Remote Application Key Installation With Low-Bandwidth Symmetric Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure installation of application keys on remote devices result in high bandwidth usage due to the need for symmetric and asymmetric encryption, which is resource-intensive, especially when frequent key updates are required.

Innovation Solution

A method involving a Key Management System (KMS) that generates a key seed and a transport key, allowing secure installation of application keys using symmetric encryption, reducing bandwidth usage by encrypting only new keys with the transport key, which is derived from the application policy and identifier.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If symmetric and asymmetric encryption methods are used for secure key transfer, then data security is improved, but bandwidth consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the key transfer process into two distinct phases: initial asymmetric key exchange for establishing security, followed by symmetric key encryption for subsequent key updates. This segmentation allows the system to use the more efficient symmetric encryption method for frequent updates while maintaining security through the initial asymmetric exchange, thereby reducing overall bandwidth consumption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by establishing asymmetric key pairs and security credentials before the actual key transfer process. The application owner device and remote device perform asymmetric key exchange in advance to establish secure channels, so that subsequent symmetric key updates can be transmitted efficiently without requiring repeated asymmetric encryption operations.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If frequent application key updates are performed, then security is maintained, but bandwidth usage and processing resources increase

Engineering Contradiction:
ImprovesecurityVSAvoidbandwidth efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic key management where the encryption method adapts based on the update frequency. For the initial key establishment, asymmetric encryption is used to ensure security. For subsequent frequent updates, the system dynamically switches to symmetric encryption which is more bandwidth-efficient, allowing frequent key updates without proportionally increasing bandwidth consumption.

Inventive Principle:
Principle #15Dynamics

3Reliability

If both symmetric and asymmetric encryption are used, then secure transfer is achieved, but device complexity increases

Engineering Contradiction:
Improvesecure transferVSAvoidencryption method complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the encryption functionality into distinct modules: an asymmetric encryption module for initial key exchange and a symmetric encryption module for subsequent key updates. This segmentation allows each module to be optimized independently and simplifies the overall system architecture by clearly defining when each encryption type should be used, reducing the operational complexity despite using both methods.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250279881A1Secure installation of application keys
Publication Date: 2025.09.04 NAGRAVISION SRL
  • US20250279881A1 patent drawing
  • US20250279881A1 patent drawing
  • US20250279881A1 patent drawing

AI summary

The present disclosure includes methods, devises and systems for preparing and installing one or more application keys owned by application owners in a remote device. The present disclosure further proposes methods, devices and systems for secure installation of subsequent application keys on a device utilising corresponding key derivation functions to associate an application with a respective policy and identifier using significantly lmv bandwidth for transfer of keys for execution of the respective application on the device.