Wireless Key Management via Secondary Secure Connection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Provisioning and managing cryptographic keys for communication networks is inefficient and insecure, often requiring user assistance through methods like QR codes or NFC tags.
Innovation Solution
A method using different wireless communication technologies for key management, where a first secure connection with a key management service is established via a second wireless technology, allowing efficient and secure negotiation of authentication information, with a gateway device facilitating communication for devices lacking direct access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user assistance methods (QR codes, NFC tags) are used for key provisioning, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent introduces a key management server as an intermediary that automatically generates, stores, and distributes cryptographic keys between communication devices. This server acts as a trusted mediator that eliminates the need for manual user assistance (QR codes, NFC tags) while maintaining high security standards through automated cryptographic operations and secure key storage mechanisms.
2Productivity
If automated key management is implemented, then productivity is improved, but device complexity is worsened
Solution Approach 1:
The patent extracts the complex key management functionality from individual communication devices and centralizes it in a dedicated key management server. This extraction allows communication devices to have simplified implementations while the server handles the computationally intensive cryptographic operations, key generation, and secure storage, thereby improving overall productivity without significantly increasing device complexity.
Solution Approach 2:
The key management server provides universal key management services to multiple communication devices through a standardized interface. This multi-functional approach allows a single server to serve numerous devices, improving productivity through automation while keeping individual device complexity low by relying on the centralized service for all complex cryptographic operations.
3Reliability
If secure connections are established for key negotiation, then security is improved, but loss of time is worsened
Solution Approach 1:
The key management server performs preliminary key generation and storage actions before actual communication between devices is needed. By pre-establishing cryptographic keys and storing them securely in the server, the system eliminates the need for time-consuming key negotiation during actual communication, thereby improving security while reducing time loss.
4Adaptability or versatility
If gateway devices are used for indirect key negotiation, then adaptability is improved, but device complexity is worsened
Solution Approach 1:
The gateway device acts as an intermediary that enables indirect access to the key management server for devices that cannot establish direct connections. The gateway maintains secure connections with the server and facilitates key negotiation on behalf of other devices, thereby improving adaptability and accessibility while keeping the overall architecture manageable through the use of a trusted mediator.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure relates to a method (60, 70) for performing key management for a plurality of communication devices, each of the plurality of communication devices being configured to perform wireless communication using a first wireless communication technology. The method comprises establishing (S60, S70, S62, S72)), by at least one of the plurality of communication devices, a first secure connection with a key management service using a second wireless communication technology. The method further comprises negotiating (S61, S71, S63, S73), by the at least one communication device with the key management service using the first secure connection, first authentication information comprising a first authentication bundle for secure communication and/or data protection on the first wireless communication technology.