Communication Device Multi-KMF Key Management via Segmented Crypto Groups
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication systems for public safety organizations often rely on a single key management facility (KMF) for key management operations, which may limit flexibility and interoperability, particularly in scenarios where multiple KMFs are beneficial for efficient and secure communication.
Innovation Solution
A communication device is configured to operate with multiple key management facilities by designating a primary and secondary KMF, storing sets of crypto groups associated with each KMF, and executing key management commands accordingly, allowing for secure and flexible key management across multiple KMFs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a communication device operates with a single key management facility, then the system complexity is reduced and ease of operation is improved, but the adaptability and flexibility are limited
Solution Approach 1:
The patent segments the key management structure by creating separate key maps for different KMFs (primary KMF key map and secondary KMF key map). Each key map independently stores crypto groups associated with a specific KMF, allowing the communication device to manage keys from multiple KMFs without mixing them together, thus reducing overall complexity while enabling multi-KMF operation
Solution Approach 2:
The patent introduces a key map as an intermediary data structure that sits between the communication device and multiple KMFs. This key map stores associations between crypto groups and KMF identifiers, mediating the relationship between the device and multiple key management facilities, thereby enabling the device to interact with multiple KMFs without direct complex coordination
2Ease of operation
If a communication device operates with a single key management facility, then the ease of operation is improved, but the interoperability and flexibility in key management are reduced
Solution Approach 1:
The patent implements a universal key management approach where the communication device is configured to recognize and process key management commands from multiple KMFs (primary and secondary). The key map structure universally handles associations between any KMF identifier and its corresponding crypto groups, enabling the device to operate with different KMF configurations without requiring different operational procedures
3Adaptability or versatility
If a communication device is configured to act on key management commands from multiple KMFs, then the adaptability is improved, but the device complexity increases
Solution Approach 1:
The patent segments command handling by establishing clear rules: the device primarily acts on key management commands from the primary KMF, while maintaining the capability to receive and process commands from secondary KMFs. This segmentation of command authority simplifies the decision logic compared to treating all KMFs equally, reducing operational complexity while maintaining multi-KMF adaptability
Data Source
AI summary
A method for operating with KMFs includes a communication device having a memory device: receiving a designation of a primary KMF for the communication device, wherein only one primary KMF is designated for the communication device at any given time instance; receiving a designation of a secondary KMF for the communication device; storing, within the memory device, a first and a second set of crypto groups, wherein each crypto group within each set of crypto groups comprises at least one keyset, wherein each set of crypto groups is associated, within the memory device, to only one KMF identifier; associating, within the memory device, the first set of crypto groups to an identifier for the primary KMF; and associating, within the memory device, the second set of crypto groups to an identifier for the secondary KMF.


