Secured Device Externalizing Encryption Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-device environments, especially with the rise of IoT technology, devices often lack secure encryption keys, leading to security vulnerabilities due to the high costs and complexities of installing security hardware modules, which are necessary for managing confidentiality and integrity.
Innovation Solution
A secured device with a security hardware module generates and manages encryption key generation information, which is transmitted securely to electronic devices only after authentication, allowing these devices to generate and use encryption keys temporarily, thereby enhancing security without exposing the encryption key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security hardware modules are installed in electronic devices to ensure confidentiality and security, then security reliability is improved, but device cost and complexity increase
Solution Approach 1:
A secured device acts as an intermediary between users and electronic devices. The secured device generates and manages encryption keys, then transmits them to electronic devices temporarily. This mediator approach allows devices without built-in security hardware modules to achieve secure communication through external key management.
Solution Approach 2:
The security hardware module functionality is extracted from individual electronic devices and centralized in a separate secured device. Instead of embedding security hardware in every device, the secured device externalizes the security function, generating and distributing encryption keys to multiple electronic devices as needed.
2Reliability
If security hardware modules are installed in electronic devices to protect confidentiality, then security reliability is improved, but manufacturing cost increases
Solution Approach 1:
The secured device serves multiple electronic devices simultaneously, providing security services to numerous devices without requiring each device to have its own security hardware module. This multi-functional approach allows one secured device to protect many electronic devices, significantly reducing per-device security costs.
Solution Approach 2:
Instead of physically distributing security hardware modules to each device, the system creates and distributes digital copies of encryption keys from the secured device to electronic devices. This digital key distribution approach is far more cost-effective than physical hardware deployment.
3Ease of operation
If encryption keys are exposed to electronic devices for usage, then ease of operation is improved, but security vulnerability increases
Solution Approach 1:
Encryption keys are transmitted from the secured device to electronic devices temporarily and periodically rather than permanently. The keys are provided only when needed for specific operations, then removed or invalidated afterward. This periodic transmission minimizes the time keys are exposed, reducing vulnerability while maintaining operational capability.
Solution Approach 2:
The system dynamically manages encryption key availability based on operational needs. Keys are generated, transmitted, and revoked in response to authentication events and operational requirements. This dynamic approach ensures keys are available when needed for ease of operation but removed when not needed to minimize security vulnerability.
Data Source
AI summary
A secured device including a security hardware module and a method thereof are provided. The secured device generates first user authentication information based on a user input, generates encryption key generation information corresponding to the first user authentication information, receives second user authentication information from an electronic device, and transmits to the electronic device the encryption key generation information corresponding to the first user authentication information when the second user authentication information matches the first user authentication information. The first user authentication information and the encryption key generation information are secured by the security hardware module.


