Automated SNMPv3 Key Generation via Digital Certificate Mutual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual configuration of SNMPv3 authentication and privacy keys is cumbersome, error-prone, and exposes keys to security risks, as it requires manual input and is not cryptographically strong, making networks vulnerable to attacks.

Innovation Solution

An automated method using pre-loaded digital certificates for mutual authentication between a management station and a network element, generating and securely transferring SNMPv3 keys via a secure file transfer protocol, eliminating the need for manual configuration and ensuring cryptographically strong keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual configuration of SNMPv3 authentication and privacy keys is used, then the key setup process is simple and direct, but it is cumbersome, error-prone, and exposes keys to security risks

Engineering Contradiction:
Improvekey configuration processVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system automatically generates and distributes SNMPv3 authentication and privacy keys without requiring manual operator input. The management station generates keys and securely transmits them to network elements autonomously, eliminating the security risks and errors associated with manual key configuration while maintaining operational simplicity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A secure file transfer protocol acts as an intermediary mechanism between the management station and network elements during key distribution. This intermediary provides encrypted communication channels that protect keys from exposure to third parties while automating the configuration process

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If manual input of initial keys is used, then the configuration process is straightforward, but it requires communication between administrator and technician which can lead to errors and key exposure

Engineering Contradiction:
Improveconfiguration processVSAvoidkey exposure to third parties
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The management station autonomously generates SNMPv3 keys and distributes them to network elements without requiring administrator-technician communication. This self-service approach eliminates the harmful factor of key exposure during verbal or written key transmission while keeping the configuration process straightforward

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual mechanical process of verbally communicating keys between administrator and technician is replaced with an automated electronic key generation and distribution system. This substitution eliminates the security vulnerability of keys being transmitted through human communication channels

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If automated key generation and secure transfer is used, then security is enhanced and keys are cryptographically strong, but the process complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey configuration process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The management station performs multiple functions including key generation, secure storage, and encrypted transmission through a single automated process. This multi-functionality enhances security and cryptographic strength while presenting a unified simple interface that masks the underlying process complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The management station pre-generates cryptographically strong keys and stores them securely before transmission. This preliminary action ensures cryptographic strength and security are built into the system architecture, with the complexity hidden from end users who only see the simplified configuration interface

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2115931B1AUTOMATED METHOD FOR SECURELY ESTABLISHING SIMPLE NETWORK MANAGEMENT PROTOCOL VERSION 3 (SNMPv3) AUTHENTICATION AND PRIVACY KEYS
Publication Date: 2018.11.07 MOTOROLA SOLUTIONS INC
  • EP2115931B1 patent drawingFigure 1
  • EP2115931B1 patent drawingFigure 2
  • EP2115931B1 patent drawingFigure 3

AI summary

In an SNMP network including a Manager Station having a first digital certificate and an Agent Station having a second digital certificate, the MS generates a simple network management protocol (SNMP) configuration file which includes SNMP authentication keys and SNMP encryption keys for use by the MS and the AS for authentication and for encrypting communications between the MS and the AS, respectively. Mutual authentication can be performed using the first and second digital certificates to establish a secure session between the MS and the AS. The MS can encrypt the SNMP configuration file and transmit it to the AS which can then decrypt the encrypted SNMP configuration file to generate the SNMP authentication keys and the SNMP privacy keys. The MS and the AS can then use the SNMP authentication and privacy keys to conduct secure SNMP communications between the MS and the AS.