Secure communication between known users

The system employs a hardware-based cryptographic key selection and physical protection to secure encrypted communications, addressing the inadequacies of software-based solutions by ensuring unpredictable key usage and robust protection against hacking.

JP7830429B2Active Publication Date: 2026-03-16SN2N LLC
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-04
Publication Date
2026-03-16

AI Technical Summary

Technical Problem

Existing software-based cybersecurity solutions are inadequate in consistently protecting encrypted communications from hacking, as they can be compromised and require frequent updates, leaving systems vulnerable to data breaches and potential malicious interference.

Method used

A system utilizing a memory module with cryptographic keys and hardware-based cryptographic key selection and code generation techniques to ensure unpredictable key usage, preventing reverse engineering and minimizing the need for software updates, combined with physical protection mechanisms to secure the cryptographic components.

Benefits of technology

This approach significantly enhances the security of encrypted communications by making it extremely difficult for hackers to decrypt the information, even with typical computer processing power, and reduces the risk of data breaches by minimizing the vulnerability to software-based attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007830429000001
    Figure 0007830429000001
  • Figure 0007830429000002
    Figure 0007830429000002
  • Figure 0007830429000003
    Figure 0007830429000003
Patent Text Reader

Abstract

A computationally secure system and method for transmitting encrypted information is disclosed, in which the probability that such transmitted information can be decrypted in a reasonable period of time or with typical computer processing power is very low. The advantageous combination of (1) a memory module containing a separate list of encryption keys that can be used to generate secure encrypted communications between known and authorized secure devices, and (2) partially or fully hardware-implemented encryption key selection and corresponding code generation techniques advantageously produces a computationally highly secure communication system and method that is relatively low cost. Such a combination facilitates the implementation of unpredictable or nearly unpredictable encryption keys, because even if a hacker somehow knows which encryption keys were used in a previous communication session, such a hacker cannot predict which encryption keys will be used in a future communication session based on those known encryption keys.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to systems and methods for secure communication between known users. More specifically, it relates to systems and methods for securing an encrypted communication system and method.

[0002] All documents cited or relied upon below are hereby expressly incorporated herein by reference.

Background Art

[0003] Cyber security has many meanings in today's world. Everything from computer viruses to ransomware, data breaches, etc. poses challenges to cyber security. Initial computers were connected to each other through cables and ultimately through modems over copper telephone lines. In the current environment, the move to the ubiquity of devices that communicate wirelessly and then enter the "Internet" is changing and transforming applications.

[0004] The concept of "hacking"—the act of secretly infiltrating computer systems to which one does not belong—has grown tremendously, fueled by the thrill of a 16-year-old hacking sophisticated international bad actors in their parents' basements. For example, the cost of data breaches, where personal financial data is stolen from banks, brokers, credit rating agencies, insurance companies, retailers, healthcare institutions, and more, can amount to hundreds of millions of dollars annually. In addition, the risks to individual and national health are rapidly increasing, along with hackers' ability to infiltrate implanted pacemakers, power grids, or autonomous vehicles. Virtually every industry, every military operation, every government agency, and every piece of equipment can be a potential entry point for clever hackers using computers and smartphones. Every day, the news includes multiple cases of hacking, ransom payments, and data breaches. However, for predetermined publicity purposes, only a small fraction of these stories are published, and the vast majority are quietly resolved. In any case, it comes at the cost of consumers, governments, and private businesses.

[0005] Some examples of security vulnerabilities include communications between two cell phones, microwave communications in first-response systems, autonomous vehicles, networked medical devices, battlefield communications between soldiers / headquarters / drones, power grids, banks and their customers, banks and correspondent banks, bond dealers and the Federal Reserve Bank, intra-corporate global pricing and marketing data, medical data, lawyers and their clients, investment banks and publicly traded acquirers, lovers and mistresses, and many others. One undesirable consequence of such vulnerabilities is the risk of data with resale value being disclosed. Others include potentially fatal scenarios such as a malicious actor hacking into someone's pacemaker and taking them hostage, or causing all autonomous vehicles to run red lights at 60 miles per hour.

[0006] For the past 35 years, computer security has focused solely on software-based solutions. These solutions include, for example, antivirus software, malware prevention, programmable firewalls, zero-day pattern detection, software encryption, and alternative methods. What they all have in common is that while some are better than others, none of them function on a consistent, broad application basis. Each is targeted at a specific situation, and even then, as we can see from the news almost daily, they can still be compromised. [Overview of the Initiative]

[0007] Systems and methods for transmitting computationally secure encrypted information are disclosed, where such transmitted information is extremely unlikely to be decrypted within a reasonable timeframe or using typical computer processing power. These systems and methods favorably rely on a combination of (1) a memory module containing a separate list of cryptographic keys usable to generate secure encrypted communications between known and authorized secure devices, and (2) cryptographic key selection and corresponding code generation techniques implemented partially or entirely in hardware. Such a combination facilitates the selection of cryptographic keys for each communication session in an unpredictable or near-unpredictable manner, because even if a hacker somehow knows which cryptographic keys were used in previous communication sessions, such hacker cannot predict which cryptographic keys will be used in current or future communication sessions based on those known cryptographic keys.

