VEKE Protocol for Tactical Group Key Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic key management systems in tactical wireless networks face challenges such as high risk of key compromise, slow over-the-air rekeying, and inefficient use of communication channel bandwidth, particularly in low bandwidth channels, which can be dangerous and impractical under battlefield conditions.

Innovation Solution

The Viral Electronic Key Exchange (VEKE) protocol establishes multiple simultaneous security associations between nodes in a group, allowing parallel operations to distribute a group cryptographic key efficiently across the network, enabling all nodes to potentially act as key distributors and reducing the need for physical key loading.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If current over-the-air rekeying protocols are used, then key distribution can be performed remotely, but the process is slow and consumes significant communication channel bandwidth

Engineering Contradiction:
Improveremote key distributionVSAvoidrekeying time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent segments the key distribution process by establishing multiple simultaneous security associations between the root node and different subsets of group members. Each security association carries a portion of the key material, allowing parallel distribution that reduces overall rekeying time and bandwidth consumption compared to sequential protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from traditional point-to-point or star-topology key distribution to a mesh-like multi-path distribution architecture. By creating multiple simultaneous security associations across different node pairs, the system adds dimensional complexity to the distribution topology, enabling parallel key material transfer that accelerates the process.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If PrePlaced Key (PPK) approach is used, then key material can be distributed manually and securely, but physical key loading is required which is dangerous under battlefield conditions

Engineering Contradiction:
Improvekey distribution securityVSAvoidphysical key loading requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical physical key loading process with an electronic key distribution system. Instead of requiring personnel to physically transport and load key material into devices, the system uses secure electronic transmission through multiple security associations to deliver key material automatically, eliminating the dangerous physical key loading operation while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables automatic key distribution where the root node and group members autonomously establish security associations and exchange key material without requiring manual intervention. This self-service capability allows the network to perform rekeying operations independently, eliminating the need for dangerous physical key loading by personnel in the field.

Inventive Principle:
Principle #25Self-service

3Device complexity

If centralized control station is used for key distribution, then key management is simplified, but the system becomes vulnerable to single point of failure and compromise

Engineering Contradiction:
Improvekey management structureVSAvoidsystem vulnerability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the centralized key distribution function by distributing key management capabilities across multiple nodes in the network. Each node can establish its own security associations and participate in key distribution, eliminating the single point of failure inherent in centralized control while maintaining manageable complexity through standardized protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a centralized vertical key management structure to a distributed horizontal architecture where multiple nodes simultaneously perform key distribution functions. This dimensional shift from single-point control to multi-point distribution reduces vulnerability while preserving operational simplicity through the standardized VEKE protocol framework.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If full intra-mission rekey is performed to revoke group membership, then security is maintained, but the operation is time-consuming and dangerous in battlefield situations

Engineering Contradiction:
Improvesecurity association protectionVSAvoidrekeying duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the rekeying process by allowing selective rekeying of only those security associations that need to be updated or revoked. Instead of performing a complete intra-mission rekey of all group members, the system can target specific nodes or subsets, dramatically reducing the time and operational risk while maintaining security through selective key material distribution.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8873759B2Electronic key management using PKI to support group key establishment in the tactical environment
Publication Date: 2014.10.28 L3HARRIS GLOBAL COMMUNICATIONS INC
  • US8873759B2 patent drawing
  • US8873759B2 patent drawing
  • US8873759B2 patent drawing

AI summary

Method for distributing a group session cryptographic key includes initiating at least one pairwise key distribution session including a root node (100) and at least one communication node (101-107). The method further includes performing at a communication node which has received the group session cryptographic key a propagated pairwise key distribution session with at least one of the communication nodes which has not previously received said group session cryptographic key. The propagated pairwise key distribution sessions are performed at each of the communication nodes which subsequently receives the group session cryptographic key until the group session cryptographic key has been securely provided to all authorized communication nodes.