Remote Secure Authorization via Triple-Encrypted Token Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless network security methods, such as WEP, are vulnerable to attacks due to weak initialization vectors and complex, expensive solutions are not feasible for small-scale networks or legacy equipment.

Innovation Solution

A secure method for remotely provisioning network cryptographic keys using triple-encrypted tokens with unique serial numbers and secret keys, where only a centralized database knows the secret keys, ensuring secure key transfer and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If WEP is used for wireless network security, then authentication is provided, but security is vulnerable to attacks due to weak initialization vectors

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a centralized database as an intermediary that securely stores and manages cryptographic keys. Instead of relying on vulnerable WEP implementation, the system uses this central authority to provision keys to clients through a secure remote process, eliminating the need for physical key exchange and preventing the initialization vector weaknesses that plague WEP

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/physical key distribution method (manual configuration or physical media exchange) with an automated electronic key provisioning system. The centralized database automatically generates, encrypts, and distributes cryptographic keys to clients through secure communication channels, eliminating the need for physical intervention and reducing human error

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If complex security solutions are implemented, then network security is improved, but cost and complexity increase making them not feasible for small-scale networks

Engineering Contradiction:
Improvenetwork securityVSAvoidsolution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized database serves multiple functions: it acts as a key generation server, a secure storage repository, an authentication authority, and a key distribution center. This multi-functional design eliminates the need for separate security appliances, authentication servers, and key management systems that would otherwise be required, making the solution scalable from small to large networks without proportionally increasing complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables clients to automatically obtain their cryptographic keys through the secure remote provisioning process without requiring manual configuration or physical intervention. The centralized database automatically authenticates clients, generates appropriate keys, and provisions them to the clients' devices, eliminating the need for complex manual key management procedures

Inventive Principle:
Principle #25Self-service

3Reliability

If physical key exchange is used, then secure key transfer is achieved, but physical presence is required which is not feasible for remote provisioning

Engineering Contradiction:
Improvesecure key transferVSAvoidphysical presence requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the physical key exchange mechanism (requiring face-to-face interaction or physical media transfer) with an electronic key provisioning system. The centralized database securely transmits cryptographic keys through encrypted communication channels over the network, maintaining security while eliminating the need for physical presence. The process uses digital authentication and encrypted data transmission to achieve what previously required physical interaction

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS7827409B2Remote secure authorization
Publication Date: 2010.11.02 KOOLSPAN INC
  • US7827409B2 patent drawing
  • US7827409B2 patent drawing
  • US7827409B2 patent drawing

AI summary

The present invention discloses a technique provisioning network cryptographic keys to a client when direct physical transfer is not feasible. In an embodiment of the invention, a client token generates a temporary key encrypted with a first secret key known only in a master token database and passes this on to an enterprise network token of a network to which service is requested. The enterprise network token then further encrypts the encrypted temporary key with a second secret key and passes that on to the master token database. Since the second secret key is also known by the master token database, the originally encrypted temporary key can be securely decoded only by a master token coupled to the master token database. The decrypted temporary key can then be re-encrypted with a key known only by the enterprise network token and the master token, and returned to the enterprise network token. This allows the enterprise network token to gain secure access to the temporary key of the client token, thereby allowing the enterprise network token to securely provision the remote client token with the appropriate enterprise Network Keys.