One-time password book encryption concentrator
By adopting a centralized OTP encryption solution in a multi-user environment, using routing hubs and OTP hubs for encryption and decryption, the problem of management complexity and security challenges in a multi-user environment is solved, and efficient and secure encrypted message routing is achieved.
Patent Information
- Application Number
- CN202510128702.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2019-01-08
- Filing Date
- 2020-01-08
- Publication Date
- 2025-05-13
AI Technical Summary
One-time password book encryption technology faces security challenges in generation, exchange and processing, especially in a multi-user environment, where a large number of unique password books are required to manage, increasing the complexity and security risks of the system.
The centralized OTP encryption scheme is adopted to route encrypted messages between multiple network users through a routing hub, and encrypt and decrypt using custom OTP, avoiding the need to distribute multiple password books to end users, and centrally handling the generation and distribution of password books through an OTP hub.
It realizes the secure routing of encrypted messages in a multi-user environment, reduces the exposure risk of password book, improves the security and management efficiency of the system, and avoids the redundant needs in the case of hub failure or ineffectiveness.
Smart Images

Figure CN119995857A_ABST
Abstract
Description
[0001] This application is a divisional application of Chinese patent application 202080019017.5, entitled “One-time Password Encryption Hub”, filed on January 8, 2020.
[0002] CROSS-REFERENCE TO RELATED APPLICATIONS
[0003] This application claims the benefit of priority to U.S. Provisional Patent Application No. 62 / 789,636, filed on January 8, 2019, the contents of which are incorporated herein by reference in their entirety. Background Art
[0004] The present invention relates to the field of data encryption.
[0005] In cryptography, a one-time pad (OTP) is an encryption technique that cannot be broken, but requires the use of a one-time pre-shared key that is the same size or longer than the message being sent. In this technique, plaintext is paired with a random key (also called a one-time pad). Each bit or character of the plaintext is then encrypted by combining it with the corresponding bit or character from the pad using one of several functions.
[0006] If the key is truly random, never reused in whole or in part, and kept secret, it should be mathematically impossible to decipher the ciphertext without a copy of the codebook. Because OTP encryption does not add any information to the encrypted text, just random noise, it represents a perfect, unbreakable encryption method.
[0007] However, one-time pad cryptography faces several implementation difficulties. First, the secure generation, exchange, and disposal of OTP material, which must be at least as long as the message, is difficult to achieve. Furthermore, the possibility of interception, copying, or forensic recovery of the pad by a third party would completely compromise the security of the method.
[0008] The above examples of the related art and limitations associated therewith are intended to be illustrative and not exclusive. Other limitations of the related art will become apparent to those skilled in the art upon reading this specification and studying the drawings. Summary of the invention
[0009] The following embodiments and aspects thereof are described and illustrated in conjunction with systems, tools, and methods which are intended to be exemplary and illustrative, not limiting in scope.
[0010] In one embodiment, a system is provided, comprising: at least one hardware processor; and a non-transitory computer-readable storage medium having program instructions stored thereon, the program instructions being executable by the at least one hardware processor to: receive, by a routing hub in a computer network, communications intended for a destination node from a source node, wherein the communications are encrypted using a one-time pad (OTP) associated with the source node, apply, by the routing hub, a custom OTP to the communications, the custom OTP being configured to simultaneously (i) encrypt the communications using the OTP associated with the destination node, and (ii) decrypt the communications using the OTP associated with the source node, and pass the communications to the destination node for decryption using the OTP associated with the destination node.
[0011] In one embodiment, a method is also provided, the method comprising: receiving, by a routing hub in a computer network, communications intended for a destination node from a source node, wherein the communications are encrypted using a one-time password (OTP) associated with the source node; applying, by the routing hub, a custom OTP to the communications, the custom OTP being configured to simultaneously (i) encrypt the communications using the OTP associated with the destination node, and (ii) decrypt the communications using the OTP associated with the source node; and passing the communications to the destination node for decryption of the communications using the OTP associated with the destination node.
[0012] In one embodiment, a computer program product is also provided, which includes a non-transitory computer-readable storage medium having program instructions embodied therein, which program instructions can be executed by at least one hardware processor to: receive, by a routing hub in a computer network, a communication intended for a destination node from a source node, wherein the communication is encrypted using a one-time password (OTP) associated with the source node; apply, by the routing hub, a customized OTP to the communication, the customized OTP being configured to simultaneously (i) encrypt the communication using the OTP associated with the destination node, and (ii) decrypt the communication using the OTP associated with the source node; and pass the communication to the destination node for decryption of the communication using the OTP associated with the destination node.
[0013] In some embodiments, the routing hub includes a series of at least two routing hubs, and wherein, with respect to each pair of routing hubs in the series, the applying includes: applying, by the first routing hub in the pair, a first inter-hub customized OTP to the communication, the first inter-hub customized OTP being configured to simultaneously (i) decrypt the communication with an OTP associated with a previous hop in a route of the communication, and (ii) encrypt the communication with an OTP associated with a second routing hub in the pair; passing the communication to the second routing hub; applying, by the second routing hub in the pair, a second inter-hub customized OTP to the communication, the second inter-hub customized OTP being configured to simultaneously (iii) encrypt the communication with an OTP associated with a subsequent hop in the route of the communication, and (iv) decrypt the communication with the OTP associated with the second routing hub in the pair; and passing the communication to the subsequent hop.
