Hierarchical Key Management for Secure Multicast Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large networks with mobile nodes face management and security challenges due to frequent changes in node membership, leading to potential security compromises and inefficiencies in communication, especially in multicast communications.

Innovation Solution

A network structure with multiple groups, each having a unique security function, utilizes a host node to provide session keys for secure intra-group and inter-group communications, with intra-group mediators managing distributed security functions to reduce latency and maintain consistent security across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multicast communication is used to distribute security keys in a large network, then communication efficiency is improved, but security is compromised due to potential interception

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The network is divided into multiple groups, each with its own group key. Security key distribution is segmented into intra-group distribution (using group keys) and inter-group distribution (using session keys), allowing efficient multicast within groups while maintaining security through hierarchical key management

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Group keys act as intermediaries between the central authority and individual nodes. The central authority distributes session keys to group keys, which then distribute to individual nodes within groups. This intermediary layer enables efficient multicast while preserving security through layered encryption

Inventive Principle:
Principle #24Intermediary (Mediator)

2Area of stationary object

If a distributed relay structure is used to distribute security infrastructure, then network coverage is improved, but latency increases due to repeated decryption and re-encryption

Engineering Contradiction:
Improvenetwork coverageVSAvoidlatency
Core Design Contradiction:
Area of stationary objectVSLoss of time

Solution Approach 1:

Group keys are pre-distributed to all nodes within a group before actual communication occurs. When a node joins or leaves, only the group key needs updating rather than individual keys for each node, eliminating repeated decryption and re-encryption operations

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adapts to node mobility by using group-based key management. When nodes move in or out of the network, the group key remains valid for existing members, allowing seamless key distribution without requiring individual key updates for each node transition

Inventive Principle:
Principle #15Dynamics

3Reliability

If serial communication is used in a large network, then security is maintained, but communication time becomes excessive

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network is segmented into multiple groups, allowing parallel key distribution to each group simultaneously. This eliminates the sequential bottleneck of serial communication while maintaining security through group-level encryption, reducing overall communication time proportionally to the number of groups

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Multiple individual key distribution operations are merged into a single group key distribution operation. By combining security management at the group level rather than individual node level, the system achieves both the security of individual key management and the efficiency of bulk distribution

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8897452B2Network having multicast security and method therefore
Publication Date: 2014.11.25 ARCHITECTURE TECH CORP
  • US8897452B2 patent drawing
  • US8897452B2 patent drawing
  • US8897452B2 patent drawing

AI summary

A method for conducting encrypted communication in a network and a network having a plurality of nodes organized into a plurality of groups which initiates encrypted communication between a first one of the plurality of nodes of a first one of the plurality of groups and a second one of the plurality of nodes of the first one of the plurality of groups different from the first one of the plurality of groups using a group key and initiates encrypted communication between a third one of the plurality of nodes of the first one of the plurality of groups and a fourth one of the plurality of nodes of a second one of the plurality groups different from the first one of the plurality of groups using a session key.