Method and system for encrypted messaging
The method and system use quantum random number generators to generate symmetric keys for secure communication, addressing vulnerabilities to quantum attacks and improving key management for enhanced security and efficiency.
Patent Information
- Application Number
- JP2023004647
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2022-01-20
- Filing Date
- 2023-01-16
- Publication Date
- 2026-02-12
- Estimated Expiration
- 2043-01-16
AI Technical Summary
Current secure communication methods are vulnerable to quantum computing attacks, lacking resistance and efficiency in key generation and distribution.
A method and system utilizing quantum random number generators to create symmetric master and pairing keys, stored in encrypted containers, for secure communication between client devices, with authentication and key management to enhance resistance to quantum hacking.
Enhances communication security by leveraging quantum randomness for key generation, providing improved resistance to quantum attacks and efficient key management, ensuring secure and efficient encrypted connections.
Smart Images

Figure 0007813041000001 
Figure 0007813041000002
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to methods and systems for encrypted messaging. [Background technology]
[0002] Current methods for secure communication between different data processing devices often use asymmetric encryption keys. Such methods may not generally be resistant to attacks that use quantum computing resources (quantum hacking). A method is needed that allows for secure communication in light of possible quantum-based attacks. Summary of the Invention [Problem to be solved by the invention]
[0003] It is an object of the present disclosure to provide a method and system with improved techniques for communicating messages between data processing devices in a secure manner. [Means for solving the problem]
[0004] To solve that problem, a method and a system for encrypted messaging are provided as set forth in the independent claims.
[0005] According to one aspect, there is provided a method for encrypted message communication in a system including a first client device, a second client device, and a quantum key device including a quantum random number generator, the method comprising the steps of: generating a first quantum random signal by the quantum random number generator; generating a symmetric first master key from the first quantum random signal by the quantum key device; transmitting the first master key to the first client device and storing it in an encrypted first client container within the first client device; generating a first encrypted package by the quantum key device by encrypting a first pairing key of a plurality of symmetric pairing keys assigned to the first client device and the second client device using the first master key; and generating a first encrypted package by the quantum key device by encrypting the first pairing key using the second master key. and generating a second encrypted package by encrypting the first encrypted package using the first master key, and transmitting the first encrypted package to the first client device and the second encrypted package to the second client device; providing a first pairing key to the first client device by decrypting the first encrypted package using the first master key, and providing the first pairing key to the second client device by decrypting the second encrypted package using the second master key; and establishing a first encrypted connection between the first client device and the second client device using the first pairing key.
[0006] According to another aspect, a quantum key device includes a first client device, a second client device, and a quantum key device having a quantum random number generator, and includes the steps of: generating a first quantum random signal by the quantum random number generator; generating a symmetric first master key from the first quantum random signal by the quantum key device; transmitting the first master key to the first client device and storing the first master key in an encrypted first client container in the first client device; generating a first encrypted package by the quantum key device by encrypting a first pairing key of a plurality of symmetric pairing keys assigned to the first client device and the second client device using the first master key; a first master key to generate a second encrypted package by encrypting a first pairing key with a first master key, and transmitting the first encrypted package to a first client device and the second encrypted package to a second client device; providing the first pairing key to the first client device by decrypting the first encrypted package with a first master key and providing the first pairing key to the second client device by decrypting the second encrypted package with a second master key; and establishing a first encrypted connection between the first client device and the second client device using the first pairing key.
[0007] The provided methods and systems may utilize the improved randomness properties of quantum random number generators to generate symmetric master keys and symmetric pairing keys for encrypted communication between data processing devices. Quantum random number generators may provide a degree of "true" randomness that can surpass the output of classical random number generators, especially pseudorandom number generators. Such keys may be significantly more resistant to attacks based on imperfect randomness. The methods and systems may further enable efficient storage, distribution, and control of such quantum-generated symmetric keys. As a result, encrypted message communication between data processing devices may be provided in an improved manner.
[0008] The step of establishing the first encrypted connection may include generating, in one of the first client device and the second client device, a first encrypted message using the first pairing key and sending the first encrypted message to the other of the first client device and the second client device. It may further be specified that a master key (neither the first master key nor the second master key) may not be used to establish the first encrypted connection. It may also be specified that the first master key and the master key may only be used for encrypted communication between the first client device and the quantum key device or between the second client device and the quantum key device.
[0009] Establishing the first encrypted connection may include authenticating the first client device and / or the second client device using the first pairing key.
[0010] The step of authenticating the first client device may include at least one of the following steps: generating, at the first client device, a first authentication code from the first authentication message using a first pairing key; transmitting the second message and the first authentication code from the first client device to the second client device; generating, at the second client device, a second authentication code from the second message using the first pairing key; and comparing, at the second client device, the first authentication code with the second authentication code.
[0011] The step of authenticating the first client device may further include determining, at the second client device, that the first client device is authenticated if the first authentication code and the second authentication code match.
[0012] The step of authenticating the second client device may include at least one of the following steps: generating, at the second client device, a third authentication code from the second authentication message using the first pairing key; transmitting the second authentication message and the third authentication code from the second client device to the first client device; generating, at the first client device, a fourth authentication code from the second authentication message using the first pairing key; and comparing, at the first client device, the third authentication code with the fourth authentication code.