[0014] In some embodiments, each of the hops in the route of the communication is one of: a network node, an end user, a server, a remote server, and an end user.
[0015] In some embodiments, each of the customized OTPs represents a calculated difference between a pair of OTPs.
[0016] In some embodiments, a computer network comprises a plurality of nodes, and wherein each of the nodes stores only an OTP associated with the node.
[0017] In some embodiments, the program instructions are further executable to perform network user authentication based at least in part on the universal hash.
[0018] In some embodiments, at least some of the OTPs are manipulated by overwriting at least a portion thereof with false data.
[0019] In some embodiments, at least some of the routing hubs further comprise at least one of: a random number generator (RNG) and an automated teller machine configured to distribute OTPs to users of the computer network.
[0020] In some embodiments, the OTP is distributed with an automated teller machine using at least one of: quantum key distribution (QKD) communications and a physically secure distribution device.
[0021] In some embodiments, the delivering is based at least in part on a routing table, and wherein the routing table takes into account an OTP usage metric, and wherein the OTP usage metric is a Key Performance Indicator (KPI) with respect to the computer network.
[0022] In one embodiment, a system is also provided, comprising: at least one hardware processor; and a non-transitory computer-readable storage medium having program instructions stored thereon, the program instructions being executable by the at least one hardware processor to: receive, by an OTP hub in a computer network, an indication associated with communications from a first network node to one or more other network nodes, send, by the OTP hub, an OTP to the first network node and to each of the other network nodes, encrypt, by the first node, the communications using the OTP, and transmit, by the first node, the communications to at least one of the one or more other network nodes.
[0023] In one embodiment, a method is also provided, comprising: receiving, by an OTP hub in a computer network, an indication associated with communication from a first network node to one or more other network nodes, sending, by the OTP hub, an OTP to the first network node and to each of the other network nodes, encrypting, by the first node, the communication using the OTP, and transmitting, by the first node, the communication to at least one of the one or more other network nodes.
[0024] In one embodiment, a computer program product is also provided, which includes a non-transitory computer-readable storage medium having program instructions embodied therein, which can be executed by at least one hardware processor to: receive an indication associated with communication from a first network node to one or more other network nodes by an OTP hub in a computer network, send an OTP to the first network node and to each of the other network nodes by the OTP hub, encrypt the communication using the OTP by the first node, and transmit the communication to at least one of the one or more other network nodes by the first node.
[0025] In some embodiments, at least one of the one or more network nodes further decrypts the communication using the OTP.
[0026] In some embodiments, the indication is received from any said network node.
[0027] In some embodiments, each of the network nodes stores an authentication OTP, and wherein the authentication OTP is configured for use in conjunction with two-step user authentication of the network node.
[0028] In some embodiments, the OTP is manipulated by overwriting at least a portion thereof with false data.
[0029] In some embodiments, the OTP hub further comprises at least one of: a random number generator (RNG) and an automated teller machine configured to distribute the OTP to the network nodes.
[0030] In some embodiments, the OTP is distributed with an automated teller machine using at least one of: quantum key distribution (QKD) communications and a physically secure distribution device.
[0031] In addition to the exemplary aspects and embodiments described above, further aspects and embodiments will become apparent by reference to the drawings and by study of the following detailed descriptions. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Exemplary embodiments are illustrated in the referenced drawings. Dimensions of components and features shown in the drawings are generally chosen for convenience and clarity of presentation and are not necessarily shown to scale. The drawings are listed below.
[0033] Figure 1A An exemplary centralized OTP encryption scheme according to one embodiment is shown;
[0034] Figure 1B An exemplary centralized OTP encryption scheme is shown according to one embodiment, wherein an OTP hub is implemented in two or more physical devices;
[0035] Figure 1C An exemplary centralized OTP encryption scheme including two or more separate OTP hubs according to one embodiment is shown;
[0036] FIG. 2A to FIG. 2B An encryption scheme including a two-tier OTP hub arrangement according to one embodiment is shown; and
[0037] Figure 3 A peer-to-peer encryption network is shown according to one embodiment. DETAILED DESCRIPTION
[0038] Disclosed herein is a system, method, and computer program product for secure routing of messages between two or more users using one-time pad (OTP) cryptography.
[0039] As mentioned above, OTP cryptography generally faces significant practical difficulties. First, in order to provide absolute cryptographic stability, OTP must have encryption keys that are truly random, the same size as the message to be encrypted, never reused, and properly disposed of immediately after use. Current random number generators can produce random key material of sufficient quality for use in OTP cryptography. Furthermore, in practice, modern computer systems can store and process the necessary amounts of random key data.
[0040] However, the security of OTP-based cryptographic systems continues to rely on secure codebook handling and distribution, as interception and duplication of codebooks by third parties will compromise the security of the process. This problem is further compounded as the number of communicators in the network increases arbitrarily, as each sender / receiver pair must maintain a unique codebook shared only between the two of them. As the number of network users increases, the number of unique codebooks required increases as a power of two, so that at some point the number of codebooks that need to be maintained by each network component becomes unmanageable.
[0041] Thus, in some embodiments, the present invention provides a centralized OTP encryption scheme in which one or more OTP hubs are responsible for routing encrypted messages between multiple network users. In some embodiments, the OTP encryption scheme of the present invention includes encrypting each bit or character of the plaintext by combining each bit or character of the plaintext with a corresponding bit or character from a codebook using at least one of modular addition, any table commutative group that is an injective or one-to-one transformation function, and / or any other homomorphic function or homomorphic encryption function.