[0008] The systems and methods of these embodiments also, advantageously, do not require the intermittent software updates required by software-based encryption techniques, thus preventing an increased ability of hackers to hack into the communications of software-based secure devices. A hacker would need to access and reverse engineer the secure device and somehow determine whether the list of cryptographic keys in the memory module can be used for secure communications with certain other secure devices in order to hack into the systems and methods of the embodiments described herein. Similarly, for these embodiments that implement an encrypted data bus, a hacker would likewise need to determine the encryption method and cryptographic keys used for such data bus encryption. Additional components may be included in certain embodiments of the invention to prevent access to and reverse engineering attempts of these components of the secure device, and to prevent X-rays, micro-drilling, or any other mechanical or optical means intended to reveal the contents of such components.

[0009] According to a particular embodiment of the present invention, a secure device system for transmitting encrypted communications over a network includes a processor having an input for receiving at least one message to be transmitted to a first other secure device, the processor being coupled to at least one data bus, and a memory module being communicably coupled to the processor, storing at least one list of cryptographic keys for use in communication with the first other secure device, the first other secure device being a memory module having a memory storing copies of the at least one list of cryptographic keys, and an encryption selection circuit coupled to the processor, the encryption selection circuit selecting a message encryption key, a message decryption key, and a hand based on the at least one list of cryptographic keys. The cryptographic selection circuit of the first other secure device is applied to process the selection code to generate copies of the message encryption key, the message decryption key, the handshake message encryption key, and the handshake message decryption key from a stored copy of at least one list of the cryptographic keys in the memory of the first other secure device, and includes a network interface which is communicatively coupled to the processor and is applied to transmit and receive digital information over a network to and from the first other secure device.

[0010] The processor operates in the initialization phase by activating the cryptographic selection circuit to generate the selection code, and is configured to generate a handshake message and send it to the first other secure device via the network interface, the handshake message including the unencrypted network addresses of the secure device and the first other secure device, and the selection code, and upon receiving a response handshake message sent by the first other secure device, operates in the acknowledgment phase, and is configured to process the first and second segments of the response handshake message using the handshake message encryption key and the handshake message decryption key, respectively, and the first and second data sequences Having acquired the first data sequence and compared it with the message encryption key, and the second data sequence with the message decryption key, and having confirmed that the first data sequence and the second data sequence correspond to the message encryption key and message decryption key, respectively, associated with the selection code, and having confirmed that the acquired first data sequence and the second data sequence correspond to the message encryption key and message decryption key, respectively, associated with the selection code, the processor is further configured to operate in the transmission phase by encrypting at least one message received at input based on the message encryption key, and to transmit the resulting encrypted at least one message to the first other secure device via the network interface.

[0011] According to a particular embodiment of the method of the present invention, the secure device includes a processor having an input for receiving at least one message to be transmitted to a first other secure device, and coupled to at least one data bus; a memory module for storing at least one list of cryptographic keys; a cryptographic selection circuit for generating a selection code based on the at least one list of cryptographic keys; and a network interface applied to transmit and receive digital information to and from the first other secure device, and operates as follows: The processor invokes the cryptographic selection circuit to generate a selection code indicating a message encryption key, a message decryption key, a handshake message encryption key, and a handshake message decryption key based on the at least one list of cryptographic keys, wherein the corresponding cryptographic selection circuit in the first other secure device is applied to process the selection code to generate copies of the message encryption key, the message decryption key, the handshake message encryption key, and the handshake message decryption key from the stored copy of the at least one list of cryptographic keys in the memory of the first other secure device. The processor then generates a handshake message including the unencrypted network addresses of the secure device and the first other secure device, and a selection code, and sends the handshake message to the first other secure device.

[0012] Upon receiving a response handshake message from the first other secure device, the processor processes the first and second segments of the response handshake message, respectively, using the handshake message encryption key and the handshake message decryption key to obtain a first data sequence and a second data sequence, and then compares the first data sequence with the message encryption key and the second data sequence with the message decryption key to confirm that the first data sequence and the second data sequence correspond to the message encryption key and the message decryption key, respectively, associated with the selection code. Having confirmed that the obtained first data sequence and the second data sequence correspond to the message encryption key and the message decryption key, respectively, associated with the selection code, the processor operates in the transmission phase by encrypting the at least one message received at input using the message encryption key, and consequently transmits the at least one encrypted message to the first other secure device via the network interface.

[0013] A further embodiment of a secure device for transmitting encrypted communications over a network to multiple other secure devices includes a processor having an input for receiving at least one message to be transmitted to a first other secure device, the processor being coupled to at least one data bus, and a memory module being communicably coupled to the processor, storing at least one list of cryptographic keys for use in communication with the first other secure device, the first other secure device being a memory module having a memory storing copies of the at least one list of cryptographic keys, and a cryptographic selection circuit being coupled to the processor, the cryptographic selection circuit being based on the at least one list of cryptographic keys The system includes: a cryptographic select circuit applied to generate at least one select code indicating a message encryption key and a handshake message encryption key, and the corresponding cryptographic select circuit in each of the plurality of other secure devices is applied to process the select code to generate copies of the message encryption key and the handshake message encryption key from stored copies of at least one list of the cryptographic keys in each of the plurality of other secure devices; and a network interface that is communicatively coupled to the processor and applied to transmit and receive digital information over the network to and from the plurality of other secure devices.

