Publish-Subscribe Key Distribution for End-to-End Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing publish-subscribe systems lack end-to-end security between communication apparatuses, as message brokers are not always trusted, and brokerless methods do not ensure secure communication between specific devices within a group.

Innovation Solution

A method involving a key distribution server that provides a group key for secure group communication and uses asymmetric encryption for point-to-point connections between communication apparatuses, ensuring that only intended recipients can decrypt messages, thereby preventing manipulation by other group members.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a message broker is used for group communication, then authentication and message distribution are simplified, but end-to-end security between communication apparatuses is compromised

Engineering Contradiction:
Improvemessage distributionVSAvoidend-to-end security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the communication system into two distinct security layers: group-level communication (handled by the message broker) and individual end-to-end communication (established directly between communication apparatuses). This segmentation allows the message broker to handle message distribution efficiently while separate point-to-point encrypted channels ensure end-to-end security between specific communication apparatuses, resolving the contradiction between ease of operation and reliability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If brokerless-based methods are used with group keys, then message protection within the group is achieved, but all group members can create, encrypt, modify and decrypt messages

Engineering Contradiction:
Improvemessage protectionVSAvoidunauthorized message manipulation
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies local quality by differentiating security requirements for different communication scenarios within the group. While group keys provide general message protection for all members, the invention adds individualized point-to-point encrypted channels for specific communication apparatuses. This allows messages to be protected at the group level while simultaneously ensuring that only intended recipients can access specific messages, preventing unauthorized manipulation by other group members.

Inventive Principle:
Principle #3Local quality

3Reliability

If point-to-point encrypted connections are established between all communication apparatuses, then end-to-end security is achieved, but system complexity increases

Engineering Contradiction:
Improveend-to-end securityVSAvoidconnection management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces the message broker as an intermediary that manages communication coordination between apparatuses. The broker handles message routing and distribution, while point-to-point encrypted channels are established only when specifically needed for secure end-to-end communication. This intermediary approach reduces overall system complexity by centralizing communication management while maintaining security options, avoiding the need for all apparatuses to directly manage encrypted connections with every other apparatus.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11838409B2Method and apparatus for transferring data in a publish-subscribe system
Publication Date: 2023.12.05 SIEMENS AG
  • US11838409B2 patent drawing
  • US11838409B2 patent drawing
  • US11838409B2 patent drawing

AI summary

The invention relates to a method for transferring data in a publish-subscribe system (100) comprising a key distribution server (200) and a plurality of communication devices (101, 102, 103, 104) which can be coupled to the key distribution server (200) and which comprise at least one server device and a number of client devices. The method comprises the following steps: a) providing (S101) a group key by means of the key distribution server (200) to a group (G) selected from the communication devices (101, 102, 103, 104) to establish group communications, secured by the group key, within the group (G) of selected communication devices (101, 102, 103, 104); b) providing (S102) a point-to-point connection which can be encrypted by means of a public key of an asymmetric encryption, between a first and a second communication device (101, 102) of the group (G); and c) transferring (S103) a message encrypted by means of the public key for the point-to-point connection and secured by means of the group key, between the first and the second communication device (101, 102).