[0042] In some exemplary embodiments, the OTP encryption scheme described herein can be used to implement OTP encrypted communications between multiple sender / receiver end users, for implementing OTP encrypted video / audio conferencing, email exchange, file exchange, multi-party digital telephone voice communication, games, etc. In other exemplary embodiments, the OTP encryption scheme described herein can be used to exchange messages using push-pull network communication technology, including but not limited to unicast messages, multicast messages, and broadcast messages, such as SMS, instant messaging, etc. In other exemplary embodiments, such communications can be implemented via wired and wireless networks and via any number and any kind of gateways and agents. In some embodiments, there can be any number of OTP hubs geographically distributed in various locations and regions. In some embodiments, one or more OTP hubs can be cloud-based OTP hubs. In some embodiments, the disclosed invention can be used to encrypt any type of communication channel, such as end-to-end communication tunnels, publish / subscribe protocol-based communications, TCP / UDP-based communications, and non-TCP communications. The disclosed encryption scheme can also be used in addition to any other data protection technology such as TLS / SSL.
[0043] In some embodiments, the OTP hub of the present invention can be implemented in hardware only, software only, or a combination of hardware and software. For example, the OTP hub can be a personal computer, a tablet computer, a smart phone, an embedded device, a handheld device coupled to a radio module, a hidden device, a device with electronic circuits, etc. In some embodiments, the OTP hub may include one or more hardware processors and a non-transitory computer-readable storage device. In various embodiments, the OTP hub may include one or more dedicated hardware devices, one or more software modules, and / or may form an addition or extension to an existing device. In some embodiments, the centralized OTP hub includes more than one separate hardware device, wherein no single hardware device retains all the codebooks required to decrypt any message.
[0044] In some embodiments, one or more dedicated hardware devices may be located in different locations. The storage medium of the OTP hub may encode software instructions thereon or be configured to operate a component of one or more hardware processors. In some embodiments, the software component may include an operating system, which includes various software components and / or drivers for controlling and managing general system tasks (e.g., memory management, storage device control, power management, etc.) and facilitating communication between various hardware and software components. In some embodiments, the program instructions are divided into one or more software modules, which may include, for example, an encryption / decryption module, a communication module, and a user interface module.
[0045] In some embodiments, by centralizing codebook distribution and retention in an OTP hub, the present invention also avoids the need to distribute multiple codebooks to end users, thereby potentially exposing the codebooks to malicious misappropriation and compromising overall system security. Thus, system-wide codebooks need only be distributed to a wired number of OTP hubs, which can be handled through secure electronic and / or physical distribution.
[0046] In some embodiments, the present invention provides a two-tier OTP processing arrangement, in which one or more routing OTP hubs are only responsible for message encryption / decryption and routing between network users, while one or more other network nodes, such as local or external OTP hubs, and / or cloud-based servers, etc., are responsible for storing and / or generating appropriate codebooks for use by one or more routing OTP hubs.
[0047] In some embodiments, codebook generation may be done on demand based on requests from one or more users of the network and / or a routing OTP hub. In some embodiments, such a two-tier arrangement may be configured for secure routing of messages between one or more user clusters in a remote network.
[0048] In some embodiments, the present invention provides a peer-to-peer OTP encryption scheme between multiple network users.
[0049] In some embodiments, the network of the present invention provides multiple possible encrypted message routes between each sender / receiver pair to ensure redundancy in the event of a hub failure or non-functioning.
[0050] In some embodiments, the present invention also provides for optimizing OTP-based message routing between multiple users and / or networks based on minimizing OTP usage metrics and / or additional routing parameters. In some embodiments, OTP usage metrics can also be used as key performance indicators (KPIs) for operational issues.
[0051] In some embodiments, the present invention also provides one or more of random number generation, message authentication, secure OTP key distribution to end users, and / or secure OTP key handling.
[0052] Therefore, one potential advantage of the present invention is that it provides a practical real-world OTP-based encryption scheme that is optimized for local and / or remote multi-user environments while ensuring secure codebook handling and distribution.
[0053] Figure 1A An exemplary centralized OTP encryption scheme according to one embodiment is shown. OTP hub A retains a corresponding code book associated with each network user (e.g., sender 1 and receiver 2). OTP hub A receives a message encrypted with the sender code book from sender 1. OTP hub A then encrypts the message with the receiver code book and removes the sender code book in each case using the corresponding code book retained by hub A and transmits the message to the receiver. Therefore, sender 1 and receiver 2 can communicate through hub A without each person retaining both of their corresponding code books.
[0054] In some embodiments, OTP hub A may be configured to first encrypt the message using the receiver codebook and then remove the sender codebook to ensure that the message is never left unencrypted by any network component.
[0055] As described above, in some embodiments, the OTP hub of the present invention, such as OTP hub A, can be implemented on a server. In some embodiments, such a server can include one or more physical devices, and / or a distributed system with more than one hardware processor and associated storage media. In some embodiments, one or more OTP hubs can be implemented on a single hardware device, and / or one or more OTP hubs can be implemented on more than one separate hardware device, wherein no single hardware device retains all the codebooks required to decrypt any message.
