Local Security Key Generation via Parameter Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network communication technologies face security risks and operational complexity due to the need for third-party key management systems to assign security keys to user devices, which can compromise network security.
Innovation Solution
Devices are enabled to locally generate security keys by exchanging and processing security parameters through key generation functions, allowing them to encrypt and decrypt communication sessions without relying on external key management systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If third-party key management systems are used to assign security keys, then key distribution can be centralized and managed, but network security is compromised and operational complexity increases
Solution Approach 1:
The patent implements self-service by enabling user devices to autonomously generate their own security keys using local key generation functions and exchanged security parameters, eliminating the need for third-party key management systems to assign keys. This self-generated approach both simplifies operations (no centralized management needed) and enhances security (keys never leave the device), simultaneously resolving both aspects of the contradiction.
Solution Approach 2:
The patent extracts the key generation function from the third-party key management system and relocates it to the user devices themselves. By taking out the key assignment function from the centralized system and embedding it in each device, the patent eliminates the security risks and operational complexity associated with centralized key management while maintaining secure key distribution.
2Extent of automation
If third-party key management systems are used to assign security keys, then key assignment can be automated, but device complexity and operational complexity increase
Solution Approach 1:
The patent enables devices to automatically generate their own security keys through built-in key generation functions that process exchanged security parameters. This self-service approach maintains full automation of key assignment while eliminating the need for complex third-party key management infrastructure, as each device independently performs the key generation task.
Solution Approach 2:
The patent introduces security parameters as an intermediary mechanism that enables automated key generation without requiring complex key management systems. Instead of directly managing keys, the system uses exchanged security parameters as mediators that each device processes locally to generate its own keys, simplifying the overall system architecture.
Data Source
AI summary
A calling device may obtain a first calling security parameter by registering with a network and obtain a second calling security parameter in response to causing an application authentication architecture of the network to verify that that the calling device is authorized to access a network service corresponding to a communication application stored by the calling device. The calling device may communicate the first and second calling security parameters to a called device and receive first and second called security parameters from the called device in response to communicating the first and second calling security parameters. The calling device may generate a security key based on the first calling security parameter, the second calling security parameter, first called security parameter, and the second called security parameter, and use the security key to encrypt or decrypt communication between the calling device and the called device.


