-device scenarios by interpreting the common identifier field differently based on context, allowing the same standard procedures to serve multiple purposes without modification while gaining multi-device capability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11218872B2Method and key management facility for managing keys of a single user having a plurality of mobile devices
Publication Date: 2022.01.04 MOTOROLA SOLUTIONS INC
  • US11218872B2 patent drawing
  • US11218872B2 patent drawing
  • US11218872B2 patent drawing

AI summary

A method and Key Management Facility (KMF) for managing keys of a single user having a plurality of devices is provided. The KMF receives an Over-The-Air Rekeying (OTAR) message relating to a first device and including an interworking bit. If the interworking bit is set, the KMF retrieves a main source RSI and a Sub-RSI field from the OTAR message. If the main source RSI matches other main source RSIs from other devices, the KMF manages keys for all devices that have the same main source RSI in an identical manner.