[0056] Figure 1B An exemplary centralized OTP encryption scheme is shown, in which an OTP hub A is implemented in two or more separate hardware devices (e.g., parts A1 and A2), each of which retains a different set of end-user codebooks. For example, part A1 can receive a message encrypted with a sender codebook and encrypt the message with a receiver codebook. The message is then transmitted to a second part A2, in which the sender codebook is removed and the message is transmitted to a receiver having only the receiver codebook. This configuration provides greater security because no single physical device possesses all the codebooks required to decrypt any message. In addition, as described above, when a message is forwarded through separate hardware devices, the message itself remains encrypted with at least one codebook at all times.
[0057] Figure 1C An exemplary centralized OTP encryption scheme including two or more separate OTP hubs is shown. In this configuration, messages can be routed through multiple hubs (e.g., hubs A and B). Each inter-hub jump involves encrypting the message with the inter-hub codebook, and only thereafter, removing the previous codebook. For example, a jump from hub A to hub B involves encrypting the message with the inter-hub codebook unique to the AB pair, and only thereafter removing the sender codebook. Once the message reaches the last hub in the chain (hub B in this example), the message is encrypted with the receiver codebook, and the most recent inter-hub codebook is then removed.
[0058] In all configurations of the present invention, in which message transmissions are to be re-encrypted with a different cipherbook, the OTP hub or any equivalent server, network component and / or network node is configured to first encrypt the transmission with a subsequent cipherbook before removing the existing cipherbook so that the transmission always retains at least one layer of encryption.
[0059] In some embodiments, the present invention provides for customized "delta" codebooks, the application of which to a transmission has the effect of encrypting the transmission with the subsequent codebook and removing the existing codebook.
[0060] In some embodiments, the encryption / removal is simultaneous. In some embodiments, the encryption / removal is sequential, where an 'incremental' codebook first encrypts the transmission with a subsequent codebook, and then removes the existing codebook. In some embodiments, the sequential encryption and removal is performed on the fly. In some embodiments, the application of an 'incremental' codebook ensures that the transmission remains encrypted at all times. In some embodiments, a custom 'incremental' codebook is generated on demand by a node of the network in response to a request and / or instruction related to a transmission between users of the network.
[0061] refer to Figure 2A In some embodiments, the centralized OTP encryption scheme of the present invention can be configured as a two-tier arrangement, where one or more routing OTP hubs are responsible for message encryption / decryption and routing between network users, and another network node, such as a local or external OTP hub, and / or a cloud-based server, etc., is responsible for warehousing and / or generating appropriate codebooks for use by one or more routing OTP hubs. In some embodiments, codebook generation can be done on demand for a specific combination of sender / one or more receivers based on a request from one or more users of the network and / or the routing OTP hub. In some embodiments, such a two-tier arrangement can be configured for secure routing of messages between one or more user clusters in a remote network.
[0062] In some embodiments, the two-tier arrangement can provide several benefits, including increased codebook security. This can be achieved by ensuring separation between the network routing hub and the codebook processing hub. For example, this means that the codebook cannot be stolen by hacking into the network routing hub, which handles network communications and is therefore more susceptible to intrusion attempts. In contrast, the OTP hub does not represent a conventional network access point and is therefore less susceptible to intrusion attempts. In addition, in most cases, the codebook created by the OTP hub will be a customized 'incremental' codebook configured for combined encryption / decryption of messages, and therefore cannot be used for decryption alone.
[0063] So when sending a message from user 1 to user 2, you can continue to refer to Figure 2A Follow these steps:
[0064] (i) User 1 sends a message encrypted with User 1's password to Routing OTP Hub A, where the message is intended for User 2;
[0065] (ii) Network Node B is informed of the expected message from User 1 to User 2, e.g. via Routing OTP Hub A and / or any other network user, node or component;
[0066] (iii) Network node B generates and sends to routing OTP hub A a packet representing the expected transmission as OTP. NEW A custom 'increment' that, when applied to a transmission, will have the effect of applying User 2's codebook and removing User 1's codebook simultaneously or sequentially (e.g., an 'increment' codebook may be described as an OTP NEW =OTP USER 2–OTP USER 1).
[0067] (iv) Routing OTP Hub A receives OTP NEW and applies it to the transmission, and then sends the transmission to User 2 such that the transmission is encrypted only with User 2's codebook, where User 2 is able to decrypt the transmission using its own codebook.
[0068] In some embodiments, the 'incremental' codebook of the present invention may work as follows: Given a message A{0x2A}, OTP1{0x39}, and OTP2{0xB6}, if the encryption operation is done bitwise XOR (exclusive OR), then encryption and decryption are the same operation of bitwise XOR. Therefore, a message A encrypted with OTP1 may be represented as:
[0069]
[0070] Similarly, message A encrypted with OTP2 can be expressed as:
[0071]
[0072] As shown below, this result is mathematically equivalent to having message A1 encrypted with OTP2, and then the encrypted message further decrypted (encrypted) with OTP1:
[0073]
[0074] This is further mathematically equivalent to having a custom 'increment' codebook OTP NEW Simply encrypting message A1, the 'increment' codebook represents the difference between OTP1 and OTP2:
[0075]
[0076] Therefore, if message A1 uses OTP NEW The result is as expected, equal to simply encrypting message A with OTP2 first:
[0077]
[0078] In some embodiments, the method can be applied not only by using a bitwise XOR operation, but also by a Vernam-like cipher operation, for example. If the symbols are bytes and the operation is a circular shift of the symbols as a set of symbols with ascending order, when encryption is circularly shifted in one direction and decryption is shifted in the other direction. This means that encryption is first adding 256 and then modulo 256, and decryption is adding 256 minus the value of the symbol and then modulo 256. Therefore, for A{0x2A}, OTP1{0x39} and OTP2{0xB6}, then:
[0079] A1=mod(A+OTP1,256)=mod({0x2A}+{0x39},256)={0x63}
[0080] A2=mod(A+OTP2,256)=mod({0x2A}+{0xB6},256)={0xD0}
[0081] As shown below, this result is mathematically equivalent to having message A1 encrypted with OTP2, and then the encrypted message further decrypted with OTP1:
[0082] A2=mod(mod(A1+OTP2,256)+256-OTP1,256)=
[0083] =mod(mod({0x63}+{0xB6},256)+256-{0x39},256)={0xD0}.