[0013] The step of authenticating the second client device may further include determining, at the first client device, that the second client device is authenticated if the third authentication code and the fourth authentication code match. The step of authenticating the first client device and / or the second client device may enable non-repudiation of authorship of exchanged messages.
[0014] At least one, and preferably each, of the first authentication code, the second authentication code, the third authentication code, and the fourth authentication code may be generated using a cryptographic hash function, which may be, for example, one of MD5, SHA-1, SHA-2, SHA-3, and RIPEMD, or any other suitable cryptographic hash function.
[0015] The steps of generating the first authentication code and generating the second authentication code may each include generating a message hash of the first authentication message and / or generating a pairing key hash of the first pairing key.
[0016] At least one, and preferably each, of the first authentication code, the second authentication code, the third authentication code, and the fourth authentication code may also be generated using a block cipher algorithm, such as one of OMAC (one-key message authentication code) and CCM (counter with cipher block chaining message authentication code).
[0017] At least one, and preferably each, of the first authentication code, the second authentication code, the third authentication code, and the fourth authentication code may be generated using a message authentication code algorithm, such as Poly1305. Using a symmetric key to generate the message authentication code may provide increased speed, as opposed to asymmetric encryption, such as that used in PKCS.
[0018] The method may further comprise deleting the first pairing key from the first client device and / or the second client device, preferably upon terminating the first encrypted connection. The method may further comprise deleting the first pairing key from the quantum key device, preferably upon transmitting the first encrypted package to the first client device and the second encrypted package to the second client device.
[0019] The method may include at least one of the following steps: generating a second quantum random signal by a quantum random number generator; generating a second master key from the second quantum random signal by a quantum key device; and transmitting the second master key to a second client device and storing it in the second client device, preferably in an encrypted second client container in the second client device.
[0020] The method may further include the step of decrypting, by the first client device, the encrypted first client container, preferably upon verifying the first client container password. The method may further include the step of decrypting, by the second client device, the second client container, preferably upon verifying the second client container password. The first client container password and / or the second client container password may have been provided to the first client device by a user. The first client container password and / or the second client container password may also be stored in separate memory pages of the first / second client device memories.
[0021] The method may include storing a first master key in a quantum key device and / or storing a second master key in a quantum key device. Storing the first master key in a quantum key device may include storing the first master key and / or the second master key in an encrypted key device container within the quantum key device.
[0022] The method may include storing a first pairing key in at least one of the first client device, the second client device, and the quantum key device, particularly in at least one of the first client device container, the second client device container, and the key device container.
[0023] The first master key may preferably have a fixed bit-size first master key portion stored in the first client device container and / or key device container. The second master key may preferably have a fixed bit-size second master key portion stored in the second client device container and / or key device container. For example, each master key portion may include 128 to 2048 bits, preferably 256 bits. The first / second master keys may include, for example, four to eight, preferably six, first / second master key portions. Essentially, the longer the key length used, the more resistant it may be to potential quantum computer attacks.
[0024] The key device container may be encrypted and / or decrypted using a key device container password, the first client container may be encrypted and / or decrypted using a first client device container password, and the second client container may be encrypted and / or decrypted using a second client device container password.
[0025] The first / second encrypted packages may be generated using only the first / second transfer subset of the first / second master key portions, for example including four of the first / second master key portions.
[0026] The method may include authenticating a quantum key device using a first master key for a first client device and / or a second master key for a second client device, preferably using a first authentication subset of the first master key portion / a second authentication subset of the second master key portion, respectively. The first / second authentication subset may, for example, include two of the first / second master key portions. The first transfer subset and the first authentication subset may be disjoint. The second transfer subset and the second authentication subset may be disjoint. As a result, different portions of the master key may be used for different method steps, such as key transfer and authentication, thereby improving security. Authenticating the quantum key device may include using a key device (message) authentication code generated using the first and / or second authentication subset.
[0027] At least one of the first client container, the second client container, and the key device container may be encrypted via AES, in particular AES-AEAD-256. At least one of the first master key, the second master key, and the plurality of pairing keys may be obtained from a corresponding one of the key device container password, the first client device container password, and the second client device container password, for example, via pbkdf2.
[0028] The quantum random number generator may continuously provide a quantum random signal, and thus continuously provide random numbers (e.g., as a continuous bit string). The quantum random number generator may be controlled, for example, by a quantum key device, to start / stop providing the quantum random signal.
[0029] The first encrypted package and / or the second encrypted package may be encrypted using at least one block cipher mode of operation, which may be one of Electronic Codebook (ECB), Cipher Block Chaining (CBC), Cipher Feedback (CFB), Output Feedback (OFB), and Authenticated Encryption with Additional Data (AEAD).
[0030] For example, using ECB may involve using a 256-bit master key for all 256-bit session / pairing keys. Using CBC may involve using a 256-bit master key for all 240-bit session / pairing keys. Using CFB may involve using a 256-bit master key for all 230-bit session / pairing keys. Using OFB may involve using one master key for all 240-bit session / pairing keys. Using AEAD may involve using a 256-bit master key for all 240-bit session / pairing keys.
