Secure Encryption Key Transfer Between Smart Card Zones
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack the ability to securely transfer encryption keys from one smart card to another in different zones, even with owner consent, due to the absence of a method to share keys between smart cards without compromising their zone capabilities.
Innovation Solution
A method is provided to facilitate the enrollment and transfer of security credentials with different permission levels between smart cards, using a cryptographic co-processor and middleware to securely move encryption keys from one smart card to another under dual control, maintaining separation of duties and zone capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If encryption keys are transferred between smart cards in different zones, then key sharing capability is improved, but security and zone integrity may be compromised
Solution Approach 1:
The patent introduces a key sharing mechanism that acts as an intermediary between smart cards in different zones. The system uses a key sharing request and key sharing response protocol that involves multiple entities (home zone, remote zone, and key sharing mechanism) to enable secure key transfer. This intermediary approach allows keys to be shared between zones without compromising the fundamental zone security architecture, as the key sharing occurs through a controlled protocol rather than direct unauthorized access.
2Reliability
If traditional zone isolation is maintained, then security is preserved, but key sharing between zones is prevented
Solution Approach 1:
The patent segments the key sharing process into distinct phases and components: key sharing requests, key sharing responses, home zone identification, and remote zone identification. This segmentation allows the system to maintain zone isolation while enabling controlled key sharing. Each segment handles a specific aspect of the key transfer, ensuring that security boundaries are respected while still allowing the necessary key sharing functionality to occur through the structured protocol.
Data Source
AI summary
The solutions disclosed enable security credentials to be shared between two entities. Embodiments of the present invention can be used to facilitate the transfer security credentials associated with a first level of permission of a first entity to a second entity that does not have the security credentials associated with the first level of permission in response to receiving a request to share security credentials between two entities.


