PTP Key Distribution via Domain Control and SignCryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The PTP protocol lacks effective key distribution and encryption methods, leading to vulnerabilities such as poor flexibility in key configuration, lack of dynamic key support, and inadequate authentication, making it susceptible to malicious attacks and key misuse.

Innovation Solution

Implementing an automatic key distribution method using a domain control device to verify and send PTP protocol keys to network nodes, combined with the SignCryption encryption algorithm for message authentication, integrity, and replay protection, enabling tracking of sending nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If manual key configuration is used in PTP protocol, then key distribution is simple to implement, but flexibility is poor and configuration complexity increases with network size

Engineering Contradiction:
Improvekey distribution implementation simplicityVSAvoidkey configuration flexibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system enables automatic key distribution where network nodes autonomously obtain encryption keys through authentication with a key management server, eliminating manual configuration requirements and allowing the system to self-manage key distribution based on node identities and authentication results

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces dynamic key generation based on authentication results and node identities, transitioning from static manually-configured keys to dynamic keys that are automatically adjusted according to network conditions and authentication status, thereby improving flexibility without increasing implementation complexity

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If static keys are stored in each network node, then key distribution is straightforward, but confidentiality is poor

Engineering Contradiction:
Improvekey storage simplicityVSAvoidkey confidentiality vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The system transitions from static key storage to dynamic key distribution where keys are automatically generated and distributed based on authentication results. Keys are updated dynamically according to network conditions and authentication status, preventing long-term static key exposure and improving confidentiality while maintaining implementation simplicity

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

A key management server acts as an intermediary between network nodes and the key distribution system. This centralised intermediary handles key generation, distribution, and management securely, eliminating the need for nodes to store static keys locally and thereby improving key confidentiality without complicating the overall system architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If symmetric message authentication code functions are used in Annex K, then message authentication and integrity are provided, but tracking capability is lost and malicious nodes cannot be identified

Engineering Contradiction:
Improvemessage authentication and integrityVSAvoidmalicious node tracking capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces asymmetric cryptography (public-key infrastructure) alongside symmetric authentication mechanisms. Each network node possesses unique cryptographic identifiers and keys that enable both message authentication/integrity verification and node tracking. The asymmetric key pairs allow the system to distinguish between legitimate nodes and malicious actors while maintaining efficient symmetric authentication for message integrity

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The system implements feedback mechanisms where authentication results and node identification information are recorded and used to track communication patterns. The key management server receives authentication feedback from network nodes and uses this information to identify and track node behavior, enabling detection of malicious activities while maintaining reliable message authentication through the same cryptographic framework

Inventive Principle:
Principle #23Feedback

4Reliability

If the number of keys is increased to match the number of nodes, then security coverage is improved, but configuration complexity increases proportionally

Engineering Contradiction:
Improvesecurity coverageVSAvoidkey configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key management server provides universal key distribution service to all network nodes through a single centralized interface. The server generates and distributes appropriate encryption keys to each node based on its identity and authentication status, enabling comprehensive security coverage across the entire network without requiring individual configuration of multiple keys at each node. This multi-functional approach simplifies configuration while maintaining extensive security coverage

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of manually configuring unique keys for each node, the system uses identity-based cryptography where keys are derived from node identities through deterministic algorithms. The key management server generates keys by copying or deriving from the node's identity information, eliminating the need for manual key entry while ensuring each node receives appropriate security credentials. This approach maintains security coverage proportional to network size while keeping configuration complexity constant

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2664099B1Methods and apparatuses for distributing keys for PTP protocol
Publication Date: 2020.06.03 ALCATEL LUCENT SA
  • EP2664099B1 patent drawingFigure 1
  • EP2664099B1 patent drawingFigure 2
  • EP2664099B1 patent drawingFigure 3~4

AI summary

The present invention provides a solution of automatically distributing PTP keys, and on that basis, provides a new encryption method. A domain control device is proposed to verify whether a network node is an eligible node in the domain; if the network node is an eligible node in the domain, then a key for the PTP protocol is sent to the network node. The methods and apparatuses according to the present invention enable access authentication of various forms of PTP network nodes, as well as the automatic configuration and dynamic sending of PTP keys, such that the security of the keys are significantly increased. Additionally, by means of Sign Cryption encryption algorithm, it is enabled that for each PTP message, not only message source authentication, message integrity authentication, message confidentiality, and replay protection can be provided, but also its sending network node can be tracked. Thus, the security is significantly increased.