[0031] Generating the first encrypted package may include encrypting the first pairing key using a hash of the first master key and / or a first key string representing the first master key, particularly a first master key filename. Generating the second encrypted package may include encrypting the first pairing key using a hash of the second master key and / or a second key string representing the second master key, particularly a second master key filename.
[0032] The method may further comprise the steps of generating and transmitting a random or pseudo-random first client sequence by the first client device to the quantum key device, and preferably generating a first master key upon receiving the first client sequence at the quantum key device. More preferably, storing the first master key in the quantum key device may comprise assigning the first master key to the first client device, in particular to the first client sequence.
[0033] The method may further comprise generating and transmitting a random or pseudo-random second client sequence by the second client device to the quantum key device, and preferably generating a first master key upon receiving the first client sequence at the quantum key device. More preferably, storing the second master key in the quantum key device may comprise assigning the second master key to the second client sequence.
[0034] The first client string and / or the second client string may include, for example, a randomly generated integer (user number) assigned to one of the first client device and the second client device.
[0035] The first master key may be transmitted to the first client device over a first secure channel between the first client device and the quantum key device.
[0036] Furthermore, the second master key may be transmitted to the second client device via a second secure channel between the second client device and the quantum key device. Subsequent master keys (particularly keys that replace the first or second master key) may also be transmitted to the first client device via the first secure channel or to the second client device via the second secure channel, respectively.
[0037] In particular, the first / second master key may be transmitted to the first / second client device via a first / second local network connection between the first / second client device and the quantum key device. Preferably, the first master key may be transmitted to the first client device via a first local wired connection (e.g., including a cable and / or an optical fiber) between the first client device and the quantum key device. Furthermore, the second master key may be transmitted to the second client device via a second local wired connection between the first client device and the quantum key device. As a result, security for transmitting the master keys may be improved.
[0038] It may be provided that further keys, excluding the master key, are transmitted via a non-local network connection, such as the Internet, rather than via the first / second local connection. For example, a pairing key may be transmitted from the quantum key device to the client device via a non-local network connection. Here, security may be provided by encrypting the pairing key using the master key. At the same time, not using a local network connection may improve the efficiency of key distribution. Communication between the client devices may also be performed via a non-local network connection.
[0039] The method may further include at least one of the following steps: generating a third quantum random signal by the quantum random number generator; generating a first pairing key and / or a second pairing key of the plurality of pairing keys and / or a plurality of further pairing keys from the third quantum random signal by the quantum key device; assigning the first pairing key and / or the second pairing key and / or each of the plurality of further pairing keys to the first client device and the second client device by the quantum key device; and storing the first pairing key and / or the second pairing key and / or the plurality of further pairing keys in the quantum key device.
[0040] At least one of the first pairing key, the second pairing key, and the plurality of further pairing keys may be stored in an (encrypted) key device container.
[0041] The method may include storing a second pairing key on at least one of the first client device and the second client device, particularly on at least one of the first client device container and the second client device container. Providing multiple ready-to-use master keys and / or pairing keys may enable increased encryption speeds, particularly for example with respect to PKCS#12 or PKCS#15.
[0042] At least one or each of the plurality of pairing keys and / or additional pairing keys may be assigned to a master key, e.g., the first pairing key may be assigned to the first master key and / or the second master key.
[0043] The step of assigning each of the plurality of further pairing keys to the first client device and the second client device may include the step of storing pairing key information indicative of the plurality of further pairing keys, the first client device, and the second client device in the quantum key device. The plurality of further pairing keys may be part of a plurality of pairing keys thus assigned to the first client device and the second client device. In other words, the plurality of pairing keys may include the plurality of further pairing keys.
[0044] A second pairing key and / or multiple additional pairing keys may be generated and / or assigned to the first client device and the second client device until a maximum number of additional pairing keys is reached.
[0045] The method may further include generating, by the quantum key device, a third encrypted package by encrypting the second pairing key and / or the plurality of further pairing keys using the first master key and sending the third encrypted package to the first client device. The method may further include generating, by the quantum key device, a fourth encrypted package by encrypting the second pairing key and / or the plurality of further pairing keys using the second master key and sending the fourth encrypted package to the second client device.
[0046] The system may further include a first server. Preferably, the step of transmitting the first encrypted package to the first client device may include transmitting the first encrypted package from the quantum key device to the first server and from the first server to the first client device. Additionally or alternatively, the step of transmitting the second encrypted package to the second client device may include transmitting the second encrypted package from the quantum key device to the first server and from the first server to the second client device. Additionally or alternatively, the first master key may be stored in the first server, particularly in the encrypted first server container. The step of transmitting the first client sequence to the quantum key device may include transmitting the first client sequence from the first client device to the first server and from the first server to the quantum key device.
[0047] As a result, the first server may act as a distribution hub and / or controller between the client devices and the quantum key devices.
[0048] The first server container may be encrypted using the first server key. A second master key may also be stored in the first server, preferably in the first server container. At least one of the pairing keys, particularly the first pairing key, may be stored in the first server container. The first / second master key may be transmitted to the first server, for example, via a physical connection between the first server and the quantum key device (e.g., a third wired connection including a cable and / or an optical fiber), particularly if the quantum key device is part of the first server.
