Touchless Key Provisioning via Symmetric TKP Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing voice and data communications require physical contact with key delivery devices for provisioning secret keys to multiple devices, which is inconvenient and costly, necessitating a more efficient and cost-effective alternative.

Innovation Solution

A touchless key provisioning method using a key management facility that imports a public key and assigns a key encryption key, deriving a symmetric touchless key provisioning key to encrypt and transmit the key encryption key to communication devices for decryption, eliminating the need for physical contact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If physical contact with key delivery device is used to provision secret keys, then security is maintained, but operational convenience and efficiency deteriorate due to manual contact requirements for each device

Engineering Contradiction:
Improvekey provisioning convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical contact-based key delivery system with a wireless communication system. The key delivery device communicates with target devices through wireless signals, eliminating the need for physical contact while maintaining security through encrypted communication channels. This substitution resolves the contradiction by improving operational convenience without compromising security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary key delivery device that acts as a mediator between the key management system and target devices. This intermediary handles the secure transmission of keys wirelessly, allowing operators to provision multiple devices without direct physical contact. The intermediary maintains security protocols while enabling efficient key distribution to multiple devices simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If key delivery device is used for each target device, then secure key delivery is achieved, but device complexity and cost increase due to multiple hardware components

Engineering Contradiction:
Improvesecure key deliveryVSAvoidhardware components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designs the key delivery device with multi-functionality, allowing it to serve multiple target devices sequentially or simultaneously through wireless communication. The same hardware unit can provision keys to different devices without requiring separate dedicated hardware for each target device. This universality reduces overall system complexity and cost while maintaining secure key delivery capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines multiple key delivery operations into a single unified system. Instead of requiring separate hardware components for each key delivery operation, the system merges these functions into one key delivery device that can handle multiple devices through software-controlled wireless communication. This merging reduces hardware complexity while preserving security through integrated key management.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If physical contact method is used for key provisioning, then security is maintained, but productivity deteriorates due to time-consuming manual process for multiple devices

Engineering Contradiction:
Improvekey provisioning efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent enables continuous key provisioning operations through wireless communication. The key delivery device can continuously transmit keys to multiple target devices without interruption or physical reconnection. This continuity significantly improves productivity by eliminating the stop-start nature of manual contact-based provisioning while maintaining security through uninterrupted encrypted communication sessions.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent implements preliminary setup of wireless communication channels and security protocols before actual key provisioning begins. Once established, these preliminary configurations allow rapid sequential key distribution to multiple devices without repeated security handshakes. This preliminary action improves productivity by preparing the system in advance, while security is maintained through pre-configured encrypted channels.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11652625B2Touchless key provisioning operation for communication devices
Publication Date: 2023.05.16 MOTOROLA SOLUTIONS INC
  • US11652625B2 patent drawing
  • US11652625B2 patent drawing
  • US11652625B2 patent drawing

AI summary

A system and process for performing a touchless key provisioning operation for a communication device. In operation, a key management facility (KMF) imports a public key and a public key identifier uniquely identifying the public key of the communication device. The public key is associated with an asymmetric key pair generated at the communication device during its factory provisioning and configuration. The KMF registers the communication device and assigns a key encryption key (KEK) for the communication device. The KMF then provisions the communication device by deriving a symmetric touchless key provisioning (TKP) key based at least in part on the public key of the communication device, encrypting the KEK with the symmetric TKP key to generate a key wrapped KEK, and transmitting the key wrapped KEK to the communication device for decryption by the communication device.