[0014] In such embodiments, the processor operates in an initialization phase by activating the cryptographic selection circuit to generate the selection code, and is applied to generate a handshake message and send it to the plurality of other secure devices via the network interface, the handshake message comprising the unencrypted network addresses of the secure device and the first other secure device, and the selection code; the processor further operates in a transmission phase by encrypting at least one message received at input based on the message encryption encryption key, and is applied to send the resulting encrypted at least one message to the plurality of other secure devices via the network interface.

[0015] According to yet another embodiment of the present invention, the secure device includes a processor having an input for receiving at least one message to be transmitted to a plurality of other secure devices, the processor being coupled to at least one data bus, a memory module for storing at least one list of cryptographic keys, a cryptographic selection circuit for generating a selection code based on the at least one list of cryptographic keys, and a network interface applied for transmission to the plurality of other secure devices.

[0016] The processor invokes the cryptographic selection circuit to generate a selection code indicating a message encryption key and a handshake message encryption key based on at least one list of the encryption keys, and the corresponding cryptographic selection circuit in each of the plurality of other secure devices is applied to process the selection code to generate copies of the message encryption key and the handshake message encryption key from the stored copies of the at least one list of encryption keys in the memory of each of the plurality of other secure devices. The processor generates a handshake message containing an unencrypted group number associated with the plurality of other secure devices and the selection code, and sends the handshake message to the plurality of other secure devices. The processor then operates in the transmission phase by encrypting at least one message received at input using the message encryption key, and consequently sends the at least one encrypted message to the plurality of other secure devices via the network interface.

[0017] It is also beneficial to have complete, secure, and reliable communication between at least two nodes (devices) within a network. These nodes could be a computer server to a mobile phone, an X-ray machine to a medical record area, or a drone to a soldier. This is best done by combining hardware and software to prevent malicious actors from infiltrating the system. Many malware and antivirus technologies rely on software to identify and neutralize threats and attacks. As such techniques are developed, hackers find ways around them and create new attack methods. The methods and devices that implement them disclosed herein prevent any of these behaviors from occurring. The elegance of a device is not only the simplicity of its design at a high level, but also the complexity of how it is executed and how it is executed correctly. This design can be implemented inexpensively. This is in contrast to secure devices that offer reliable security characteristics but are orders of magnitude more expensive, such as those used by intelligence agencies. The intelligence community relies on dedicated equipment behind locked doors with armed guards and administrators. Mobile phones, pacemakers, autonomous vehicles, and the Internet of Things (IoT) are all areas where the high cost of equipment and labor prevents the realization of mobility.

[0018] Various embodiments of the teaching allow for different but relevant techniques, for example, with respect to the differences between mobile devices that require an orthogonal relationship with a specific authorized user and stationary, fixed devices.

[0019] In one aspect of this disclosure, ensuring communication between two devices may include, but is not limited to, a single device such as Device 1(D1) having several biometric authentication identification elements, including iris scanning, facial recognition, fingerprint scanning, hand geometry, finger geometry, vein recognition, voice recognition, or DNA identification. This proves that the person holding the device is authorized to hold it, i.e., that the person is a known, trusted user (KTU). This cannot be changed once initialized, except by a factory reset. A second device, such as Device 2(D2), has biometric authentication, but does not necessarily have to use the same technology.

[0020] D1 initializes the call by powering it on if it is not already turned on. A security icon and a biometric authentication icon are displayed. Biometrics, such as a fingerprint, are detected or read for the device. As mentioned above, biometric authentication information can be any element that identifies the KTU as being under the control of D1. Once the biometrics are detected or read and authenticated, the device enters initialization mode. In one embodiment, using a smartphone as an example, the smartphone screen notifies the user by displaying a message such as “initialization phase”. During this mode, three strong encryption / keys (described below) are loaded from D1 memory into the D1 register. If the encryption is not loaded correctly, or if initialization fails for technical reasons, for example, or if it does not occur within a specified time (e.g., 15 seconds) after the initialization request, initialization fails, the device must be shut down, and reinitialization is required. Upon successful initialization, D1 then enters an operating mode in which the handshake message is encrypted by one of the ciphers, and an attempt is made to connect to D2. Simultaneously, D1 encrypts the data bus using a first cipher in register 3. In one embodiment of the present invention, the cipher can be used to use any one of a number of cryptographic techniques, such as transposition or substitution ciphers, or, in particular, some of the other recognized techniques, such as AES, RSA, Triple DES, or Blowfish. In another embodiment of the present invention, the cipher encrypts the message by substituting non-ASCII character sets. One embodiment of the present invention encrypts (1) a handshake message, including at least another cipher of approximately equal length, and an optional cipher update (CR), and (2) an encrypted image of biometrics used to verify the authorized user of D1.In addition, the current timestamp, the sending media access control (MAC) address, and the receiving MAC address are appended to the message in plain text.

