Single Cryptographic Group Key Management for Multiple Periods
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional OTAR two-way radio systems are limited to managing only one cryptographic period, making it complex and confusing to manage multiple cryptographic periods and keysets, and introducing interoperability issues with storage location numbers (SLNs).
Innovation Solution
The system allows different cryptographic periods to be maintained for each storage location number (SLN) within a single cryptographic group by using two keysets and an additional keyset to manage communications, with the Key Management Facility (KMF) determining and updating key material based on individual SLN cryptographic periods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple cryptographic groups are used to manage multiple cryptographic periods, then the ability to support different key change intervals is improved, but the system complexity and difficulty of management increase
Solution Approach 1:
The patent merges multiple cryptographic periods into a single cryptographic group by allowing each SLN to have its own cryptographic period assignment. Instead of creating separate cryptographic groups for different key change intervals, the system combines them in one group with individual period management per SLN, thereby reducing system complexity while maintaining the ability to support multiple key change intervals.
Solution Approach 2:
The single cryptographic group is designed to serve multiple functions by accommodating different cryptographic periods for different SLNs simultaneously. This multi-functional approach allows the same cryptographic group to manage diverse key change intervals (e.g., monthly for some SLNs, quarterly for others) without requiring separate groups, thus improving versatility while controlling complexity.
2Adaptability or versatility
If multiple cryptographic groups are implemented, then different cryptographic periods can be managed, but interoperability issues and coordination requirements increase
Solution Approach 1:
The patent combines multiple cryptographic periods into a single cryptographic group to eliminate interoperability coordination issues between groups. By having all SLNs within one group with individually assigned periods, the system avoids the complexity of coordinating SLNs across multiple groups, ensuring reliable interoperability while maintaining diverse cryptographic periods.
3Adaptability or versatility
If a new SLN is added to an existing system with multiple cryptographic groups, then the system capacity increases, but the process becomes more complex requiring determination of cryptographic period, finding or creating cryptographic group, and obtaining SLN
Solution Approach 1:
The patent merges all SLNs into a single cryptographic group, eliminating the need to find or create cryptographic groups when adding new SLNs. The simplified process requires only determining the cryptographic period for the new SLN and obtaining an SLN from the single group, thereby increasing system capacity while significantly improving ease of operation.
4Ease of operation
If only one cryptographic group and two keysets are used as per conventional OTAR protocol, then the system is simpler to manage, but only one cryptographic period is supported
Solution Approach 1:
The patent applies local quality by allowing each SLN within the single cryptographic group to have its own cryptographic period assignment and keyset management. This means different parts of the system (different SLNs) can have different cryptographic periods while remaining within the same group, thereby maintaining management simplicity while improving cryptographic period support capability.
Data Source
AI summary
A plurality of storage location numbers (“SLNs”), each having a cryptographic period, is received at a first device (100). A system cryptographic period is determined based on the SLN cryptographic periods. Prior to expiration of each system cryptographic period, if at least one SLN requires an updated, the first device sends updated key material for the at least one SLN. A second device (102) maintains first, second, and third keysets, wherein the first and second keysets comprise key material. The second device receives a message to make the first keyset active, and a second message for updating at least a portion of the key material in the second keyset with updated key material for at least one SLN. The second device makes the third keyset equivalent to the second keyset, updates the second keyset with the updated key material, and receives a third message to make the second keyset active.


