Local Security Key Generation via Parameter Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network communication technologies face security risks and operational complexity due to the need for third-party key management systems to assign security keys to user devices, which can compromise network security.

Innovation Solution

Devices are enabled to locally generate security keys by exchanging and processing security parameters through key generation functions, allowing them to encrypt and decrypt communication sessions without relying on external key management systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If third-party key management systems are used to assign security keys, then key distribution can be centralized and managed, but network security is compromised and operational complexity increases

Engineering Contradiction:
Improvekey distribution managementVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements self-service by enabling user devices to autonomously generate their own security keys using local key generation functions and exchanged security parameters, eliminating the need for third-party key management systems to assign keys. This self-generated approach both simplifies operations (no centralized management needed) and enhances security (keys never leave the device), simultaneously resolving both aspects of the contradiction.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the key generation function from the third-party key management system and relocates it to the user devices themselves. By taking out the key assignment function from the centralized system and embedding it in each device, the patent eliminates the security risks and operational complexity associated with centralized key management while maintaining secure key distribution.

Inventive Principle:
Principle #2Taking out (Extraction)

2Extent of automation

If third-party key management systems are used to assign security keys, then key assignment can be automated, but device complexity and operational complexity increase

Engineering Contradiction:
Improvekey assignment automationVSAvoidkey management system complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent enables devices to automatically generate their own security keys through built-in key generation functions that process exchanged security parameters. This self-service approach maintains full automation of key assignment while eliminating the need for complex third-party key management infrastructure, as each device independently performs the key generation task.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces security parameters as an intermediary mechanism that enables automated key generation without requiring complex key management systems. Instead of directly managing keys, the system uses exchanged security parameters as mediators that each device processes locally to generate its own keys, simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10142305B2Local security key generation
Publication Date: 2018.11.27 VERIZON PATENT & LICENSING INC
  • US10142305B2 patent drawing
  • US10142305B2 patent drawing
  • US10142305B2 patent drawing

AI summary

A calling device may obtain a first calling security parameter by registering with a network and obtain a second calling security parameter in response to causing an application authentication architecture of the network to verify that that the calling device is authorized to access a network service corresponding to a communication application stored by the calling device. The calling device may communicate the first and second calling security parameters to a called device and receive first and second called security parameters from the called device in response to communicating the first and second calling security parameters. The calling device may generate a security key based on the first calling security parameter, the second calling security parameter, first called security parameter, and the second called security parameter, and use the security key to encrypt or decrypt communication between the calling device and the called device.