Secure Key Distribution via Identity Management Server Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face security vulnerabilities during ID-based registration and authentication, as private keys and IDs are not adequately protected, leading to potential leakage and compromised security performance.

Innovation Solution

A key distribution method and system where the identity management server encrypts private keys using a negotiated key, ensuring secure transmission between the server and terminal, compatible with existing network authentication methods and enhancing end-to-end communication security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the ID and private key are transmitted using existing technology without encryption at the network layer, then the registration and authentication process can be completed, but information security of the private key and ID is not ensured leading to potential leakage

Engineering Contradiction:
Improveinformation securityVSAvoidcommunication security mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by establishing a security mechanism before the actual transmission of sensitive data. The identity management server and terminal negotiate and establish encryption keys and authentication mechanisms in advance, before the private key and ID are transmitted. This ensures that when the actual data transmission occurs, robust security protections are already in place, preventing information leakage while maintaining a manageable level of complexity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption and authentication are implemented at the network layer, then communication security is improved, but the complexity of the authentication mechanism increases

Engineering Contradiction:
Improvecommunication security performanceVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses an intermediary approach by introducing an identity management server as a mediator between the terminal and the network. This server handles the complex tasks of key negotiation, encryption setup, and authentication verification. By centralizing these security functions in a dedicated intermediary entity, the patent achieves strong communication security performance while managing system complexity through specialized role assignment rather than distributing complex security logic across all components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a secure communication manner is implemented for key transmission, then information leakage is prevented, but the authentication process becomes more complex

Engineering Contradiction:
Improveinformation securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies self-service by enabling the terminal and identity management server to autonomously negotiate and establish encryption keys without requiring manual configuration or intervention. The terminal actively participates in the key negotiation process, generating and managing its own cryptographic materials. This automated self-service approach ensures information security through robust encryption while keeping the authentication process relatively simple and efficient, as the system performs the complex security operations automatically without increasing operational burden on users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3726797B1Key distribution method, device and system
Publication Date: 2023.10.04 HUAWEI TECH CO LTD
  • EP3726797B1 patent drawingFigure 1~2
  • EP3726797B1 patent drawingFigure 3
  • EP3726797B1 patent drawingFigure 4

AI summary

This application provides a key distribution method, an apparatus, and a system. The method includes: determining, by an identity management server based on AAA authentication information in an ID registration request message sent by a terminal, whether AAA authentication on the terminal succeeds; if the AAA authentication on the terminal succeeds, allocating an ID to the terminal and sending the ID of the terminal to a key management server; and generating, by the key management server, a private key of the terminal based on the ID of the terminal and returning the private key to the management server. After negotiating with the terminal to generate a first key, the identity management server encrypts the ID and the private key of the terminal by using the first key, and sends an encrypted ID and an encrypted private key to the terminal. After receiving the encrypted ID and the encrypted private key, the terminal obtains the ID and the private key of the terminal through decryption by using the first key. According to the key distribution method, apparatus, and system provided in this application, communication security performance of the terminal during ID-based registration authentication is improved.