[0049] The method may include authenticating the first server using a first master key for the first client device and / or a second master key for the second client device, preferably using a first authentication subset of the first master key portion / a second authentication subset of the second master key portion, respectively. Authenticating the first server may include using a first server (message) authentication code generated using the first and / or second authentication subsets.
[0050] Sending the first client sequence to the quantum key device may include sending the first client sequence to a first server and from the server to the quantum key device.
[0051] Additionally, transmitting the second client sequence to the quantum key device may include transmitting the second client sequence to the first server and / or from the server to the quantum key device.
[0052] The quantum key device may be separate from the first server. Alternatively, the first server may include the quantum key device. In this case, transmission between the first server and the quantum key device may include transmission between a first server memory and the quantum key device (memory).
[0053] Alternatively, the first client sequence may be sent directly from the first client device to the quantum key device. Further, the second client sequence may be sent directly from the second client device to the quantum key device. The first encrypted package may be sent directly from the quantum key device to the first client device. Further, the second encrypted package may be sent directly from the quantum key device to the second client device.
[0054] A server-client pairing key may be generated and / or provided and / or used for encrypted message communication between a first client device and a server, or between a second client device and a server corresponding to the first pairing key.
[0055] The first server may be or may include at least one of a security server, a transport server, a transport router, a message archive server, and a key distribution server.
[0056] The first server (memory) may contain a routing table indicating the data processing devices of the system, in particular the first client device, the second client device and the quantum key device.
[0057] The first master key file name and / or the second master key file name may be provided according to the NM principle, where N may be the first server name and M may be the first client string / second client string and / or a random client number. Such a naming convention may be used to establish the assignment of master keys to each data processing device. The pairing key name may be provided in a 2M-K format, where M may be one of the first client string and the second client string, and K may be the other of the first client string and the second client string. The modulus 2 may represent a pairing key corresponding to pair-wise communication.
[0058] At least one of the first client container, the second client container, the key device container, and the first server container may include a (respective) key table (key data array). For example, the first client container may include a first client key table, the second client container may include a second client key table, the key device container may include a key device key table, and the first server container may include a first server container key table.
[0059] At least one of the first pairing key, the second pairing key, the plurality of further pairing keys, and the server-client pairing key may be stored in a key table, preferably in one of a plurality of key table cells. At least one of the first key string, the second key string, the first client string, and the first server string indicating the first server may further be stored in a key table, preferably in one of a plurality of key table cells. The first / second master keys may be stored, for example, in a first / second client container outside the first / second client key table.
[0060] The key table may include multiple sub-tables, each of which may preferably be assigned to one of the data processing devices of the system. Each of the sub-tables may be, for example, at least one of a key table row, a key table column, and a key table cell group. At least one of the sub-tables, and preferably each of them, may be separately encrypted, preferably using a different one of multiple sub-table keys. At least one of the sub-tables, and preferably each of them, may include a separate sub-table variable. Each sub-table variable may be generated by a quantum random number generator. Each sub-table variable may have a length of 64 bits to 2048 bits, preferably 512 bits.
[0061] At least one of the sub-table keys, and preferably each of them, may be generated using a respective master key and sub-table variable, preferably using a hash of the respective master key and the least significant bits (or most significant bits) of the respective sub-table variable. For example, a first sub-table assigned to a first client device may be generated using a first master key and a first sub-table variable, preferably using a hash of the first master key and the first least significant bits of the first sub-table variable.
[0062] The key table may further be encrypted with the first master key or the second master key (e.g., using an AEAD), preferably if the user is determined to be inactive by one of the data processing devices.
[0063] The key table may be configured such that at least one of the first pairing key, the second pairing key, the plurality of additional pairing keys, and the server-client pairing key may be asynchronously readable and writable. The first client container and / or the second client container may be configured such that the master key may be asynchronously readable and writable. The asynchronous reading and writing may accommodate a mismatch between the key generation rate and the key usage rate. The asynchronous reading and writing may accommodate the container and / or the key table being divided into separately encrypted data ranges. Because each data range may be open only for reading or writing, switching to a new encryption key (e.g., when the usage limit of the old key is reached) may allow for a transparent and undetermined switch to the new key. As a result, a step of simultaneously storing multiple sets of keys for communication between the client device and the server may be provided.
[0064] It may be specified that the first master key and the master key are only used for encrypted communications between the first client device and the first server, between the second client device and the first server, and / or between the quantum key device and the first server.
[0065] The method may further include at least one of the following steps: sending a pairing query message from the first client device to the first server, the pairing query message indicating the second client device; when it is determined that at least one of the plurality of pairing keys is assigned to the first client device and the second client device and stored in the first server, sending at least one of the plurality of pairing keys from the first server to the first client device; when it is determined that none of the plurality of pairing keys is assigned to the first client device and the second client device and stored in the first server, sending a pairing key server request message from the first server to the quantum key device; and when it is determined that none of the plurality of pairing keys is assigned to the first client device and the second client device and stored in the first server, sending at least one of the plurality of pairing keys from the quantum key device to the first server and from the first server to the first client device upon receiving the pairing key server request message at the quantum key device.
[0066] Correspondingly, a step of sending a second pairing query message indicating the first client device from the second client device to the first server, and a step of sending a pairing key to the second client device may be provided.
[0067] At least one of the plurality of pairing keys may include a first pairing key and / or a second pairing key.
