Communication Device Multi-KMF Key Management via Segmented Crypto Groups

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems for public safety organizations often rely on a single key management facility (KMF) for key management operations, which may limit flexibility and interoperability, particularly in scenarios where multiple KMFs are beneficial for efficient and secure communication.

Innovation Solution

A communication device is configured to operate with multiple key management facilities by designating a primary and secondary KMF, storing sets of crypto groups associated with each KMF, and executing key management commands accordingly, allowing for secure and flexible key management across multiple KMFs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a communication device operates with a single key management facility, then the system complexity is reduced and ease of operation is improved, but the adaptability and flexibility are limited

Engineering Contradiction:
Improveability to operate with multiple KMFsVSAvoidkey management structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the key management structure by creating separate key maps for different KMFs (primary KMF key map and secondary KMF key map). Each key map independently stores crypto groups associated with a specific KMF, allowing the communication device to manage keys from multiple KMFs without mixing them together, thus reducing overall complexity while enabling multi-KMF operation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key map as an intermediary data structure that sits between the communication device and multiple KMFs. This key map stores associations between crypto groups and KMF identifiers, mediating the relationship between the device and multiple key management facilities, thereby enabling the device to interact with multiple KMFs without direct complex coordination

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a communication device operates with a single key management facility, then the ease of operation is improved, but the interoperability and flexibility in key management are reduced

Engineering Contradiction:
Improvekey management operation simplicityVSAvoidinteroperability with multiple KMFs
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal key management approach where the communication device is configured to recognize and process key management commands from multiple KMFs (primary and secondary). The key map structure universally handles associations between any KMF identifier and its corresponding crypto groups, enabling the device to operate with different KMF configurations without requiring different operational procedures

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If a communication device is configured to act on key management commands from multiple KMFs, then the adaptability is improved, but the device complexity increases

Engineering Contradiction:
Improvemulti-KMF command processing capabilityVSAvoidkey map structure and command handling complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments command handling by establishing clear rules: the device primarily acts on key management commands from the primary KMF, while maintaining the capability to receive and process commands from secondary KMFs. This segmentation of command authority simplifies the decision logic compared to treating all KMFs equally, reducing operational complexity while maintaining multi-KMF adaptability

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8948396B2Method for a communication device to operate with multiple key management facilities
Publication Date: 2015.02.03 MOTOROLA SOLUTIONS INC
  • US8948396B2 patent drawing
  • US8948396B2 patent drawing
  • US8948396B2 patent drawing

AI summary

A method for operating with KMFs includes a communication device having a memory device: receiving a designation of a primary KMF for the communication device, wherein only one primary KMF is designated for the communication device at any given time instance; receiving a designation of a secondary KMF for the communication device; storing, within the memory device, a first and a second set of crypto groups, wherein each crypto group within each set of crypto groups comprises at least one keyset, wherein each set of crypto groups is associated, within the memory device, to only one KMF identifier; associating, within the memory device, the first set of crypto groups to an identifier for the primary KMF; and associating, within the memory device, the second set of crypto groups to an identifier for the secondary KMF.