Server-Mediated Key Exchange for Secure Device-to-Device Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication technologies face challenges in establishing secure device-to-device communication channels without relying on potentially insecure and untrusted communication channels, particularly in scenarios where sensitive data needs to be shared locally among trusted devices while preventing unauthorized access.

Innovation Solution

A method and system that utilize pre-established secure communication channels to exchange address data and cryptographic keys between devices, allowing the establishment of a secure device-to-device communication channel while ensuring that the exchange occurs over trusted channels, and enforcing user and usage policies through a server system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If address data and cryptographic keys are exchanged over a direct device-to-device communication channel, then the establishment of secure communication becomes simpler and more direct, but the security is compromised because the channel may be insecure and untrusted

Engineering Contradiction:
Improvesimplicity of channel establishmentVSAvoidsecurity of communication channel
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A server acts as an intermediary to facilitate the exchange of address data and cryptographic keys between devices. The server receives connection requests from both devices, verifies permissions, and distributes the necessary connection information through secure channels, eliminating the need for direct insecure key exchange while maintaining operational simplicity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The server performs preliminary verification of user identities and permissions before allowing address data and cryptographic keys to be exchanged. Connection requests are authenticated and authorized in advance, ensuring that only permitted devices can establish secure communication channels

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a server mediates the exchange of connection data through pre-established secure channels, then security and policy enforcement are improved, but the complexity of the system increases

Engineering Contradiction:
Improvesecurity and policy enforcementVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server performs multiple functions including receiving connection requests, verifying user identities, checking permissions, distributing address data, and managing cryptographic keys. This multi-functional approach consolidates security mechanisms into a single system that handles all aspects of secure channel establishment

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Devices automatically exchange connection data through the server without requiring manual configuration or intervention. The server autonomously manages the distribution of address data and cryptographic keys, and devices self-configure their secure communication channels based on the received information

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10397202B2Secure communication channels
Publication Date: 2019.08.27 BLACKBERRY LTD
  • US10397202B2 patent drawing
  • US10397202B2 patent drawing
  • US10397202B2 patent drawing

AI summary

A method and system for negotiating a secure device-to-device communications channel between a first computing device and a second computing device, wherein the first computing device is associated with a first user and the second computing device is associated with a second user. The method comprises receiving, at a server, a first connection request comprising first address data and a first cryptographic key associated with the first computing device, the first connection request being received over a first secure communications channel, and receiving, at the server, a second connection request comprising second address data and a second cryptographic key associated with the second computing device, the second connection request being received over a second secure communications channel.