[0021] Upon receiving a connection request, the D2 KTU must perform the same action on its side, namely, perform biometric authentication of the KTU. The same sequence of initialization and operation phases is cycled through. Once D2 is operational, an encrypted handshake is sent to D2 along with the plaintext MAC address and timestamp. In one embodiment, D1's fingerprint is also sent. In one embodiment, the encryption key used for the message body is also encrypted and included as part of the message. In one embodiment, the CR is encrypted and included as part of the message. D2 reads the encrypted message, decrypts it using the same encryption key that D1 used to encrypt the message, and if there is a match in the handshake, sending MAC address, receiving MAC address, and timestamp, D2 performs a similar sequence to verify the D1 message by sending its own handshake message back, and communication is permitted. Otherwise, D2 assumes it may be under attack and stops any further communication. In one embodiment, the message is stored for forensic purposes.

[0022] In one embodiment of the present invention, which includes stationary devices such as computer servers D1 and D2, they are physically secure and protected, like a server farm. Since they are not assigned or allocated to humans, there is no biometric authentication. However, the handshake sequence is the same, except for the transmission of the fingerprint of D1. Other devices that are not locked but do not have a specific authorized user can also transmit messages, just like locked stationary devices. A device such as an IoT device, for example, a “smart” home thermostat connected to a wireless network, establishes verification once but is always connected wirelessly. In this way, it can only communicate with the network and cannot communicate with potential malicious actors attempting to infiltrate the network. If communication with the network is interrupted, the device needs to re-establish the connection and handshake sequence.

[0023] Each device has a secure unit consisting of a central processing unit, numerous active registers, and storage. The central processing unit can be a combination of a specially designed computing device, a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), or other elements capable of generating the execution of a computer program. For ultimate security, symmetric encryption is used, which means that each side of the communication must use the same key. For a key to be effective, the less it needs to be repeated as practically possible, the less likely it is to be discovered. The more random the key, the less likely it is to be discovered by a malicious actor. A perfectly random key means that it is impossible to know the existing characters and determine the next character. Computer software cannot generate perfectly random bit sequences. There are no conditional bits, and each "1" or "0" has an equal probability of occurring. Even the best computer software can only generate pseudorandom characters, which can be discovered with sufficient computational power. However, the techniques taught here minimize the possibility of key discovery and, as a result, maintain a high level of security even with the use of pseudorandom numbers. Furthermore, the required level of security varies, and back-office video surveillance cameras do not need to target as many targets as bank servers, thus allowing for a wider range of pseudo-random encryption methods to be used.

[0024] The length of the key can vary according to usage. For absolute security, the key should be at least longer than the message being encrypted to prevent repetition, and preferably even longer. For example, a lawyer sending a document may require a key of 1 million ASCII characters, while someone communicating securely with a bank may only require 1000 ASCII characters. For true security, the key is used only once and new keys are provided to both sides. This can be achieved by installing multiple keys in the device from the start. In one embodiment, each device has n handshake ciphers and m message ciphers. However, it is possible to create a new random key from an existing random key. In a simple example, assume the key is 100 characters (K) used to encrypt a 40-character message (M). Padding characters of a random number (P) are added by using the next few characters to determine the number of padding characters. The message length is now M + P < K. Since each character of K is completely random, it can be assumed that starting anywhere within the key (K1...K100) is also random. By simply starting the next message at character M + P + 1 and rotating the key, a new key can be established for the next message. As a result, the length of the next message exceeds K100 as described above and starts again at K1(M + P + 1) mod (100). Alternatively, by taking N random characters (sent as CR) after M + P + 1 and applying any of a number of transformations to the existing key to generate a new random key, the keys for each pair of devices can be randomly changed by using CR for the start cipher and key rotation. Assuming the fact that the key sequence is random, based on picking a part of the key which is also random, the rearrangement of the random key generates another random key.

[0025] In one embodiment, each device can communicate with only one other device. In another embodiment, a device can communicate with multiple devices. Thus, D1 has a unique set of ciphers for all other devices that it communicates securely with (D2...Dn). Each pair of devices has a unique set of ciphers for each other and thus becomes a known pair (KP). Thus, a non-military mobile phone for personal use only needs to communicate securely with six (half dozen) other endpoints, such as a bank or broker. A computer server would need to communicate securely with hundreds of thousands of other devices. The server, as an example of D1, stores a unique random cipher for each device, which has secure communication paired with its MAC address, and, if necessary, stores encrypted images of biometric authentication.

[0026] In one embodiment, the SU is embedded in an FPGA, ASIC, or similar device. It is self - contained but has an interface to the operating system within the device (D1 or D2). The SU is physically protected in two ways. First, the SU is covered with a material that can resist X - ray or other types of electronic scans that attempt to view integrated circuit gates, memory, or register dumps. In addition, the device is sealed and contains an inert gas, such that if a micropore is drilled into the chip or other attempts are made to damage the outer layer of the device, the pressure changes due to the release of the inert gas, and thus the pressure sensor embedded within the SU is triggered to self - destruct the SU by creating a short - circuit with sufficient power to destroy the key circuitry. In another embodiment, the SU is part of a larger set of components consisting of individual memories, cpus, and registers and can be etched onto silicon in the form of an FPGA, ASIC, or similar design. In this embodiment, the segregated portion of the component that is the SU is protected using the mechanisms described above.

