Touchless Key Provisioning via Symmetric TKP Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securing voice and data communications require physical contact with key delivery devices for provisioning secret keys to multiple devices, which is inconvenient and costly, necessitating a more efficient and cost-effective alternative.
Innovation Solution
A touchless key provisioning method using a key management facility that imports a public key and assigns a key encryption key, deriving a symmetric touchless key provisioning key to encrypt and transmit the key encryption key to communication devices for decryption, eliminating the need for physical contact.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If physical contact with key delivery device is used to provision secret keys, then security is maintained, but operational convenience and efficiency deteriorate due to manual contact requirements for each device
Solution Approach 1:
The patent replaces the mechanical contact-based key delivery system with a wireless communication system. The key delivery device communicates with target devices through wireless signals, eliminating the need for physical contact while maintaining security through encrypted communication channels. This substitution resolves the contradiction by improving operational convenience without compromising security.
Solution Approach 2:
The patent introduces an intermediary key delivery device that acts as a mediator between the key management system and target devices. This intermediary handles the secure transmission of keys wirelessly, allowing operators to provision multiple devices without direct physical contact. The intermediary maintains security protocols while enabling efficient key distribution to multiple devices simultaneously.
2Reliability
If key delivery device is used for each target device, then secure key delivery is achieved, but device complexity and cost increase due to multiple hardware components
Solution Approach 1:
The patent designs the key delivery device with multi-functionality, allowing it to serve multiple target devices sequentially or simultaneously through wireless communication. The same hardware unit can provision keys to different devices without requiring separate dedicated hardware for each target device. This universality reduces overall system complexity and cost while maintaining secure key delivery capabilities.
Solution Approach 2:
The patent combines multiple key delivery operations into a single unified system. Instead of requiring separate hardware components for each key delivery operation, the system merges these functions into one key delivery device that can handle multiple devices through software-controlled wireless communication. This merging reduces hardware complexity while preserving security through integrated key management.
3Productivity
If physical contact method is used for key provisioning, then security is maintained, but productivity deteriorates due to time-consuming manual process for multiple devices
Solution Approach 1:
The patent enables continuous key provisioning operations through wireless communication. The key delivery device can continuously transmit keys to multiple target devices without interruption or physical reconnection. This continuity significantly improves productivity by eliminating the stop-start nature of manual contact-based provisioning while maintaining security through uninterrupted encrypted communication sessions.
Solution Approach 2:
The patent implements preliminary setup of wireless communication channels and security protocols before actual key provisioning begins. Once established, these preliminary configurations allow rapid sequential key distribution to multiple devices without repeated security handshakes. This preliminary action improves productivity by preparing the system in advance, while security is maintained through pre-configured encrypted channels.
Data Source
AI summary
A system and process for performing a touchless key provisioning operation for a communication device. In operation, a key management facility (KMF) imports a public key and a public key identifier uniquely identifying the public key of the communication device. The public key is associated with an asymmetric key pair generated at the communication device during its factory provisioning and configuration. The KMF registers the communication device and assigns a key encryption key (KEK) for the communication device. The KMF then provisions the communication device by deriving a symmetric touchless key provisioning (TKP) key based at least in part on the public key of the communication device, encrypting the KEK with the symmetric TKP key to generate a key wrapped KEK, and transmitting the key wrapped KEK to the communication device for decryption by the communication device.


