Secured Device Externalizing Encryption Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-device environments, especially with the rise of IoT technology, devices often lack secure encryption keys, leading to security vulnerabilities due to the high costs and complexities of installing security hardware modules, which are necessary for managing confidentiality and integrity.

Innovation Solution

A secured device with a security hardware module generates and manages encryption key generation information, which is transmitted securely to electronic devices only after authentication, allowing these devices to generate and use encryption keys temporarily, thereby enhancing security without exposing the encryption key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security hardware modules are installed in electronic devices to ensure confidentiality and security, then security reliability is improved, but device cost and complexity increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A secured device acts as an intermediary between users and electronic devices. The secured device generates and manages encryption keys, then transmits them to electronic devices temporarily. This mediator approach allows devices without built-in security hardware modules to achieve secure communication through external key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security hardware module functionality is extracted from individual electronic devices and centralized in a separate secured device. Instead of embedding security hardware in every device, the secured device externalizes the security function, generating and distributing encryption keys to multiple electronic devices as needed.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If security hardware modules are installed in electronic devices to protect confidentiality, then security reliability is improved, but manufacturing cost increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The secured device serves multiple electronic devices simultaneously, providing security services to numerous devices without requiring each device to have its own security hardware module. This multi-functional approach allows one secured device to protect many electronic devices, significantly reducing per-device security costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of physically distributing security hardware modules to each device, the system creates and distributes digital copies of encryption keys from the secured device to electronic devices. This digital key distribution approach is far more cost-effective than physical hardware deployment.

Inventive Principle:
Principle #26Copying

3Ease of operation

If encryption keys are exposed to electronic devices for usage, then ease of operation is improved, but security vulnerability increases

Engineering Contradiction:
Improveease of operationVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Encryption keys are transmitted from the secured device to electronic devices temporarily and periodically rather than permanently. The keys are provided only when needed for specific operations, then removed or invalidated afterward. This periodic transmission minimizes the time keys are exposed, reducing vulnerability while maintaining operational capability.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system dynamically manages encryption key availability based on operational needs. Keys are generated, transmitted, and revoked in response to authentication events and operational requirements. This dynamic approach ensures keys are available when needed for ease of operation but removed when not needed to minimize security vulnerability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10601817B2Method and apparatus for providing securities to electronic devices
Publication Date: 2020.03.24 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US10601817B2 patent drawing
  • US10601817B2 patent drawing
  • US10601817B2 patent drawing

AI summary

A secured device including a security hardware module and a method thereof are provided. The secured device generates first user authentication information based on a user input, generates encryption key generation information corresponding to the first user authentication information, receives second user authentication information from an electronic device, and transmits to the electronic device the encryption key generation information corresponding to the first user authentication information when the second user authentication information matches the first user authentication information. The first user authentication information and the encryption key generation information are secured by the security hardware module.