Secure Public Key Exchange Using Manufacturing Initialization Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for establishing a secure channel between devices require storing multiple public keys and certificates, which is cumbersome and inefficient.
Innovation Solution
A method involving a protocol management computer that uses near-field communications to securely exchange public keys between a reader device and a thin client device using initialization keys stored during manufacturing, eliminating the need for certificate authorities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If certificates authorized by a certification authority are used to exchange public keys, then security is established, but the complexity of key management increases and multiple public keys must be stored on each device
Solution Approach 1:
The patent extracts the certification authority from the key exchange process by using pre-shared initialization keys that are directly embedded in devices during manufacturing. This eliminates the need for certificate-based authentication and the associated complexity of managing multiple public keys and certificates, while maintaining security through the use of these initialization keys for encrypting public key exchanges.
2Reliability
If multiple public keys and certificates are stored on each device for secure communication, then security is improved, but data storage requirements increase
Solution Approach 1:
The patent removes the need to store multiple certificates and public keys by using a single initialization key per device that is pre-loaded during manufacturing. This initialization key is sufficient for securing all future communications, dramatically reducing the quantity of cryptographic data that must be stored on each device while maintaining equivalent security.
3Reliability
If conventional certificate-based key exchange is used, then secure channels can be established, but the process becomes cumbersome and inefficient
Solution Approach 1:
The patent applies preliminary action by pre-loading initialization keys into devices during the manufacturing process. This eliminates the need for complex real-time certificate validation and key management during operation, allowing devices to efficiently establish secure channels immediately upon first use without cumbersome setup procedures.
Data Source
AI summary
Systems and methods are disclosed for performing a secure exchange of encryption keys (e.g., public keys) between two devices. One or more initialization keys are stored at both devices. In some embodiments, at least one device (e.g., a reader device) stores the initialization key(s) (e.g., a symmetric key, an asymmetric key pair) in local memory as part of performance of a manufacturing process for the device. The second device (e.g., a thin client device) may receive the initialization key(s) from an acceptance cloud (e.g., a server computer configured to perform terminal processing). The initialization key(s) are utilized to perform a secure exchange of the devices' respective public keys. Once these public keys are exchanged, the devices may proceed to establishing a secure connection with which subsequent operations may be performed.


