PUF-Based Key Management System with Load Balancing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current key management systems face inefficiencies when handling excessive requests and are vulnerable to damage or loss of secure memory, as key generators struggle to operate efficiently and cryptographic keys become unserviceable.

Innovation Solution

A physically unclonable function (PUF)-based key management system with a load balancer and backup channel, where key management components include PUF units, key derivation function logic, and memory, distributing workload and generating cryptographic keys, and storing backup copies to ensure secure and reliable key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are stored in secure memory, then security is improved, but the keys become unserviceable upon damage or loss of the secure memory

Engineering Contradiction:
ImprovesecurityVSAvoidserviceability
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The patent creates backup copies of cryptographic keys in backup key management components. When the primary key management component's memory is damaged or lost, the system can retrieve keys from the backup components, making the keys serviceable again while maintaining security through controlled access mechanisms.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent performs preliminary key backup before memory damage occurs. Backup key management components are pre-configured with copies of cryptographic keys, so that when the primary memory is damaged, the system can immediately switch to backup components without loss of serviceability.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If a single key generator is used, then device complexity is reduced, but productivity decreases when receiving excessive requests

Engineering Contradiction:
Improvesystem complexityVSAvoidrequest handling capacity
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent divides the key management system into multiple key management components, each capable of handling key generation requests independently. This segmentation allows the system to distribute excessive requests across multiple components, significantly improving productivity while maintaining manageable complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each key management component is designed to be universal and multi-functional, capable of both generating keys and serving as a backup for other components. This multi-functionality allows any component to handle requests from any client, improving overall system productivity without requiring specialized components for different functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If multiple key management components are deployed, then productivity and reliability are improved, but device complexity increases

Engineering Contradiction:
Improverequest handling capacityVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges the functions of key generation and key backup into a single unified key management component architecture. Each component can both generate keys and serve as backup for others, eliminating the need for separate dedicated backup systems and reducing overall system complexity while maintaining high productivity and reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates equipotential key management components where each component has equal capability to generate and manage keys. This equipotential design simplifies the system architecture by eliminating hierarchical complexity, allowing any component to serve any function, thereby improving productivity without proportionally increasing management complexity.

Inventive Principle:
Principle #12Equipotentiality

Data Source

PatentUS12113895B2Key management system providing secure management of cryptographic keys, and methods of operating the same
Publication Date: 2024.10.08 PUFSECURITY CORP
  • US12113895B2 patent drawing
  • US12113895B2 patent drawing
  • US12113895B2 patent drawing

AI summary

A method of operating the physically unclonable function (PUF)-based key management system includes upon receiving a key generation request including a parameter, a load balancer dispatching a key generation request including a parameter from an external device according to workloads of a plurality of key management components (KMCs). A KMC having minimum workload among the plurality of KMCs is designated as the key-generation KMC and the key generation request is dispatched thereto, and remaining KMCs of the plurality of KMCs are designated as backup KMCs. The method further includes the key-generation KMC generating a key according to the parameter and a first PUF sequence, transmitting the key and an identifier associated therewith to the backup KMC via a backup channel, and the backup KMC generating a wrapped key according to the key and a second PUF sequence.