Wireless Key Management via Secondary Secure Connection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Provisioning and managing cryptographic keys for communication networks is inefficient and insecure, often requiring user assistance through methods like QR codes or NFC tags.

Innovation Solution

A method using different wireless communication technologies for key management, where a first secure connection with a key management service is established via a second wireless technology, allowing efficient and secure negotiation of authentication information, with a gateway device facilitating communication for devices lacking direct access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user assistance methods (QR codes, NFC tags) are used for key provisioning, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of key provisioningVSAvoidsecurity of key management
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a key management server as an intermediary that automatically generates, stores, and distributes cryptographic keys between communication devices. This server acts as a trusted mediator that eliminates the need for manual user assistance (QR codes, NFC tags) while maintaining high security standards through automated cryptographic operations and secure key storage mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automated key management is implemented, then productivity is improved, but device complexity is worsened

Engineering Contradiction:
Improveefficiency of key managementVSAvoidcomplexity of key management system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts the complex key management functionality from individual communication devices and centralizes it in a dedicated key management server. This extraction allows communication devices to have simplified implementations while the server handles the computationally intensive cryptographic operations, key generation, and secure storage, thereby improving overall productivity without significantly increasing device complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The key management server provides universal key management services to multiple communication devices through a standardized interface. This multi-functional approach allows a single server to serve numerous devices, improving productivity through automation while keeping individual device complexity low by relying on the centralized service for all complex cryptographic operations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure connections are established for key negotiation, then security is improved, but loss of time is worsened

Engineering Contradiction:
Improvesecurity of communicationVSAvoidtime for key negotiation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The key management server performs preliminary key generation and storage actions before actual communication between devices is needed. By pre-establishing cryptographic keys and storing them securely in the server, the system eliminates the need for time-consuming key negotiation during actual communication, thereby improving security while reducing time loss.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If gateway devices are used for indirect key negotiation, then adaptability is improved, but device complexity is worsened

Engineering Contradiction:
Improveaccessibility to key management serviceVSAvoidcomplexity of gateway architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The gateway device acts as an intermediary that enables indirect access to the key management server for devices that cannot establish direct connections. The gateway maintains secure connections with the server and facilitates key negotiation on behalf of other devices, thereby improving adaptability and accessibility while keeping the overall architecture manageable through the use of a trusted mediator.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4250641B1Method, devices and system for performing key management
Publication Date: 2025.12.24 U-BLOX
  • EP4250641B1 patent drawingFigure 1
  • EP4250641B1 patent drawingFigure 2
  • EP4250641B1 patent drawingFigure 3

AI summary

The present disclosure relates to a method (60, 70) for performing key management for a plurality of communication devices, each of the plurality of communication devices being configured to perform wireless communication using a first wireless communication technology. The method comprises establishing (S60, S70, S62, S72)), by at least one of the plurality of communication devices, a first secure connection with a key management service using a second wireless communication technology. The method further comprises negotiating (S61, S71, S63, S73), by the at least one communication device with the key management service using the first secure connection, first authentication information comprising a first authentication bundle for secure communication and/or data protection on the first wireless communication technology.