[0084] This is further mathematically equivalent to having a custom 'increment' codebook OTP NEW Simply encrypting message A1, the 'increment' codebook represents the difference between OTP1 and OTP2:
[0085] OTP NEW =OTP2–OTP1=mod(OTP2+256-OTP1,256)=mod({0xB6}+256-{0x39},256)={0x7D}.
[0086] Therefore, if message A1 uses OTP NEW The result is, as expected, equal to simply encrypting message A with OTP2 first:
[0087] mod(A1+OTP NEW ,256)=mod({0x63}+{0x7D},256)={0xD0}.
[0088] In an exemplary embodiment, for added security, Figure 2A The network node B in the hub can also apply the inter-hub code book to the OTP NEW , so that the transmission between network node B and routing OTP hub A is further encrypted with another layer of encryption unique to AB.
[0089] Figure 2B Shows the use of Figure 2A A two-layer arrangement similar to the arrangement shown in is configured for the centralized OTP encryption scheme of the present invention for secure transmission of messages across user clusters in a remote network.
[0090] Therefore, when sending a message from user 3 to user 6, the following steps may occur:
[0091] (i) User 3 in the first cluster I sends a message encrypted with the user 3 codebook through the routing OTP hub A of cluster I, where the message is intended for user 6 in the second cluster II;
[0092] (ii) a first network node B associated with cluster 1 is informed of the expected message from user 3 to user 6, e.g., via routing OTP hub A of cluster 1, and / or any other network user, node or component;
[0093] (iii) Network Node B generates and sends a unique codebook OTP for the intended transmission to Routing OTP Hub A NEW 3, when applied to a transmission, this codebook will have the effect of simultaneously or sequentially applying the inter-cluster codebook for secure transmission to the routing OTP hub C of cluster II and removing the codebook of user 3 (e.g., a unique codebook may be described as OTP NEW 3=OTP C –OTP USER 3);
[0094] (iv) Routing OTP Hub A receives OTP NEW 3, and applies it to the transmission, and then sends the transmission to the routing OTP hub C of cluster II;
[0095] (v) Then, a second network node D associated with cluster II prepares and sends a second unique codebook OTP for the intended transmission to the routing OTP hub C. NEW 6, when applied to a transmission, this second unique codebook will have the same or sequential application of user 6 codebook and remove the OTP C The effect (for example, OTP NEW 6=OTP USER 6–OTP C );as well as
[0096] (vi) Routing OTP Hub C receives OTP NEW 6 and applies it to the transmission, and then sends the transmission to user 6 so that the transmission is encrypted only with user 6's codebook.
[0097] In an exemplary embodiment, for increased security, network nodes B and D may also apply the inter-hub codebook to the OTP respectively. NEW 3 and OTP NEW 6, so that the transmission between network node B and routing OTP hub A and the transmission between network node D and routing OTP hub C are further encrypted with another layer of encryption unique to the specific pair.
[0098] In some embodiments, the present invention may be configured to provide a peer-to-peer OTP encryption scheme between multiple network users, where secure messages can be passed directly between pairs of end users without being routed through one or more OTP hubs. The term "directly" refers to the direct transmission of data between users' devices without any intermediary devices, or more commonly, the transmission from the user through the network - where the server through which the transmission passes is not an OTP hub, but a standard network node. In some embodiments, on-demand passwords can be generated and / or stored by, for example, an OTP hub of the present invention, and provided to relevant end users to facilitate secure transmission. That is, the provision of OTP can be provided by a hub that does not participate in the actual transmission of encrypted messages between the two parties. In some embodiments, the OTP hub can be a local network component, can be part of a remote network, or can be a cloud-based OTP hub.
[0099] Thus, when sending a message from User 1 to one or more other network users (e.g., User 2 and User 3), the following steps may be performed:
[0100] (i) may be, for example, a cloud-based OTP hub A informed of an expected message from user 1 to user 2, for example via any network user, node or component;
[0101] (ii) OTP Hub A generates the appropriate codebook OTP X , and sends it to User 1, User 2, and User 3 as an encrypted message; and
[0102] (iii) User 1 can then use the OTP X Transmit the encrypted message to User 2 and User 3, who can then use the OTP X Decrypts the received message.