[0068] The step of transmitting at least one of the plurality of pairing keys from the quantum key device to the first server and / or from the first server to the first client device may include transmitting at least one of the plurality of pairing keys in an encrypted package.
[0069] The method may further include a step of deleting at least one of the plurality of pairing keys from the first server upon transmitting at least one of the plurality of pairing keys from the first server to the first client device.
[0070] The method may also include generating a third quantum random signal by a quantum random number generator upon receiving the pairing key request message at the quantum key device.
[0071] At least one or each of the plurality of pairing keys may be a session key and / or a chat key.
[0072] The pairing query message may be sent from the first client device to the first server when contact information, preferably indicative of the second client device, is provided to the first client device.
[0073] The method may include the step of sending a first pairing key request message from the first client device to the quantum key device upon determining that fewer pairing keys than a first pairing key threshold are stored in the first client device, and / or the step of sending a second pairing key request message from the second client device to the quantum key device upon determining that fewer pairing keys than a second pairing key threshold are stored in the second client device.
[0074] Upon receiving the first and / or second pairing key request message at the quantum key device, at least one further pairing key may be transmitted in a further encrypted package from the quantum key device to the first and / or second client device. The first and / or second pairing key threshold may be, for example, 2 to 10, preferably 5.
[0075] The method may include at least one of the following steps: providing a second pairing key of the plurality of pairing keys to the first client device by decrypting the first encrypted package or the third encrypted package sent from the quantum key device to the first client device using a first master key; providing the second pairing key to the second client device by decrypting the second encrypted package or the fourth encrypted package sent from the quantum key device to the second client device using the second master key; establishing a second encrypted connection between the first client device and the second client device using the second pairing key; providing first pairing data to the first client device and / or the quantum key device indicating a first number of pairing keys used and the first master key; and providing second pairing data to the second client device and / or the quantum key device indicating a second number of pairing keys used and the second master key.
[0076] The first number of pairing keys used may refer to the pairing keys used that were decrypted with the first master key. The second number of pairing keys used may refer to the pairing keys used that were decrypted with the second master key. As a result, the number of pairing keys per master key may be tracked.
[0077] The step of providing the first and / or second pairing data may comprise the steps of generating the first and / or second number of used pairing keys or modifying the first and / or second number of used pairing keys, in particular incrementing the first and / or second number of used pairing keys, preferably by 1. The first and / or second number of used pairing keys may be integer values. The first and / or second number of used pairing keys may have an initial value of 0.
[0078] Additionally or alternatively, the pairing data may be provided to the first server. A second pairing key may be assigned to the first master key and / or the second master key.
[0079] The method may further include at least one of encrypting, at the first client device and / or the second client device, the first pairing key using a first encryption key and encrypting the second pairing key using a second encryption key different from the first encryption key, and storing the encrypted first pairing key and second pairing key in the first client device and / or the second client device.
[0080] In particular, at least two of the first master key, the second master key, the first pairing key, the second pairing key, each of the further pairing keys, and each of the server-client pairing keys may be encrypted using different pairwise encryption keys and may preferably be stored in an encrypted state in at least one of the first client device, the second client device, the first server, and the quantum key device. For example, each of the first pairing key, the second pairing key, and the further pairing key may be encrypted using different pairwise encryption keys and stored in an encrypted state in the first client device.
[0081] The first pairing key and the second pairing key may be stored in a key table. A first encryption key may be generated using a first master key and a first sub-table variable, preferably using a hash of the first master key and the first least significant bits of the first sub-table variable. A second encryption key may be generated using the first master key and a second sub-table variable, preferably using a hash of the first master key and the second least significant bits of the second sub-table variable. In particular, the different encryption keys may be sub-table keys.
[0082] The method may further include at least one of generating a fourth quantum random signal by the quantum random number generator, generating a symmetric third master key from the fourth quantum random signal by the quantum key device and storing it in the quantum key device, transmitting the third master key to the first client device and storing it in the first client device, and deleting the first master key from the quantum key device and / or the first client device.
[0083] The method may further include at least one of the following steps: generating a fifth quantum random signal by the quantum random number generator; generating a symmetric fourth master key from the fifth quantum random signal by the quantum key device and storing it in the quantum key device; transmitting the fourth master key to the second client device and storing it in the second client device; and deleting the second master key from the quantum key device and / or the second client device.
[0084] The third master key may be transmitted to the first client device when the quantum key device and / or the first client device determines that a first number of pairing keys used exceeds a first threshold, and the fourth master key may be transmitted to the second client device when the quantum key device and / or the second client device determines that a second number of pairing keys used exceeds a second threshold.
[0085] The first master key may be deleted from the quantum key device and / or the first client device when it is determined by the quantum key device and / or the first client device that a first number of pairing keys used exceeds a first threshold, and the second master key may be deleted from the quantum key device and / or the second client device when it is determined by the quantum key device and / or the second client device that a second number of pairing keys used exceeds a second threshold.
[0086] Deleting the key may include zeroing out every bit in each memory location and double overwriting with a random sequence.
[0087] The first threshold and the second threshold may be the same. The first threshold and / or the second threshold may be between 1,000 and 100,000, preferably between 10,000 and 60,000, and more preferably 50,000. As a result, for example, a new master key may be used for every 50,000 encrypted connection / pairing keys.
