Smart Key Mutual Authentication for Secure Cryptographic Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data processing systems face limitations in protecting sensitive information, such as cryptographic keys, as additional layers of security often require protection of new sensitive information, creating a dilemma where each attempt to enhance security introduces more data to be secured.

Innovation Solution

A method involving a pair of smart key devices, where a removable storage media and a hardware security unit mutually authenticate, enabling cryptographic functions within the system unit, with the removable storage media storing a private key of one asymmetric key pair and the hardware security unit storing the corresponding public key, allowing secure management and protection of master secrets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional layers of security are implemented to protect sensitive information, then security protection is improved, but the amount of sensitive information that needs to be secured increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidamount of sensitive information
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines the master secret storage and cryptographic key management functions into a single smart card device. The smart card integrates both the secret information storage and the cryptographic processing capabilities, eliminating the need for separate protection mechanisms for the master secret. This merging approach allows the system to enhance security through integrated hardware enforcement while avoiding the proliferation of additional sensitive information that would result from layered software-based security mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

2Ease of operation

If master secrets are stored in software-based mechanisms, then ease of operation is improved, but security protection deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The smart card acts as an intermediary hardware device that mediates between the software environment and the master secret. Instead of storing the master secret directly in software or requiring physical access to hardware components, the smart card serves as a secure intermediary that holds the master secret and provides cryptographic services through standardized interfaces. This allows software applications to operate conveniently while the hardware-enforced security boundaries protect the master secret from unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If hardware security tokens are used to protect sensitive data, then security protection is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The smart card is designed as a universal security device that performs multiple functions: storing the master secret, generating cryptographic key pairs, signing data, and providing authentication services. By consolidating these diverse security functions into a single multi-functional hardware token, the system achieves strong security protection without proportionally increasing device complexity. The smart card's ability to handle multiple security operations internally reduces the need for additional specialized hardware components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7908492B2Method for using a compact disk as a smart key device
Publication Date: 2011.03.15 META PLATFORMS INC
  • US7908492B2 patent drawing
  • US7908492B2 patent drawing
  • US7908492B2 patent drawing

AI summary

A data processing method accepts a removable storage media, which becomes electrically engaged with a system unit within the data processing system, after which the removable storage media and the hardware security unit mutually authenticate themselves. The removable storage media stores a private key of a first asymmetric cryptographic key pair and a public key of a second asymmetric cryptographic key pair that is associated with the hardware security unit, and the hardware security unit stores a private key of the second asymmetric cryptographic key pair and a public key of the first asymmetric cryptographic key pair that is associated with the removable storage media. In response to successfully performing the mutual authentication operation between the removable storage media and the hardware security unit, the system unit is enabled to invoke cryptographic functions on the hardware security unit while the removable storage media remains engaged with the system unit.