Key Management System Using Re-Encryption for Secure Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The key distribution process in existing key management systems is vulnerable to data leakage, particularly when the master key is compromised, leading to increased security risks and management costs due to the need for strict protection measures.

Innovation Solution

A key management system that includes a master key management device generating a re-encryption key using a first secret key and a third public key, which is then stored in a key management server device, allowing for secure re-encryption of system secret keys without constant connectivity, thereby isolating the master key management device and reducing the need for strict protection of the key management server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If all system secret keys are managed in a single key management server device, then key distribution efficiency is improved, but security risk increases due to potential master key compromise

Engineering Contradiction:
Improvekey distribution efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the key management system into two distinct components: a master key management device that generates re-encryption keys and a key management server device that stores encrypted system secret keys. This segmentation allows efficient key distribution through centralized management while reducing security risk by isolating the master key in a separate, more secure environment. The master key never resides in the key management server, creating a security boundary that prevents catastrophic failure from server compromise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a re-encryption key as an intermediary element that enables secure key distribution without exposing the master key. The re-encryption key acts as a mediator that allows the key management server to re-encrypt system secret keys for distribution to clients without having access to or storing the master key. This intermediary mechanism resolves the contradiction by enabling efficient centralized key management while maintaining security through cryptographic isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict protection measures are implemented for the key management server, then security is improved, but management cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidmanagement cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the master key from the key management server device and places it exclusively in the master key management device. This extraction eliminates the need for strict protection measures at the key management server, as the master key (the most critical security asset) never resides there. The server only handles encrypted data and re-encryption keys, which are cryptographically protected and do not require the same level of physical and operational security as the master key.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs re-encryption keys that are generated specifically for distribution purposes and can be discarded after use. These re-encryption keys serve as disposable cryptographic elements that enable secure key distribution without requiring long-term secure storage or strict protection measures. The key management server handles these temporary, purpose-specific keys rather than permanent master keys, reducing security requirements and management costs.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Speed

If the master key is stored in the key management server for easy access, then key distribution speed is improved, but information leakage risk increases

Engineering Contradiction:
Improvekey distribution speedVSAvoidinformation leakage risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary encryption of system secret keys with the master key in advance, storing only the encrypted versions in the key management server. When key distribution is needed, the server can quickly retrieve and re-encrypt these pre-prepared encrypted keys without needing to access or decrypt the master key. This preliminary action enables fast key distribution while maintaining security, as the master key remains isolated and never needs to be present during distribution operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical approach of storing and physically accessing the master key in the key management server with a cryptographic substitution using re-encryption keys. Instead of mechanically having the master key available for quick access, the system uses cryptographic mechanisms where the server holds encrypted system secret keys and re-encryption keys that enable fast distribution without master key exposure. This substitution eliminates the security risk of master key leakage while maintaining distribution speed through efficient cryptographic operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP2677682B1Key management system
Publication Date: 2017.04.19 TOSHIBA SOLUTIONS
  • EP2677682B1 patent drawingFigure 1~2
  • EP2677682B1 patent drawingFigure 3~4
  • EP2677682B1 patent drawingFigure 5~6

AI summary

A master key management device includes re-encryption key generation means for generating, by using a first secret key stored in first storage means and a third public key, a re-encryption key used to re-encrypt a second secret key which is stored in second storage means and which is encrypted with a first public key to the second secret key encrypted with the third public key. A key management server device includes reception means for receiving the generated re-encryption key from the master key management device while the master key management device and the key management server device are connected to each other, and third storage means for storing the received re-encryption key. The master key management device and the key management server device are disconnected after the re-encryption key is stored in the third storage means.