Brief Description of the Drawings

[0027] Some embodiments of the present invention are illustrated by way of example and are not limited to the figures of the accompanying drawings. Like references herein can indicate like elements. [Figure 1] FIG. 1 shows an illustrative example of a block diagram of a user device, namely a secure unit, for performing secure communication according to various embodiments described herein. [Figure 2] FIG. 2 shows a block diagram of one exemplary secure unit for secure communication according to various embodiments described herein. [Figure 3]Figure 3 shows an example of an encryption key table that can be used by a secure unit for secure communication according to various embodiments described herein. [Figure 4] Figure 4 shows a flowchart of one exemplary method by a secure unit for performing secure communication according to various embodiments described herein. [Figure 5] Figure 5 shows an illustrative example of a block diagram of components related to the exemplary secure unit of FIG. 1 for secure communication according to other embodiments described herein. [Figure 6] Figure 6 shows a flowchart of one exemplary method by the secure unit of FIG. 5 for performing secure communication according to other embodiments described herein. **DETAILED DESCRIPTION OF THE INVENTION**

[0028] The terms used herein are for the purpose of describing particular embodiments only and are not intended to be limiting of the present invention. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed items. As used herein, the singular forms “a”, “an”, and “the” are intended to include the plural forms as well as the singular forms unless the context clearly dictates otherwise. The term “comprises” and / or “comprising” when used herein, specifies the presence of the stated features, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, steps, operations, elements, components, and / or groups thereof.

[0029] Various exemplary embodiments are described more fully with reference to the accompanying drawings. It should be noted that certain structural and functional details disclosed herein are merely representative for the purpose of illustrating the exemplary embodiments. The exemplary embodiments can be carried out in many alternative forms and should not be construed as being limited to the embodiments described herein.

[0030] The terms "first," "second," etc., can be used here to describe various elements, but these elements should not be limited by these terms, for such terms are used only to distinguish one element from another. For example, without departing from the scope of the embodiment, the first element can be referred to as the second element, and similarly, the second element can be referred to as the first element. Furthermore, the first and second elements may be implemented by a single element that can provide the necessary functionality of the separate first and second elements.

[0031] As used herein, the term “and” is used in both a conjugative and dejugative sense, and includes any and all combinations of one or more listed items relating to each other. It will be further understood that the term “comprises,” “comprising,” “includes,” and “including,” as used herein, identifies the presence of a listed feature, integer, step, behavior, element, and / or component, but does not preclude the addition of one or more other features, integers, steps, behaviors, elements, components, and / or groups thereof.

[0032] Unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as those generally understood by those skilled in the art to which the exemplary embodiments belong. It should also be noted that in some alternative implementations, the functions / operations described above may deviate from the order shown in the figures. For example, depending on the related functions / operations, two figures shown consecutively may actually be performed substantially simultaneously, and sometimes even in reverse order. Thus, while certain elements must be performed sequentially, others may be performed asynchronously.

[0033] definition

[0034] As used herein, the term “computer” refers to a machine, apparatus, or device that can accept and execute logical operations from software code. The terms “application,” “software,” “software code,” or “computer software” refer to any set of instructions that can operate a computer to perform an operation. Accordingly, the methods and systems of the present invention may be executed by a computer or computing device having a processor based on instructions from software or instructions provided by a computer application.

[0035] As used herein, the terms “secure device” and “secure unit” refer to a type of computing device that is generally capable of secure communication with other devices and computer servers. In some instances of this disclosure, such a secure device or secure unit is referred to as a “transmitter system” and / or “receiver system.” In some embodiments, the device is a smartphone or computer applied to receive and transmit data from a computer server or other device that may be operating locally or in the cloud. Non-limiting examples of devices include computer servers, computers, personal computers (PCs), IoT devices, portable communication devices such as smartphones, laptops, tablet PCs, wearable devices, robots, consumer products, industrial and manufacturing equipment, medical devices such as pacemakers, insulin pumps, and hearing aids, and communication systems installed in autonomous and non-autonomous vehicles such as automobiles, trains, aircraft, and other transport vehicles.

[0036] As used herein, the term “computer readable medium” refers to any medium involved in providing instructions to a processor for execution. Computer readable mediums can take many forms, including, but are not limited to, non-volatile media, volatile media, and transmission media. Non-volatile media include, for example, optical disks, magnetic disks, and magneto-optical disks such as hard disks or removable media drives. Volatile media include dynamic memory, such as main memory. Transmission media include coaxial cables, copper wires, and optical fibers, and include wires that make up a bus. Transmission media can also take the form of sound waves or light waves, such as those generated during wireless communication and infrared data communication.

[0037] As used herein, the terms “data network” or “network” refer to an infrastructure that connects two or more computers, such as client devices, by wire or wireless means, enabling the transmission and reception of data. Non-exclusive examples of data networks include wireless networks (i.e., “wireless networks”), which may include the Internet, Wi-Fi, and cellular networks. For example, a network may include a local area network (LAN), a wide area network (WAN) (e.g., the Internet), a mobile relay network, an ad-hoc network, a telephone network, a cellular network, or a Voice over IP (VoIP) network.

[0038] This disclosure should be considered as one example of the present invention and is not intended to limit the invention to any specific embodiment illustrated by the following drawings or description.