[0088] The third master key and / or the fourth master key may be tested by sending a test message from the first / second client device to the first server and / or quantum key device. The test message may have a length of, for example, 128 bits. The test message may comprise a bit sequence, for example: 1010 0101 1111 0000 1100 0011 1010 0101 1111 0000 1010 0101 1111 0000 1010 0101 1111 0000 1010 0101 1111 0000 1100 0011 1010 0101 1111 0000 1010 0101 1111 0000 1010 0101 1111 0000 1100 0011 1010 0101 1111 0000 1010 0101 1111 0000. Essentially, any sequence known to both the first and second client devices may be used. The test message may be encrypted using the third / fourth master key.
[0089] The method may include providing third pairing data to the first client device and / or quantum key device indicating a third number of pairing keys used and a third master key, and providing fourth pairing data to the second client device and / or quantum key device indicating a fourth number of pairing keys used and a fourth master key.
[0090] At least one, and preferably each, of the first master key, the second master key, the third master key, the fourth master key, the first pairing key, the second pairing key, the further pairing key, and the server-client pairing key may be stored (e.g., in a random access memory) using a respective mask. Each mask may be a randomly generated number (e.g., a bit sequence) that is preferably stored in a separate memory page (within the encrypted container). Each mask may be randomly generated, for example, by a quantum key device. Storing at least one or each of the keys using their respective mask may comprise applying an XOR operation to (a binary representation of) the key and the mask and storing the resulting (bit) string. Accessing / providing the key (e.g., for subsequent use of the key for encryption) may comprise applying an XOR operation to the resulting string and the mask, thereby obtaining the key.
[0091] The method may include revoking at least one of the first master key, the second master key, the third master key, the fourth master key, the first pairing key, the second pairing key, the further pairing key, and the server-client pairing key, for example upon determining that the key has been compromised. Revoking the key may include removing and / or replacing the key from all data processing devices in the system.
[0092] The first client device, the second client device, the first server and the quantum key device may be connected to each other by cables and / or wirelessly.
[0093] The embodiments described above in relation to a method for encrypted messaging may correspondingly be provided for a system for encrypted messaging. Embodiments as described herein with respect to a first entity, such as a first client device or a first pairing key, may be provided to a corresponding second entity and / or a third entity and / or a fourth entity. As understood herein, storing in a data processing device may include storing in a memory of the data processing device.
[0094] Hereinafter, an embodiment will be described by way of example with reference to the drawings. [Brief explanation of the drawings]
[0095] [Figure 1] FIG. 1 shows a graphical representation of a system comprising multiple data processing devices. [Figure 2] FIG. 2 shows a graphical representation of a method for encrypted messaging. DETAILED DESCRIPTION OF THE INVENTION
[0096] 1 shows a graphical representation of a system comprising a plurality of data processing devices 10, 11, 12, 13, i.e. a plurality of client devices 10, 11 (including a first client device 10 and a second client device 11), a quantum key device 12 and a first server 13. A second server and further client devices, for example a third client device and a fourth client device (not shown) may also be provided.
[0097] The first client device 10 includes a first client device memory 10a, a first client device processor 10b, and a first client device transceiver unit 10c. The second client device 11 includes a second client device memory 11a, a second client device processor 11b, and a second client device transceiver unit 11c.
[0098] The quantum key device 12 includes a key device memory 12a, a key device processor 12b, a key device communication interface 12c (e.g., a key device transceiver), and a quantum random number generator 12d. The first server 13 includes a first server memory 13a, a first server processor 13b, and a first server transceiver unit 13c. The first server 13 may also include the quantum key device 12.
[0099] The data processing devices 10-13 exchange signals via respective communication channels 10d, 10e, 11d, 11e, 12e, 14, in particular a first channel 10d between the first client device 10 and the quantum key device 12, a second channel 11d between the second client device 11 and the quantum key device 12, a third channel 10e between the first client device 10 and the first server 13, a fourth channel 11d between the second client device 11 and the first server 13, a fifth channel 12e between the quantum key device 12 and the first server 13, and a sixth channel 14 between the first client device 10 and the second client device 11. Each of the communication channels 10d, 10e, 11d, 11e, 12e, 14 may comprise a wireless channel. Additionally or alternatively, the communication channels 10d, 10e, 11d, 11e, 12e, 14 may include physical connections, such as electrical and / or wired connections, e.g., cables and / or optical fibers. Each of the communication channels 10d, 10e, 11d, 11e, 12e, 14 may include, for example, an Internet connection and / or a WiFi connection and / or a Bluetooth connection. The communication channels 10d, 10e, 11d, 11e, 12e, 14 (particularly the communication channels connected to the quantum key device 12, such as the first channel 10d, the second channel 11d, and / or the fifth channel 12e) may each include a local network connection, preferably a local wired connection. Communication between the client devices 10, 11 may occur directly using the sixth channel 14 and / or via the first server 13.
[0100] Furthermore, each of the data processing devices 10-13 may include respective input and / or output devices (not shown).
[0101] Each of the client devices 10, 11 and the first server 13 may be a single computing device. Alternatively, at least one of the client devices 10, 11 and the first server 13 may not be limited to a single computing device, and may preferably further include multiple sub-devices. Each of the client devices 11, 12 may also be or include a user device, such as a personal computer, a tablet computer, and / or a mobile phone. Each of the client devices 11, 12 may also correspond to a further server, particularly for further client devices.
