Trusted Authority Key Management for Secure Device Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption methods for secure data transmission between independent devices, such as mobile equipment and smart cards, face challenges in ensuring correct key matching and authentication due to conflicting market interests between device manufacturers and service operators, leading to compromised identification and authentication processes.

Innovation Solution

The method involves two distinct Trusted Authorities associated with each device, which generate and manage secret keys independently, allowing for encrypted communication between devices without the need for a shared supervisory authority, using identity-based encryption and symmetrical or asymmetric cryptographic methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a shared Certification Authority is used to manage keys between devices from different manufacturers, then key authentication can be standardized, but market interests of independent manufacturers and operators conflict and compromise security

Engineering Contradiction:
Improvekey authentication reliabilityVSAvoidmarket independence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the authentication authority into multiple independent Trusted Authorities, each associated with a specific device or operator. Instead of a single centralized CA, each device has its own TA that can independently generate and manage keys, eliminating the conflict between standardized authentication and market independence.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each Trusted Authority serves itself and its associated device independently without requiring other TAs. The TAs autonomously generate keys, authenticate devices, and establish encrypted communications without needing to trust or coordinate with other authorities, enabling market independence while maintaining authentication reliability.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If independent Trusted Authorities are used for each device, then market interests are protected and no shared database is needed, but key matching and authentication complexity increases

Engineering Contradiction:
Improvemarket independenceVSAvoidauthentication process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication process is simplified because each TA independently performs all authentication functions without needing to query shared databases or coordinate with other authorities. The self-service nature eliminates complex inter-authority communication and database synchronization, reducing overall system complexity despite multiple independent authorities.

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional PKI with Certification Authority is used, then key authenticity can be guaranteed, but the system requires shared databases and supervisory authorities that compromise security

Engineering Contradiction:
Improvekey authenticityVSAvoidshared database vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The invention extracts and removes the centralized shared database and supervisory authority from the PKI system. Each Trusted Authority operates independently with its own key management, eliminating the single point of failure and security vulnerability associated with shared databases while maintaining key authenticity through independent cryptographic verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The centralized PKI authority is segmented into multiple independent Trusted Authorities, each managing its own keys and authentication processes. This segmentation eliminates the need for a shared database that stores all keys centrally, distributing key management across independent entities to reduce security vulnerabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7716483B2Method for establishing a communication between two devices
Publication Date: 2010.05.11 STMICROELECTRONICS SRL
  • US7716483B2 patent drawing
  • US7716483B2 patent drawing
  • US7716483B2 patent drawing

AI summary

A method establishes a communication between a first electronic device associated with a first trusted authority and a second electronic device. The method includes: making a first key available to the first device for the communication between the first authority and the first device. A second trusted authority, associated with the second device and distinct and autonomous with respect to the first authority, generates a second key in order to communicate with the second device. Furthermore, the method includes: making the second key available to the second device; and providing the first and second devices with a communication key, to be used communication between the first and second devices, through at least one of the first and second authorities.