PUF-Based Key Management System with Load Balancing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current key management systems face inefficiencies when handling excessive requests and are vulnerable to damage or loss of secure memory, as key generators struggle to operate efficiently and cryptographic keys become unserviceable.
Innovation Solution
A physically unclonable function (PUF)-based key management system with a load balancer and backup channel, where key management components include PUF units, key derivation function logic, and memory, distributing workload and generating cryptographic keys, and storing backup copies to ensure secure and reliable key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys are stored in secure memory, then security is improved, but the keys become unserviceable upon damage or loss of the secure memory
Solution Approach 1:
The patent creates backup copies of cryptographic keys in backup key management components. When the primary key management component's memory is damaged or lost, the system can retrieve keys from the backup components, making the keys serviceable again while maintaining security through controlled access mechanisms.
Solution Approach 2:
The patent performs preliminary key backup before memory damage occurs. Backup key management components are pre-configured with copies of cryptographic keys, so that when the primary memory is damaged, the system can immediately switch to backup components without loss of serviceability.
2Device complexity
If a single key generator is used, then device complexity is reduced, but productivity decreases when receiving excessive requests
Solution Approach 1:
The patent divides the key management system into multiple key management components, each capable of handling key generation requests independently. This segmentation allows the system to distribute excessive requests across multiple components, significantly improving productivity while maintaining manageable complexity through modular design.
Solution Approach 2:
Each key management component is designed to be universal and multi-functional, capable of both generating keys and serving as a backup for other components. This multi-functionality allows any component to handle requests from any client, improving overall system productivity without requiring specialized components for different functions.
3Productivity
If multiple key management components are deployed, then productivity and reliability are improved, but device complexity increases
Solution Approach 1:
The patent merges the functions of key generation and key backup into a single unified key management component architecture. Each component can both generate keys and serve as backup for others, eliminating the need for separate dedicated backup systems and reducing overall system complexity while maintaining high productivity and reliability.
Solution Approach 2:
The patent creates equipotential key management components where each component has equal capability to generate and manage keys. This equipotential design simplifies the system architecture by eliminating hierarchical complexity, allowing any component to serve any function, thereby improving productivity without proportionally increasing management complexity.
Data Source
AI summary
A method of operating the physically unclonable function (PUF)-based key management system includes upon receiving a key generation request including a parameter, a load balancer dispatching a key generation request including a parameter from an external device according to workloads of a plurality of key management components (KMCs). A KMC having minimum workload among the plurality of KMCs is designated as the key-generation KMC and the key generation request is dispatched thereto, and remaining KMCs of the plurality of KMCs are designated as backup KMCs. The method further includes the key-generation KMC generating a key according to the parameter and a first PUF sequence, transmitting the key and an identifier associated therewith to the backup KMC via a backup channel, and the backup KMC generating a wrapped key according to the key and a second PUF sequence.


