Shared Private Key Detection in Computerized Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computerized systems, shared keys, particularly private keys, can lead to security risks and unintended operational vulnerabilities due to unnoticed or forgotten key sharing, affecting numerous entities and causing unpredictable consequences during key management operations.

Innovation Solution

A method and apparatus for detecting and managing shared private keys by performing a shared key operation, which includes displaying information about shared keys, relocating them, preventing unauthorized key management, and blacklisting, to mitigate risks and ensure secure operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If key management operations are performed on shared private keys, then key management functionality is provided, but security risks and unintended consequences increase

Engineering Contradiction:
Improvekey management operationVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary detection to identify shared private keys before key management operations are executed. By detecting shared keys in advance and notifying users, the system prevents unintended consequences of operations on shared keys, allowing users to take corrective actions before security risks materialize.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by notifying users when shared private keys are detected. This feedback loop provides visibility into key sharing status and enables users to make informed decisions about whether to proceed with key management operations, thereby controlling security risks.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If shared private keys are allowed in the system, then key sharing functionality is provided, but system vulnerability increases

Engineering Contradiction:
Improvekey sharingVSAvoidsystem vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system continuously monitors and provides feedback about key sharing status across the network. By detecting when private keys are shared and notifying relevant users, the system maintains adaptability for key sharing while providing the information needed to manage and reduce associated vulnerabilities.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes the state parameter of key management by introducing awareness and control mechanisms. When shared keys are detected, the system modifies the operational parameters by notifying users and enabling them to change key management policies, thereby reducing vulnerability while maintaining necessary key sharing functionality.

Inventive Principle:
Principle #35Parameter changes

3Speed

If key management operations are performed without detection, then operational speed is maintained, but unexpected consequences occur

Engineering Contradiction:
Improveoperation speedVSAvoidawareness of shared keys
Core Design Contradiction:
SpeedVSLoss of information

Solution Approach 1:

The detection of shared private keys is performed as a preliminary action before key management operations execute. This preliminary detection occurs in the background and does not significantly slow down operations, while simultaneously providing the necessary information awareness to prevent unexpected consequences.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system allows key management operations to proceed rapidly through the detection and execution phases, skipping unnecessary delays. By implementing efficient background detection and targeted notification only when shared keys are actually found, the system maintains high operation speed while still providing critical information awareness.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentEP3065333B1Shared keys in a computerized system
Publication Date: 2021.03.31 SSH COMMUNICATIONS SECURITY
  • EP3065333B1 patent drawingFigure 1~2
  • EP3065333B1 patent drawingFigure 3~5

AI summary

Methods and apparatuses for managing keys in a computerized system are disclosed. A private key is determined as a shared key, a private key being a shared key when information of the private key can be shared by a plurality of entities or would be shared by a plurality of entities as a result of a requested key management operation. A shared key operation is then performed based on the determining.