[0039] It will be understood that many techniques and steps are disclosed in describing the present invention. Each of these has its own advantages, and each can also be used in conjunction with one or more, or in some cases all, of the other disclosed techniques. Therefore, for clarity, this description refrains from unnecessarily repeating every possible combination of the individual steps. Nevertheless, this specification and the claims should be read with the understanding that such combinations are entirely within the scope of the present invention and the claims.

[0040] Figure 1 shows two secure devices 101 and 102 that communicate securely with other devices 120 and 121, according to embodiments of the present invention, via communication channels 103 and 104. Suitable non-limiting communication channels for communication channels 103 and 104 may include, for example, telephone lines, wireless communication, the Internet, wired communication, microwave transmission, shortwave radio, or other forms of electronic or optical communication. Devices 101 and 102 are both non-orthogonal and therefore can communicate with multiple devices 120 and 121. 101 and 102 may be standalone devices or part of a more complex device such as a computer, mobile phone, or two-way radio. They may be stationary, as in the case of a computer server; mobile, as in the case of a mobile phone; or hybrid, as in the case of an autonomous vehicle, or pacemaker, or IoT device. Each of such devices 101 and 102 may operate as a transmitter system or a receiver system. The activation of devices 101 and 102 (and by extensions 120 and 121) may be event-driven in the sense that authorized users can initiate secure communication, or it may be always connected, as in the case of two computer servers within the same company. Communication between devices may be hybrid, being both event-driven and constant, as in the case of computer servers where communication with other computer servers is secure, but communication with mobile phones is only occasional.

[0041] Figure 2 illustrates the details of the secure communication establishment and methodology. In Figure 2, in one embodiment, the user engages the secure unit (SU) by pressing a “button” on a device, e.g., a mobile phone (101 or 102) in Figure 1. The button may be a physical, electrical, or electronic touch switch, or a pressure-sensitive area on a touchscreen. In another embodiment, it is always on and does not need to be activated by a button. Once the device is powered on, the security icon and biometric device are activated. After a specified number of simultaneous taps (e.g., three), a message appears on the device screen indicating that the device is in the “initialization phase”. During the initialization phase, three strong ciphers are loaded into registers 3, 4, and 5 (207, 211, and 208). If the registers are not loaded correctly, the program terminates. The device uses a biometric scanning device (215) to sense or “read” the biometric information of an authorized user. If the authorized user's biometric authentication, located in register 1 (206), matches the biometric authentication icon identification in register 2 (210), and the registers and program load correctly, the device signals “initialization complete” to the display, and then signals “operational phase” to the display. If the values ​​in 206 and 210 do not match, the SU is shut down. In one embodiment, the entire device (D1) may be shut down after receiving a mismatch message from the SU. Physical reasons such as signal loss, battery depletion, or similar events may also cause the initialization phase to fail and the program to terminate. Depending on the application, there may be a delay before another attempt is made. In a battlefield situation, there is no delay in the second attempt.In civilian settings, the delay may be as short as 15 seconds, or it may be longer as deemed necessary by usage. The delay time may be extended by providing a number of attempts, or after the maximum number of failed attempts in identity verification, the SU must be permanently shut down or reinitialized by resetting the password and / or identity. The process of resetting the password also relies on an encrypted message stored in register 6(212). Only authorized administrators can change the password or ID. This allows a failed device to be reissued or reset for another user.

[0042] During the operational phase, the SU encrypts the data bus 204 using a randomly generated cipher previously loaded into register 3 (207). Each cipher included in the SU in Figure 2 is symmetrical with respect to the second device. Therefore, the cipher must be entered into both devices. This can be done via an external device such as a memory card or USB device, or by an administrator using the reset password cipher in register 6 (212). Once the data bus is encrypted, the sending SU, D1, generates a message (M1) which includes encrypting the biometrics icon in register 2 (210), using the encrypted second cipher (message cipher) in register 4 (211) as the encryption cipher, the third cipher in register 5 (208) as the encryption cipher, optionally as CR, and appending the sender MAC address, receiver MAC address, and timestamp as plaintext. M1 is then sent to device D2 via the external network connection (201). 201 may be a transmitter for telephone, wireless network, wired network, microwave network, or other forms of optical or electronic communication.

[0043] Once the encrypted and plaintext handshake is received, the second device, D2, decrypts and verifies the received encrypted message, confirming that it is associated with the sender MAC address and verifying the timestamp. If D2 cannot verify the received message, the SU of device D2 is immediately shut down, assuming it is under attack. D2 can then store the message in isolated memory for forensic purposes and shut down its SU. In one embodiment, the SU of D2 sends a negative acknowledgment back to the SU of D1. In one embodiment, if the SU of D2 verifies the message sent from D1, D2 performs the same identity verification process that D1 performed, and if successful, sends an acknowledgment message back to D1 from the network connection / transmitter (201). Once the handshake is complete, the message “communication enabled” is displayed on both devices.

[0044] Once secure communication is established between D1 and D2, D1 sends an encrypted message (M2) using the encryption key contained in register 5 (208). In one embodiment, M2 embeds a number of padded characters and a CR key. Two-way asynchronous communication can be performed between the devices. It is important to understand that the messages described in this invention may include, but are not limited to, data, text, voice, sound, image, video, or any combination of data types, and may be any embodiment of data that can be represented digitally.

[0045] Figure 4 shows the sequence of events in a graph.

