Management Device Group Key Distribution via Binary Tree

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing group key distribution systems face availability issues due to the need to update device keys for all communication devices before distributing the group key, leading to system unavailability during key updates.

Innovation Solution

A management device employs a binary tree structure to selectively distribute the group key by encrypting it using node keys, allowing distribution before all device keys are updated, using subtrees with updated and unupdated node keys, enabling secure and timely group key dissemination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device keys are updated for all communication devices before distributing the group key, then system security is maintained, but system availability declines during the key update process

Engineering Contradiction:
Improvesystem securityVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the device key update process into two distinct phases: first, updating device keys for a subset of communication devices; second, distributing the group key to devices with updated keys. This segmentation allows the system to maintain partial functionality during key updates by serving only the subset of devices that have completed their key updates, rather than requiring all devices to be updated before any group key distribution can occur.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by updating device keys for a subset of communication devices before distributing the group key. This allows the system to prepare some devices with new security credentials in advance, enabling selective group key distribution to those devices without waiting for all devices to complete their key updates, thus maintaining system availability during the transition period.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If device keys are updated using authenticated key exchange protocol for each communication device, then key security is ensured, but the time required for complete key update increases significantly

Engineering Contradiction:
Improvekey securityVSAvoidkey update speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by updating device keys for only a subset of communication devices rather than all devices before group key distribution. This partial approach reduces the total time required for key updates while maintaining security for the devices that are updated, as the system can distribute group keys to the updated subset immediately without waiting for all devices to complete their key exchange protocols.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If group key distribution waits until all device keys are updated, then security integrity is maintained, but system response time increases

Engineering Contradiction:
Improvesecurity integrityVSAvoidsystem response time
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments the device key update process into two distinct phases: first, updating device keys for a subset of communication devices; second, distributing the group key to devices with updated keys. This segmentation allows the system to maintain partial functionality during key updates by serving only the subset of devices that have completed their key updates, rather than requiring all devices to be updated before any group key distribution can occur.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by updating device keys for a subset of communication devices before distributing the group key. This allows the system to prepare some devices with new security credentials in advance, enabling selective group key distribution to those devices without waiting for all devices to complete their key updates, thus maintaining system availability during the transition period.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10581598B2Management device and management method
Publication Date: 2020.03.03 KK TOSHIBA
  • US10581598B2 patent drawing
  • US10581598B2 patent drawing
  • US10581598B2 patent drawing

AI summary

According to one embodiment, a management device includes a management tree storage and one or more processors. The management tree storage stores therein a binary tree including a plurality of nodes that are assigned with respective node keys. The processors update at least one of the node keys. The processors selects at least one of a first subtree and a second subtree, the first subtree and the second subtree being subtrees including leaf nodes of the binary tree, the leaf nodes corresponding to respective communication devices included in a group, the first subtree including only leaf nodes with the respective node keys assigned thereto not having been updated, the second subtree including only leaf nodes with the respective node keys assigned thereto having been updated. The processors transmit a group key encrypted using a node key assigned to a root node of the selected subtree.