M2M Encryption Key Allocation for Isolated Communication Pairs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In M2M communication systems, distributing the same encryption key to all applications and terminals leads to security breaches due to lack of isolation between applications, while distributing different keys increases the processing load on the service platform, which is unsustainable for devices with limited capabilities.

Innovation Solution

Allocate a unique encryption key for each application-terminal pair, ensuring exclusive communication and eliminating the need for decryption or re-encryption processing between them, thereby reducing the processing load on both the service platform and terminals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the same communication encryption key is distributed to all M2M applications and M2M terminals, then the processing load of the M2M service platform is reduced, but the security of communication data cannot be guaranteed due to lack of isolation between applications

Engineering Contradiction:
Improveprocessing load of M2M service platformVSAvoidsecurity of communication data
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the encryption key management by creating exclusive binding relationships between terminals and applications. Each terminal is bound to only one application, and each application is bound to only one terminal, forming isolated communication pairs. This segmentation allows the system to use the same encryption key across multiple isolated pairs without compromising security, as keys are not shared between different application-terminal pairs.

Inventive Principle:
Principle #1Segmentation

2Reliability

If different communication encryption keys are distributed to all M2M applications and M2M terminals respectively, then the security of communication data is improved, but the processing load of the M2M service platform increases significantly

Engineering Contradiction:
Improvesecurity of communication dataVSAvoidprocessing load of M2M service platform
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the key management approach by using a single encryption key for multiple isolated communication pairs. Instead of distributing different keys to each application-terminal pair, the system allows the same key to be used across all exclusively bound pairs, eliminating the need for key distribution and management overhead while maintaining security through isolation.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If the M2M service platform distributes different communication encryption keys to M2M applications and M2M terminals, then data security is enhanced, but the processing capability requirements for the service platform become higher

Engineering Contradiction:
Improvedata securityVSAvoidprocessing capability requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by establishing exclusive binding relationships that isolate communication channels. This segmentation allows simplified key management where the same encryption key can be used across multiple isolated pairs, reducing the processing capability requirements for the service platform while maintaining data security through the isolation mechanism.

Inventive Principle:
Principle #1Segmentation

4Reliability

If M2M terminals perform encryption-transmission and reception-decryption with different communication encryption keys for multiple applications, then communication security is maintained, but the power consumption and processing load of terminals increase

Engineering Contradiction:
Improvecommunication securityVSAvoidpower consumption of terminals
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent merges the encryption key usage for terminals bound to a single application. Since each terminal is exclusively bound to one application, the terminal can use the same encryption key for both sending encrypted messages to and receiving decrypted messages from its bound application, eliminating the need for multiple different keys and reducing power consumption.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2536189B1Encryption communication method, apparatus and system
Publication Date: 2016.11.16 HUAWEI TECH CO LTD
  • EP2536189B1 patent drawingFigure 1~2
  • EP2536189B1 patent drawingFigure 3~4
  • EP2536189B1 patent drawingFigure 5

AI summary

Embodiments of the present invention provide an encrypted communication method, apparatus and system, relating to the communication technologies. In order to reduce, on the premise that the data security can be guaranteed, the processing load of devices in a M2M system, the embodiments of the present invention provide the following technical solution: allocating a same encryption key for a first application and a terminal which is only bound with the first application;, transparently transmitting the information interacted between the terminal and the first application when determining that the terminal communicates with the first application by using the same encryption key. The present invention is applicable for encrypted transmission.