[0103] In some embodiments, the centralized OTP encryption scheme of the present invention may provide multiple OTP hubs, wherein each OTP hub is provided with a set of designated end-user codebooks associated with at least some of the end users of the network. Such a multi-hub network may provide multiple routing paths between each pair of users and thus provide redundancy in the event of, for example, hub failure and / or selection of optimal routes to, for example, optimize hub codebook usage. In some embodiments, one or more routing algorithms may be implemented to select appropriate and / or optimized routes. In some embodiments, OTP usage metrics may also be used as KPIs for operational issues.
[0104] In some embodiments, by increasing the number of hubs in the network and / or the number of codebooks per hub, greater routing redundancy is created within the network.
[0105] In some embodiments, two or more hubs maintaining a codebook for the same user may be provided with different versions of the user's codebook in order to avoid different hubs retaining the same codebook.
[0106] In some embodiments, two or more secure networks of the present invention can provide inter-network communication by providing a shared key book to each hub in each network. In some embodiments, each hub in the network can retain a different shared key book to avoid duplication of the shared key book across multiple hubs. The shared key book can be stored in a separate dedicated hub or multiple dedicated hubs (e.g., for redundancy purposes) for inter-network connections, or can be stored by a conventional hub.
[0107] Message routing optimization
[0108] In some embodiments, as described above, the present invention provides a communication network layout having multiple optional message routes from sender to receiver through one or more hubs within the network and / or through one or more remote networks. In some embodiments, this can provide redundancy in the event of a hub failure, for example.
[0109] In some embodiments, the present invention may also be configured to optimize message routing based on specified criteria, including but not limited to based on OTP usage metrics. In some embodiments, additional and / or other optimization criteria may be used, including network bandwidth, network storage capacity, network latency, OTP hub hop count, path actual usage cost, load, MTU (maximum transmission unit), reliability, and / or communication cost. In some embodiments, OTP usage metrics may also be used as KPIs for operational issues.
[0110] Because OTP is a consumable resource, the hub ( FIG. 2A to FIG. 2B ) and / or network clusters ( Figure 3 ) involves the use and consumption of at least a portion of one or more OTPs. Therefore, in some embodiments, optimized routing is configured to minimize OTP usage along the route, for example, by minimizing the number of hops between hubs and / or network clusters. In some embodiments, the present invention can be configured to calculate the route from the sender to the receiver with the minimum total OTP usage metric. In some embodiments, the OTP usage metric can also be used as a KPI for operational issues.
[0111] As background, in the context of computer networks, message routing is the process of selecting a path for traffic within a network or across multiple networks. In packet-switched networks, routing typically involves forwarding packets based on routing tables, which maintain records of routes to various network destinations. A routing table or routing information base (RIB) is a table of data stored in a network node (e.g., a router, networked computer, or server) and lists routes and associated metrics (such as distance, operating cost, or delay) to a specific network destination. A routing table contains information about the topology of the network immediately surrounding it that is constructed using routing protocols based on manual input, such as during network initialization. For example, a routing table may contain a network / next hop association that tells a router that a specific network destination can be best reached by sending a packet to a specific router that represents the "next hop" on the way to the final destination. In some cases, one or more remote networks may be added to a routing table during initialization or by a dynamic routing protocol.
[0112] However, because the route optimization metric in the current case involves dynamic consumable resources, route optimization cannot be determined based on a static routing table. Therefore, in some embodiments, the centralized encryption scheme of the present invention can be configured to generate a routing table, wherein each network node, such as an OTP hub and / or an end user, can be configured to collect information about all other network nodes to which it can be connected. In some embodiments, each network node can then independently assemble this information into a routing table and / or a network map. In some embodiments, based on these separate routing tables, each network node can use one or more known shortest path algorithms, such as distance vector algorithms (e.g., Bellman-Ford algorithm, Dijkstra's algorithm, Viterbi algorithm), list short path algorithms, path vector protocols, etc. to independently determine the minimum cost path from itself to each other node. The result can be a tree graph with the current node as the root, so that the path through the tree from the root to any other node is the minimum cost path to the node. Then, the tree is used to build a routing table that specifies the best next hop from the current node to any other node.
[0113] In some embodiments, the communication network of the present invention may provide a centralized message routing control that may be used to manage routing in the network or any portion thereof. In this case, OTP usage metrics determined by one or more network nodes may be communicated to the control function, which may then determine the routing path. In some embodiments, OTP usage metrics may also be used as a KPI for operational issues.
[0114] In some embodiments, the optimized route can be determined based solely on the codebook usage matrix and / or represent a combination of multiple parameters, including but not limited to bandwidth, network latency, hop count, path actual usage cost, load, MTU (maximum transmission unit), reliability and / or communication cost. In some embodiments, the OTP usage metric can also be used as a KPI for operational issues.
[0115] Message Authentication
[0116] In some embodiments, the present invention provides positive identification and authentication of end users in a network.
[0117] As mentioned above, in OTP-based encryption schemes, user authentication is crucial because an end-user's password book may be stolen and / or copied by a bad actor and then used to impersonate the actual user of the network.
[0118] One-time pads do not inherently provide message authentication, and this lack of authentication can pose a security threat to real-world applications. Direct XOR with a keystream creates potential vulnerabilities in message integrity that are particularly easy to exploit. For example, an attacker who knows that a message contains the string "Meet Jane and me tomorrow at 3:30 PM" at a specific point in time can replace that content with any other content of exactly the same length, such as "3:30 meeting canceled, stay home", without having access to the one-time pad.