[0102] FIG. 2 shows a graphical representation of a method for encrypted messaging.
[0103] In a first step 21, the first client device 10 generates a random first client sequence (first user number) and sends the first user number to the first server 13 to obtain a symmetric first master key.
[0104] In a second step 22, the first server 13 checks whether a connection has previously been established with the first client device 10. If the first server determines that the connection with the first client device 10 is a first connection, it requests a first master key from the quantum key device 12. To this end, the first server 13 sends the first user number to the quantum key device 12.
[0105] In response (in a third step 23), the quantum key device 12 assigns to the first client device 10 (via the first user number) a first master key generated from the first quantum random signal generated by the quantum random number generator 12d. The first master key is then transmitted from the quantum key device 12 to the first client device 10. At this stage, the first client device 10 should be close (i.e., physically nearby) to the quantum key device 12, for example, by receiving the first master key via a local network without the presence of a cryptographic analyst. Once received, the first master key is stored in an encrypted first client container in the first client device 10. A password must be entered each time before opening / decrypting the first client container. The first master key is also stored in an encrypted first server container in the first server 13. The first master key is now installed. Correspondingly, a second master key for the second client device 11 is installed.
[0106] In a fourth step 24, the first client device 10 is provided with an address from which a table of user connections is generated and sent to the first server 13 (corresponding to a pairing query message).
[0107] In a fifth step 25, the first server 13 determines whether a corresponding symmetric pairing key already exists for the provided user connection from the first client device 10. For example, if the provided user connection includes a connection with a second client device 11, the server 13 determines whether corresponding pairing keys have been assigned to the first client device 10 and the second client device 11.
[0108] If the server 13 so determines, the corresponding pairing key (first pairing key) is sent directly from the first server 13 to the first client device 10 in a first encrypted package encrypted with the first master key. The first pairing key is also sent from the first server 13 to the second client device 11 in a second encrypted package encrypted with the second master key. Otherwise, the first pairing key is requested to be generated in the quantum key device 12 and sent to the first server 13 for further transmission to the first client device 10 and the second client device 11. The first pairing key is generated from the corresponding quantum random signal by the quantum random number generator 12d and stored in the encrypted key device container or is pre-stored. Further session and chat keys are similarly generated and provided to the client devices.
[0109] In a sixth step 26, a first encrypted connection is established between the first client device 10 and the second client device 11 using the first pairing key stored in both client devices 10, 11. Using the first pairing key, the first client device 10 and the second client device 11 can further authenticate each other, for example via a message authentication code. After terminating the first encrypted connection, the used first pairing key is deleted.
[0110] For a subsequent second encrypted connection between the first client device 10 and the second client device 11 (seventh step 27), a symmetric second pairing key must be generated and provided to both client devices 10, 11. Again, the second pairing key is sent to the first client device 10 encrypted with the first master key and to the second client device 11 encrypted with the second master key.
[0111] For security reasons, the first / second master should not be used to transmit more than a certain number of pairing keys (e.g., 50,000), after which the first / second master key should be replaced by the next master key.
[0112] The features disclosed in the specification, the figures and / or the claims may be material for the realization of various embodiments, taken alone or in various combinations thereof.
Claims
1. A method for encrypted message communication in a system comprising a first client device (10), a second client device (11), and a quantum key device (12) including a quantum random number generator (12d), comprising: - generating a random or pseudo-random first client sequence by the first client device (10) and sending it to the quantum key device (12); - generating a first quantum random signal by said quantum random number generator (12d); - upon receiving the first client sequence at the quantum key device (12), generating a symmetric first master key from the first quantum random signal by the quantum key device (12); - storing said first master key in an encrypted key device container in said quantum key device (12), said storing step comprising assigning said first master key to said first client sequence; - transmitting said first master key to said first client device (10) and storing it in an encrypted first client container in said first client device (10); - generating a first encrypted package by the quantum key device (12) using the first master key to encrypt a first pairing key of a plurality of symmetric pairing keys assigned to the first client device (10) and the second client device (11); - generating a second encrypted package by encrypting the first pairing key using a second master key with the quantum key device (12) and sending the first encrypted package to the first client device (10) and the second encrypted package to the second client device (11); - providing the first pairing key to the first client device (10) by decrypting the first encrypted package using the first master key and providing the first pairing key to the second client device (11) by decrypting the second encrypted package using the second master key; - establishing a first encrypted connection between the first client device (10) and the second client device (11) using the first pairing key. method.
2. The step of establishing a first encrypted connection includes: - generating a first encrypted message using the first pairing key in one of the first client device (10) and the second client device (11) and sending the first encrypted message to the other of the first client device (10) and the second client device (11). The method of claim 1.
3. Establishing the first encrypted connection includes authenticating the first client device (10) and / or the second client device (11) using the first pairing key. The method of claim 1.
4. The step of authenticating the first client device (10) comprises: - generating, in said first client device (10), a first authentication code from a first authentication message using said first pairing key; - sending a second message and said first authentication code from said first client device (10) to said second client device (11); - generating, in the second client device (11), a second authentication code from the first authentication message using the first pairing key; - comparing, in said second client device (11), said first authentication code with said second authentication code. The method of claim 3.
