Remote Secure Authorization via Triple-Encrypted Token Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless network security methods, such as WEP, are vulnerable to attacks due to weak initialization vectors and complex, expensive solutions are not feasible for small-scale networks or legacy equipment.
Innovation Solution
A secure method for remotely provisioning network cryptographic keys using triple-encrypted tokens with unique serial numbers and secret keys, where only a centralized database knows the secret keys, ensuring secure key transfer and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If WEP is used for wireless network security, then authentication is provided, but security is vulnerable to attacks due to weak initialization vectors
Solution Approach 1:
The patent introduces a centralized database as an intermediary that securely stores and manages cryptographic keys. Instead of relying on vulnerable WEP implementation, the system uses this central authority to provision keys to clients through a secure remote process, eliminating the need for physical key exchange and preventing the initialization vector weaknesses that plague WEP
Solution Approach 2:
The patent replaces the mechanical/physical key distribution method (manual configuration or physical media exchange) with an automated electronic key provisioning system. The centralized database automatically generates, encrypts, and distributes cryptographic keys to clients through secure communication channels, eliminating the need for physical intervention and reducing human error
2Reliability
If complex security solutions are implemented, then network security is improved, but cost and complexity increase making them not feasible for small-scale networks
Solution Approach 1:
The centralized database serves multiple functions: it acts as a key generation server, a secure storage repository, an authentication authority, and a key distribution center. This multi-functional design eliminates the need for separate security appliances, authentication servers, and key management systems that would otherwise be required, making the solution scalable from small to large networks without proportionally increasing complexity
Solution Approach 2:
The system enables clients to automatically obtain their cryptographic keys through the secure remote provisioning process without requiring manual configuration or physical intervention. The centralized database automatically authenticates clients, generates appropriate keys, and provisions them to the clients' devices, eliminating the need for complex manual key management procedures
3Reliability
If physical key exchange is used, then secure key transfer is achieved, but physical presence is required which is not feasible for remote provisioning
Solution Approach 1:
The patent replaces the physical key exchange mechanism (requiring face-to-face interaction or physical media transfer) with an electronic key provisioning system. The centralized database securely transmits cryptographic keys through encrypted communication channels over the network, maintaining security while eliminating the need for physical presence. The process uses digital authentication and encrypted data transmission to achieve what previously required physical interaction
Data Source
AI summary
The present invention discloses a technique provisioning network cryptographic keys to a client when direct physical transfer is not feasible. In an embodiment of the invention, a client token generates a temporary key encrypted with a first secret key known only in a master token database and passes this on to an enterprise network token of a network to which service is requested. The enterprise network token then further encrypts the encrypted temporary key with a second secret key and passes that on to the master token database. Since the second secret key is also known by the master token database, the originally encrypted temporary key can be securely decoded only by a master token coupled to the master token database. The decrypted temporary key can then be re-encrypted with a key known only by the enterprise network token and the master token, and returned to the enterprise network token. This allows the enterprise network token to gain secure access to the temporary key of the client token, thereby allowing the enterprise network token to securely provision the remote client token with the appropriate enterprise Network Keys.