[0119] Thus, in some embodiments, the present invention provides a user authentication code book that is stored by a user and can be used to authenticate and verify the user, for example in the event that the original user code book has been compromised.
[0120] For example, when a user joins the network of the present invention, a primary authentication one-time password (PAOTP) can be assigned to the user, which can be provided on, for example, a physical portable memory device, such as a memory card or a key disk. A copy of the PAOTP can also be saved to one or more centralized OTP hubs of the network, and / or can be split between two or more OTP hubs so that each split is different from the other parts. When communicating within the network for the first time, for example, a portion of the PAOTP can be used for initial identification and authentication. At the time of initial authentication, the used portion of the PAOTP can then be discarded. The user can then receive a runtime password book for use in regularly performed communications over the network. The PAOTP can then be saved by the user in a safe place in case it may be needed again for future two-step authentication of the user.
[0121] During ongoing runtime network communications, users can be identified by using portions of a runtime password book. However, in some cases, a stronger two-step verification process is required. For example, a user may wish to revoke a runtime user password book, or the network may require a user to update / replace their runtime password book, such as in the case of suspicious activity. In this case, POTP can be used to authenticate the end user.
[0122] In some embodiments, universal hashing can also be used as an additional authentication mechanism. Universal hashing provides a method to authenticate messages up to arbitrary security boundaries (i.e., for any p>0, a sufficiently large hash ensures that even a computationally unbounded attacker has a probability of successful forgery less than p). However, universal hashing comes at the cost of using additional random data from the encryption codebook.
[0123] Random Number Generation
[0124] In some embodiments, OTPs for use in conjunction with the present invention may be generated in a variety of locations, including but not limited to within an OTP hub or in a centralized location.
[0125] In some embodiments, one or more of the OTP hubs may include devices and / or functionality responsible for generating large amounts of true random data. In some embodiments, random data generation may be based on one or more physical processes, such as microscopic phenomena such as thermal noise, the photoelectric effect, other quantum phenomena, chaotic mechanics, and / or any other similar processes. In some embodiments, the present invention may provide for testing random data generated as described below, such as by entropy and similar tests.
[0126] ATM for OTP delivery
[0127] In some embodiments, the present invention may utilize a physical distribution network, such as an automated teller machine (ATM) and / or similar safe deposit mechanism, for the delivery and distribution of OTPs to end users. For example, such an ATM may distribute an external memory device, such as a key disk, containing the OTP. In some embodiments, the ATM of the present invention may have a hard drive containing the OTP, distributed to an external memory device, such as a portable memory device (e.g., a flash drive) provided by a user. In some embodiments, the ATM of the present invention may be configured to generate the OTP locally using suitable random data generation hardware, and / or be provided with an externally generated OTP, such as through an OTP hub. The ATM may also be responsible for the OTP hub of the OTP update system for distribution to end users.
[0128] In some embodiments, in addition to OTP generation capabilities, one or more of the OTP hubs of the present invention may include an ATM. Each such OTP hub may form an independent physical security device that generates and distributes OTPs to end users and then handles the resulting encrypted traffic for the network. Thus, a centralized OTP encryption scheme may be established from any desired location using one or more such devices.
[0129] In some embodiments, the stand-alone ATM of the present invention can be located in various desired locations to distribute OTPs to end users as needed. The OTP can then be generated locally within the ATM and / or remotely and securely delivered to the ATM for further distribution to the end users in that location. The secure delivery of the OTP with the ATM can be performed by quantum key distribution (QKD) communications and / or, for example, physical security devices such as security vehicles and / or containers. The end user can then access the ATM to obtain the OTP by, for example, loading a memory device or exchanging a memory device. Once assigned to a user, the OTP can be represented by the system as being associated with the user and used to route messages to the user.
[0130] In some embodiments, the OTP may be delivered directly to an OTP hub and / or end user via QKD and / or a physical security device (such as a secure vehicle and / or container).
[0131] QKD is the process of using quantum communication to establish a shared key between two parties without a third party knowing anything about that key, even if the third party can eavesdrop on all communications between the two parties. Thus, the QKD key can be used to deliver the OTP to a specific defined destination in this system.
[0132] OTP Disposal
[0133] As mentioned above, the used OTP must be deleted and disposed of to prevent any misappropriation. In some embodiments, the OTP of the present invention may be disposed of by overwriting all or part of the OTP with false data.
[0134] The present invention may be a system, a method and / or a computer program product. The computer program product may include a computer-readable storage medium (or multiple media) having computer-readable program instructions thereon for causing a processor to perform various aspects of the present invention.
[0135] A computer-readable storage medium may be a tangible device that can retain and store instructions for use by an instruction execution device. A computer-readable storage medium may be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: a portable computer floppy disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device having instructions recorded thereon, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium should not be interpreted as a transient signal itself, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagated through a waveguide or other transmission medium (e.g., a light pulse through a fiber optic cable), or an electrical signal transmitted through a wire. In contrast, a computer-readable storage medium is a non-transient (i.e., non-volatile) medium.
[0136] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in the corresponding computing / processing device.
