Network Key Update System Using Address Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network key update methods, such as those using key trees, face inefficiencies in communication overhead and redundancy, especially when a large number of clients need to be updated, leading to potential performance degradation and increased communication costs.
Innovation Solution
A network key update system that allocates address keys to clients across multiple address spaces, allowing for the generation of a network key update key that is unique to each client, enabling efficient encryption and distribution of new network keys without relying on a key tree structure, using address keys that are difficult to generate from the disconnected client's address key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a key tree structure is used for network key distribution, then key management can be organized hierarchically, but the number of communications increases and performance degrades when updating keys for a large number of clients
Solution Approach 1:
The patent extracts the hierarchical key tree structure and replaces it with a flat key distribution mechanism. Each client receives keys directly from the server without traversing a tree structure, eliminating the communication overhead associated with tree-based key management while maintaining secure key distribution.
Solution Approach 2:
The patent segments the key distribution process by assigning different key types (group keys, individual keys, session keys) to different communication scenarios. This segmentation allows efficient key updates for specific client groups without requiring full tree restructuring, improving update efficiency while maintaining organizational structure.
2Ease of operation
If all clients share a common network key for participation, then network access control is simplified, but disconnecting a specific client becomes problematic as the key cannot be selectively revoked
Solution Approach 1:
The patent applies local quality by assigning different key characteristics to different clients and key types. Each client possesses a unique individual key in addition to group keys, allowing selective revocation of specific clients' access rights while maintaining shared access for remaining clients. This enables both simplified group management and precise individual control.
Solution Approach 2:
The patent implements preliminary action by pre-distributing multiple key types to each client before network operations begin. Clients receive individual keys, group keys, and session keys in advance, enabling the server to quickly revoke or update access rights by simply stopping key renewal or issuing revocation commands, without requiring complex real-time key management during operations.
3Measurement precision
If address keys are allocated across multiple address spaces, then client identification becomes more precise, but key generation complexity increases
Solution Approach 1:
The patent introduces multiple address spaces as additional dimensions for client identification. Instead of using a single complex identifier, clients are identified across multiple independent address spaces (e.g., network address, host address, service address). This dimensional approach enables precise client identification while maintaining relatively simple key generation within each address space, as keys can be generated independently for each dimension.
Data Source
AI summary
In order to reduce the frequency with which communication occurs when updating a network key is reduced and minimize the deterioration in performance due to updating without relying on a key tree, a server is provided with an address key allocation unit which generates identifiers for identifying clients by the combination of addresses on a plurality of address spaces and allocates address keys to respective addresses included in the generated identifier, and a network key ciphering unit which generates a network key update key which cannot be generated from the address keys allocated to a client to be disconnected, ciphers a new network key using the network key update key, and delivers the new network key to the clients.