[0046] It is important to understand that computer-generated keys are not truly random, but rather pseudo-random, meaning there is a (small or very small) bias in character generation. The smaller the bias, the more difficult it is to reverse-engineer the cipher. Only truly random ciphers need to be externally generated. Reusing a cipher over a period of time creates opportunities for malicious actors to eavesdrop and reveal the cipher using various techniques. In one embodiment of the present invention, all ciphers used are long enough to encode all messages. The message size limit can be set in a way that does not represent a practical problem or user inconvenience. The reason messages must be long enough is to prevent repetition in the use of the cipher by rolling it to the beginning of the cipher if the message exceeds the length of the cipher. In one embodiment, each device has a set of ciphers similar to a One Time Pad. Each cipher is discarded once used. The capacity of the number of ciphers or characters in a cipher depends on the size of the memory, and the price of memory continues to fall.

[0047] The use of cryptography can be one of many transformation or substitution techniques that require the use of a cryptographic key. These techniques are in the public domain, and any of them can be employed in this embodiment. Similarly, if both use the same technique, a new transformation or substitution technique may be used at the user-pair's request. The use of a non-public transformation or substitution technique does not in any way alter the originality of the invention.

[0048] In one embodiment, the SU receives a message and uses one of a number of cryptographic techniques to encrypt the message using an appropriate cipher (the message cipher of register 4(211)). In one embodiment, the encrypted message to be transmitted may be in the form of non-ASCII characters.

[0049] As described above, for true security, the keys are random, used only once, and new keys are provided on both sides. However, it is possible to generate a new, completely random key from an existing random key. The classical definition of a random number is that the next character in a string cannot be determined or predicted in any way from the preceding characters. In a simple example, assume the key is 100 characters (K) used to encrypt a 40 - character message (CM). Random padding characters (P) are added by using the next few characters to determine the number of padding characters. These padding characters are also encrypted here using the cipher. The message length is, here, CM + P < K. Since each character in K is random, starting from any position in the key (K1...K100) and wrapping around to the beginning can also be assumed to be random. A new key (NK) can be established for the next message by rotating the key by simply starting the next message at the position of CM + P + 1, so that the next message length shown starts beyond K100 and starts again at K1(M + P + 1) mod (100). Alternatively, the key for each pair of devices can be changed by using the starting key or taking N characters after CM + P + 1 and applying any number of transformations to the existing key to rotate the key in order to generate a new random key. Assuming the fact that the key sequence is random, the rearrangement of the random key based on picking a part of the key that is also random generates another random key. What makes it difficult to steal the encrypted message is that the encrypted message changes for each consecutive message, thus making it impossible for a malicious person to use normal brute - force or a given mathematical decryption technique. This methodology depends on D1 and D2 remaining synchronized with each other regarding the message length.

[0050] In one embodiment, the encryption used for the device to transmit top secret drone video messages in real time remains unchanged until the end of the session, and the closing or session end message includes code to create a new key (NK) using the aforementioned technology.

[0051] In one embodiment, the SU includes a lookup table of n re-randomized cryptographic update keys (Figure 3), if n is sufficiently large. What is embedded in the message M can be plaintext or an encrypted reference to the lookup table. The lookup table uses the index of the provided table and then modifies the cryptographic key based on the re-randomizer. At the end of each message or session, depending on usage, the SU re-creates a new random key that is usable once. Both the sending and receiving devices modify the cryptographic key using the same re-randomizer. The re-randomization or cryptographic update process can be one of many standard substitution, nth elimination, or dislocation techniques. The re-randomized (cryptographic update) key itself is random or sufficiently random. Since the initial key is random, the CR key is random, and any permutation based on the re-randomized key generates another random key.

[0052] Communication between D1(101) and D2(102) terminates when either device terminates the session or issues a session termination message (MT). The message is sent in plaintext along with the sending MAC address, receiving MAC address, and timestamp. The reason the MT is sent in plaintext is obvious: to avoid exposing keys unnecessarily, it is desirable not to encrypt and send things that do not need to be encrypted. Alternatively, the session is terminated by one of many abends, such as signal loss, power loss, or message quality degradation, using standardized methods to measure such behavior. Signal quality is monitored by an external device in the CPU of device (214) of the SU, which communicates the status abend to the CPU (204) of the SU, and then terminates the message.

[0053] In one embodiment, SU is a component of device D1…DN that does not require biometric authentication. The device may not have human contact. This could be one device D1 in communication, or devices D1 and D2 on both sides. An example of one side of communication would be a mobile phone connecting to a server, such as a personal bank account on the internet. The server is known to be secure and resides behind a locked door, such as within a server firm. A second example is a soldier in a battlefield making contact with a drone. If the drone does not make human contact in the air, the soldier would need to identify themselves and verify them using the process described above. There are many examples of one- or two-sided non-human contact that do not require biometric authentication, as secure trust has been established beforehand. All other protocols of the device remain the same.

[0054] In one embodiment, an SU may be protected from physical attack or intrusion by having one or more of several protection methods. To prevent someone from "reading" a microscopic circuit gate using an X-ray device, a thin layer of X-ray-attenuating metallic material may be used to surround the integrated circuit. Similarly, circuits and junctions dissipate heat. Heat patterns can be "read" by a malicious actor. A thin layer of aluminum absorbs the heat, making it impossible to read.

