Electronic Device Secure Key Sharing Without Provisioning Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing solutions for managing external electronic device keys, such as vehicle keys, often require separate key provisioning servers, leading to security concerns and additional costs when sharing keys among multiple portable terminals.
Innovation Solution
An electronic device equipped with a processor, communication module, and security module that generates and manages shared keys for external electronic devices, allowing secure key sharing without the need for a separate provisioning server, using secure-module-to-secure-module communication standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a key provisioning server is used to share keys among multiple portable terminals, then key sharing functionality is achieved, but additional costs and security risks are introduced
Solution Approach 1:
The patent introduces a key sharing server as an intermediary that facilitates secure key distribution without exposing the master key. The server stores only encrypted key data and authentication information, acting as a mediator between the electronic device and portable terminals. This resolves the contradiction by enabling key sharing functionality while maintaining security through the intermediary's controlled access mechanisms.
Solution Approach 2:
The patent extracts the master key from the key sharing server and keeps it exclusively in the electronic device's secure storage. Only encrypted key data and authentication credentials are stored on the server. This separation ensures that even if the server is compromised, the master key remains secure, thus enabling key sharing while preserving security.
2Adaptability or versatility
If a key provisioning server is deployed, then key management functionality is provided, but additional system complexity and costs are incurred
Solution Approach 1:
The electronic device performs self-service by generating and storing the master key locally in its secure storage. The device independently manages key generation and can authenticate portable terminals without requiring complex server-side key management infrastructure. This reduces system complexity while maintaining key management functionality.
Solution Approach 2:
The patent segments the key management system into distinct functional components: master key generation and storage in the electronic device, encrypted key data storage on the server, and authentication credential verification. This segmentation allows each component to be optimized independently, reducing overall system complexity while providing comprehensive key management capabilities.
3Adaptability or versatility
If master key is shared among multiple portable terminals, then key sharing is enabled, but security vulnerabilities arise
Solution Approach 1:
The patent creates encrypted copies of the master key for each portable terminal instead of sharing the actual master key. Each terminal receives a unique encrypted key data set that can be used for authentication but cannot be used to derive the master key. This enables key sharing functionality while eliminating security risks associated with master key exposure.
Solution Approach 2:
The patent implements local quality by providing each portable terminal with customized encrypted key data and authentication credentials specific to that terminal. The encryption keys and authentication information are tailored to individual terminals, ensuring that compromise of one terminal does not affect others. This enables secure key sharing with each terminal having appropriate local security properties.
Data Source
AI summary
An electronic device according to an embodiment may include a processor, a wireless communication module, and a security module. The security module may store and manage a shared key and an authentication key. The processor may be configured to receive a request for transmission of the authentication key to a first external electronic device and transmit, to the security module, information and command for generation of the shared key. The security module may generate the shared key based on the information for generation of the shared key, and the security module may transmit, to the first external electronic device, the generated shared key and information associated with the generated shared key. Various other embodiments are possible.