5. moreover, - generating a second quantum random signal by said quantum random number generator (12d); - generating the second master key from the second quantum random signal by the quantum key device (12); - transmitting said second master key to said second client device (11) and storing it in an encrypted second client container in said second client device (11). The method of claim 1.
6. The first master key is transmitted to the first client device (10) via a first secure channel (10d) between the first client device (10) and the quantum key device (12). The method of claim 1.
7. moreover, - generating a third quantum random signal by said quantum random number generator (12d); - generating, by said quantum key device (12), said first pairing key and / or a plurality of further pairing keys from said third quantum random signal; - assigning, by the quantum key device (12), the first pairing key and / or each of the plurality of further pairing keys to the first client device (10) and the second client device (11); - storing said first pairing key and / or said plurality of further pairing keys in said quantum key device (12). The method of claim 1.
8. The plurality of further pairing keys are generated and / or assigned to the first client device (10) and the second client device (11) until a maximum number of further pairing keys is reached. The method of claim 7.
9. The system further comprises a first server (13), preferably - transmitting the first encrypted package to the first client device (10) comprises transmitting the first encrypted package from the quantum key device (12) to the first server (13) and from the first server (13) to the first client device (10); - transmitting the second encrypted package to the second client device (11) comprises transmitting the second encrypted package from the quantum key device (12) to the first server (13) and from the first server (13) to the second client device (11); - said first master key is stored on said first server (13); The method of claim 1.
10. moreover, - sending a pairing query message from the first client device (10) to the first server (13) indicating the second client device (11); - upon determining that at least one of the plurality of pairing keys has been assigned to the first client device (10) and the second client device (11) and stored in the first server (13), transmitting at least one of the plurality of pairing keys from the first server (13) to the first client device (10); - upon determining that none of the plurality of pairing keys are assigned to the first client device (10) and the second client device (11) and stored in the first server (13), sending a pairing key server request message from the first server (13) to the quantum key device (12); Upon receiving the pairing key server request message at the quantum key device (12), transmitting at least one of the plurality of pairing keys from the quantum key device (12) to the first server (13) and from the first server (13) to the first client device (10).
10. The method of claim 9.
11. moreover, - providing a second pairing key of the plurality of pairing keys to the first client device (10) by decrypting the first encrypted package or the third encrypted package transmitted from the quantum key device (12) to the first client device (10) using the first master key; - providing the second pairing key to the second client device (11) by decrypting the second encrypted package or the fourth encrypted package sent from the quantum key device (12) to the second client device (11) using the second master key; - establishing a second encrypted connection between the first client device (10) and the second client device (11) using the second pairing key; - providing first pairing data to the first client device (10) and / or the quantum key device (12), the first pairing data indicating a first number of pairing keys used and the first master key; providing second pairing data to the second client device (11) and / or the quantum key device (12), the second pairing data indicating a second number of pairing keys used and the second master key; The method of claim 1.
12. moreover, - encrypting, at the first client device (10) and / or the second client device (11), the first pairing key using a first encryption key and the second pairing key using a second encryption key different from the first encryption key; storing the encrypted first and second pairing keys in the first client device (10) and / or the second client device (11). The method of claim 11.
13. moreover, - generating a fourth quantum random signal by said quantum random number generator (12d); - generating a symmetric third master key from the fourth quantum random signal by the quantum key device (12) and storing it in the quantum key device (12); - transmitting said third master key to said first client device (10) and storing it in said first client device (10); - deleting the first master key from the first client device (10) and / or the quantum key device (12). The method according to any one of claims 1 to 12.
14. A system for encrypted message communication comprising a first client device (10), a second client device (11), and a quantum key device (12) having a quantum random number generator (12d), - generating a random or pseudo-random first client sequence by the first client device (10) and sending it to the quantum key device (12); - generating a first quantum random signal by said quantum random number generator (12d); - upon receiving the first client sequence at the quantum key device (12), generating a symmetric first master key from the first quantum random signal by the quantum key device (12); - storing said first master key in an encrypted key device container in said quantum key device (12), said storing step comprising assigning said first master key to a first string of clients; - transmitting said first master key to said first client device (10) and storing it in an encrypted first client container in said first client device (10); - generating a first encrypted package by the quantum key device (12) using the first master key to encrypt a first pairing key of a plurality of symmetric pairing keys assigned to the first client device (10) and the second client device (11); - generating a second encrypted package by encrypting the first pairing key using a second master key with the quantum key device (12) and sending the first encrypted package to the first client device (10) and the second encrypted package to the second client device (11); - providing the first pairing key to the first client device (10) by decrypting the first encrypted package using the first master key and providing the first pairing key to the second client device (11) by decrypting the second encrypted package using the second master key; - establishing a first encrypted connection between the first client device (10) and the second client device (11) using the first pairing key, system.
Citation Information
Patent Citations
Contents utilization device and recording medium recording contents utilization program
JP2000101565A
Secure communication method
JP2002290397A
Security system
JP2008172728A
Network security symmetric quantum cryptography key based encryption device
KR1020200135157A
Techniques for confidential delivery of random data over a network
US20170244687A1