One-Way Key Chain for Disconnected Service Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing key management systems for traffic keys in communication and satellite navigation systems face challenges in periodically renewing keys while ensuring transparent access for authorized users who may not be continuously connected, balancing security and usability.
Innovation Solution
A method using a one-way function to derive successive traffic keys from a unique secret parameter, allowing users to memorize current and future keys with different confidence levels, and employing an OTAR function to broadcast keys within the service itself, ensuring access during transitions and maintaining security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the traffic key is renewed periodically through OTAR broadcasts, then system security is improved, but authorized users who are disconnected during key transitions lose access to the service
Solution Approach 1:
The system performs preliminary actions by having users memorize multiple future traffic keys in advance (key buffering). Users receive and store keys K(t), K(t+1), ..., K(t+d-1) before they are needed, allowing them to maintain access even when disconnected during key transitions. This preliminary key acquisition resolves the contradiction by ensuring continuous access while maintaining periodic key renewal for security.
Solution Approach 2:
The system changes the parameter of key validity duration from a fixed short period to a variable extended period through confidence levels. Users are assigned different confidence levels d that determine how many future keys they can rely on without continuous connection. This parameter change allows the system to provide transparent access to disconnected users while maintaining security through differentiated key management policies.
2Ease of operation
If manual offline distribution of keys is used, then users can maintain access during disconnections, but the transparency and automation of the OTAR system is lost
Solution Approach 1:
The system implements self-service by enabling users to autonomously manage their own key buffers. Users automatically receive and store multiple future keys through OTAR broadcasts without requiring manual intervention. The system self-regulates by allowing users to independently maintain access during disconnections through their buffered keys, eliminating the need for manual offline key distribution while preserving automation.
Solution Approach 2:
The system performs preliminary automatic key distribution by broadcasting multiple future traffic keys to users in advance through OTAR messages. Users automatically receive and store these keys before disconnection events occur, maintaining continuous access without manual intervention. This preliminary automated action resolves the contradiction by providing both continuous access and system automation.
3Ease of operation
If all users are given the same high confidence level for key retention, then access transparency is improved, but system security is compromised for users with lower trust levels
Solution Approach 1:
The system applies local quality by assigning different confidence levels d to different user groups based on their specific trust requirements. Instead of a uniform key retention policy, each user group receives keys with confidence levels appropriate to their security clearance and operational needs. This localized differentiation resolves the contradiction by providing transparent access to each group while maintaining appropriate security levels for each user category.
Solution Approach 2:
The system changes the parameter of confidence level from a uniform value to a variable parameter that can be adjusted for different user groups. Users with higher trust levels receive larger confidence levels d, allowing them to retain more future keys and have longer periods of transparent access. Users with lower trust levels receive smaller confidence levels, maintaining stricter security controls. This parameter differentiation resolves the contradiction between access transparency and security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention concerns a method for managing keys allowing a user to access one or more given services S in a communication system, though the user may not be continuously connected to said service. The invention is characterized in that in includes at least the following steps: generating a key K(t) providing access to the day's service [t] for all the t<tfin by using a one-way function in the following manner (one-way function defined as being a function for which it is not presently possible and by computing means to obtain the inverse function); using a root key K(tfin) and generating the key K(tfin-1) for the day [tfin-1] prior to the day tfin, by using a function f such that K(tfin-1) = f(K(tfin)); using the new key value K(tfin-1) for generating the key for the previous day K(tfin-2) and repeating said step over the limited time period of day[t] to day [t+d] to obtain the chain 20 K(t+d-1), K(t+d-2).....; sending each day t, the key K(t+d) to the users or group of users having a trust level d (providing a potential access to the service during d consecutive days).