M2M Encryption Key Allocation for Isolated Communication Pairs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In M2M communication systems, distributing the same encryption key to all applications and terminals leads to security breaches due to lack of isolation between applications, while distributing different keys increases the processing load on the service platform, which is unsustainable for devices with limited capabilities.
Innovation Solution
Allocate a unique encryption key for each application-terminal pair, ensuring exclusive communication and eliminating the need for decryption or re-encryption processing between them, thereby reducing the processing load on both the service platform and terminals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the same communication encryption key is distributed to all M2M applications and M2M terminals, then the processing load of the M2M service platform is reduced, but the security of communication data cannot be guaranteed due to lack of isolation between applications
Solution Approach 1:
The patent segments the encryption key management by creating exclusive binding relationships between terminals and applications. Each terminal is bound to only one application, and each application is bound to only one terminal, forming isolated communication pairs. This segmentation allows the system to use the same encryption key across multiple isolated pairs without compromising security, as keys are not shared between different application-terminal pairs.
2Reliability
If different communication encryption keys are distributed to all M2M applications and M2M terminals respectively, then the security of communication data is improved, but the processing load of the M2M service platform increases significantly
Solution Approach 1:
The patent merges the key management approach by using a single encryption key for multiple isolated communication pairs. Instead of distributing different keys to each application-terminal pair, the system allows the same key to be used across all exclusively bound pairs, eliminating the need for key distribution and management overhead while maintaining security through isolation.
3Reliability
If the M2M service platform distributes different communication encryption keys to M2M applications and M2M terminals, then data security is enhanced, but the processing capability requirements for the service platform become higher
Solution Approach 1:
The patent applies segmentation by establishing exclusive binding relationships that isolate communication channels. This segmentation allows simplified key management where the same encryption key can be used across multiple isolated pairs, reducing the processing capability requirements for the service platform while maintaining data security through the isolation mechanism.
4Reliability
If M2M terminals perform encryption-transmission and reception-decryption with different communication encryption keys for multiple applications, then communication security is maintained, but the power consumption and processing load of terminals increase
Solution Approach 1:
The patent merges the encryption key usage for terminals bound to a single application. Since each terminal is exclusively bound to one application, the terminal can use the same encryption key for both sending encrypted messages to and receiving decrypted messages from its bound application, eliminating the need for multiple different keys and reducing power consumption.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
Embodiments of the present invention provide an encrypted communication method, apparatus and system, relating to the communication technologies. In order to reduce, on the premise that the data security can be guaranteed, the processing load of devices in a M2M system, the embodiments of the present invention provide the following technical solution: allocating a same encryption key for a first application and a terminal which is only bound with the first application;, transparently transmitting the information interacted between the terminal and the first application when determining that the terminal communicates with the first application by using the same encryption key. The present invention is applicable for encrypted transmission.