[0137] The computer-readable program instructions for performing the operation of the present invention can be assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages, such as Java, Smalltalk, C++, etc., and traditional process programming languages, such as "C" programming language or similar programming languages. The computer-readable program instructions can be executed completely on the user's computer, partially on the user's computer, as an independent software data packet, partially on the user's computer and partially on a remote computer or completely on a remote computer or server. In the latter case, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, by using the Internet of an Internet service provider). In some embodiments, the electronic circuit including, for example, a programmable logic circuit, a field programmable gate array (FPGA) or a programmable logic array (PLA) can execute the computer-readable program instructions to personalize the electronic circuit by utilizing the state information of the computer-readable program instructions, so as to perform various aspects of the present invention.
[0138] Various aspects of the present invention are described herein with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to embodiments of the present invention. It will be understood that each box of the flowchart and / or block diagram, and the combination of each box in the flowchart and / or block diagram can be implemented by computer-readable program instructions.
[0139] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device create a device for implementing the functions / actions specified in the flowchart and / or block diagram (one or more) square blocks. These computer-readable storage instructions can also be stored in a computer-readable storage medium, which can guide a computer, a programmable data processing device, and / or other devices to operate in a specific manner, so that the computer-readable storage medium having instructions stored therein includes an article of manufacture, which includes instructions for implementing various aspects of the functions / actions specified in the flowchart and / or block diagram (one or more) square blocks.
[0140] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing device, or other device, so that a series of operational steps to be performed on the computer, other programmable device, or other device produces a computer-implemented process, so that the instructions executed on the computer, other programmable device, or other device implement the functions / actions specified in the flowchart and / or block diagram (one or more) boxes.
[0141] The flow chart and block diagram in the accompanying drawings illustrate the architecture, function and operation of the possible implementation of the system, method and computer program product according to various embodiments of the present invention. In this regard, each square block in the flow chart or block diagram can represent the part of module, segmentation or instruction, which includes one or more executable instructions for implementing the specified (one or more) logical functions. In some alternative embodiments, the function marked in the square block may not occur in the order marked in the figure. For example, according to the function involved, the two square blocks shown in succession can actually be performed substantially at the same time, or sometimes these square blocks can be performed in reverse order. It will also be noted that each square block of the block diagram and / or flow chart illustration, and the combination of the square blocks in the block diagram and / or flow chart illustration can be implemented by a system based on special-purpose hardware, and these systems based on special-purpose hardware perform specified functions or actions, or perform a combination of special-purpose hardware and computer instructions.
[0142] The description of various embodiments of the present invention is presented for the purpose of illustration, but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terms used herein are selected to best explain the principles of the embodiments, practical applications, or technical improvements over technologies found in the marketplace, or to enable other persons of ordinary skill in the art to understand the embodiments disclosed herein.
Claims
1. A system, comprising: at least one hardware processor; and a non-transitory computer-readable storage medium having stored thereon program instructions executable by the at least one hardware processor to: notifying at least one network node (B, D) of an intended communication from a source node (1, 3) to a destination node (2, 6) via at least one routing hub (A, C) in a computer network, receiving, by said at least one routing hub (A, C), said communication from said source node, wherein said communication is encrypted using a one-time pad (OTP) associated with said source node; receiving, by the at least one routing hub (A, C), a customized OTP from the at least one network node (B, D), wherein the customized OTP represents a difference between an OTP associated with the source node and an OTP associated with the destination node; applying, by said at least one routing hub (A, C), said customized OTP to said communication to simultaneously (i) encrypt said communication with said OTP associated with said destination node, and (ii) decrypt said communication with said OTP associated with said source node, and The communication is passed to the destination node for decryption of the communication using the OTP associated with the destination node.
2. The system of claim 1, wherein the at least one routing hub comprises a series of at least two routing hubs (A, C), and wherein with respect to each pair of routing hubs in the series, the application comprises: receiving, by a first routing hub (A) of the pair from the at least one network node (B, D), a first inter-hub customized OTP configured to simultaneously (i) decrypt the communication with an OTP associated with a previous hop in a route of the communication, and (ii) encrypt the communication with an OTP associated with a second routing hub of the pair; as well as applying, by the first routing hub in the pair, the first inter-hub customized OTP to the communication; as well as The communication is passed to the second routing hub.
3. The system according to claim 2, wherein the application further comprises: receiving, by a second routing hub (C) of the pair from the at least one network node (D), a second inter-hub customized OTP configured to simultaneously (i) encrypt the communication with an OTP associated with a subsequent hop in the route of the communication, and (ii) decrypt the communication with an OTP associated with the second routing hub of the pair; as well as applying, by the second routing hub (C) in the pair, a second hub-customized OTP to the communication; as well as The communication is passed to the subsequent hop.
4. The system according to any one of claims 1-3, wherein the customized OTP is calculated as a bitwise exclusive OR between the OTP of the source node and the OTP of the destination node.
5. The system according to any one of claims 1-4, wherein the customized OTP is calculated as a Vernam cryptographic operation between the OTP of the source node and the OTP of the destination node.
6. The system of claim 3, wherein each of the hops in the route of the communication is one of: a network node, an end user, a server, a remote server, and an end user.
7. The system of any one of claims 1-6, wherein each of the customized OTPs represents a calculated difference between a pair of OTPs.
8. The system of any one of claims 1-7, wherein the computer network comprises a plurality of nodes, and wherein each of the nodes stores only the OTP associated with the node.
9. The system of any one of claims 1-8, wherein the program instructions are further executable to perform network user authentication based at least in part on a universal hash.
10. The system of any one of claims 1-9, wherein at least some of the OTPs are manipulated by overwriting at least a portion thereof with false data.