[0055] To prevent microscopic punctures and insertions of a microscope camera for "reading" the circuit, in one embodiment, the SU may be sealed so that it is impregnated with an inert gas and creates a constant pressure within the SU. Any microscopic puncture would release the gas. Inside the SU, there is a microscopic pressure sensor and a battery (215) that constantly transmits pressure and compares it to a normal pressure level stored in register #7 (209). If the pressure changes beyond an acceptable level, the gas pressure sensor triggers the battery, destroying the key circuit of the SU.

[0056] Figure 5 shows a schematic block diagram 500 of an alternative embodiment relating to secure devices 101 and 102 of Figure 1, and a secure device 108 for secure communication over network 510 in accordance with this disclosure. In Figure 5, secure device 101 includes a processor 140 having an input communicatively coupled to a data source 150. The processor 140 is also communicatively coupled to the output of a network interface 160, which is then connected to an antenna 190 for use in a conventional 5G cellular network supporting IoT devices, for example. The processor 140 is further connected to a cryptographic selection circuit 170 and a memory module 180, which include a list of cryptographic keys, which may include, for example, a re-randomized cryptographic key table shown in Figure 3. In addition, an optional tamper sensor 198 is shown connected to the processor 140, the cryptographic selection circuit 170, and the memory module 180.

[0057] Secure devices 102 and 108 include processors 142 and 145, respectively, which have inputs communicatively coupled to data sources 152 and 155. Processors 142 and 145 are also communicatively coupled to network interfaces 162 and 165, and then connected to antennas 192 and 195, respectively. Processors 142 and 145 are further connected to cryptographic selection circuits 172 and 175, and memory modules 182 and 185, which contain lists of cryptographic keys.

[0058] It should be readily apparent that the type and nature of the data sources and network interfaces used for data sources 150, 152, and 155, and network interfaces 160, 162, and 165, are not important for carrying out the embodiments described. Suitable data sources may include, for example, sources that provide digital information representing text, symbols, images, audio, and / or video, or any combination thereof. Suitable network interfaces may include commercially available network interface adapters and / or wireless network interface components, depending on whether the secure device operates on a wired and / or wireless network. Similarly, the type and nature of the processors used for processors 140, 142, and 145 are not important for carrying out the embodiments described, and commercially available microprocessors or processor systems and / or application-specific integrated circuits or components are suitable for use with the embodiments described.

[0059] The disclosed embodiments implement an improved cryptographic communication method such that each secure device's memory module includes at least one list of cryptographic keys which is identical to the corresponding list of cryptographic keys in the memory module of the secure device authorized to perform secure communication. For example, if secure device 101 is authorized to communicate with secure devices 102 and 108, but secure devices 102 and 108 are not authorized to communicate with each other, then the memory module 180 of secure device 101 includes at least two lists of cryptographic keys: a first list which is available for communication with secure device 102 and includes a copy of the first list of cryptographic keys, and a second list which is available for communication with secure device 108 and includes a copy of the second list of cryptographic keys. However, the memory modules 182 and 185 of secure devices 102 and 108 each include only a single list for communication with secure device 101 and do not include any additional lists of cryptographic codes for communication with each other. Furthermore, as mentioned above, using random numbers or characters for the cryptographic keys in the list of cryptographic keys is advantageous; however, the use of pseudorandom numbers or sequences can still provide a relatively high level of security, particularly in terms of the critical use of the cryptographic selection circuit used in the embodiments described herein.

[0060] In this embodiment, the cryptographic selection circuits of two secure devices permitted to communicate with each other generate selection codes that indicate the message encryption key, message decryption key, handshake message encryption key, and handshake message decryption key, based on an identical list of cryptographic codes in their respective memory modules, and implement the same algorithm for corresponding reading. Each time a new secure device initiates a new communication session with another secure device, a selection code for the new secure device is generated. A communication session may include, for example, a single message, an exchange of a predetermined number of messages, or an exchange of messages over a specific period. Alternatively, a communication session may terminate after a predetermined time in which no further message exchanges occur.

[0061] The specific selection code generation process used by the selection circuit of the initiating secure device in step 610 may be any default process for generating a code understandable by the receiving device to identify the specific cryptographic keys to be used as the message encryption key, message decryption key, handshake message encryption key, and handshake message decryption key. Such a selection code may indicate, for example, the location of the cryptographic key in the list of ciphers in the memory module, the starting bits to be performed on the cryptographic key at the indicated location, and / or a specific transformation. Such transformations may include, as described above, inverting all or part of the cryptographic key, constructing such a cipher based on each or n bits in the stored cryptographic key sequence, using selected sections of bits and characters of the cryptographic key, and combining the results of performing different cryptographic keys or some mathematical operations on such cryptographic keys.

[0062] As shown in Figure 5, it is advantageous for such cryptographic selection circuits 170, 172, and 175 to implement the same algorithm using hardware. Suitable hardware for this purpose may include, for example, gate arrays, programmable gate arrays, application-specific integrated circuits, and such hardware integrated into their respective processors. However, it is also advantageous to implement such cryptographic selection algorithms in hybrid hardware and software.

[0063] The cryptographic selection circuits 170, 172, and 175 can implement any number of different techniques and / or algorithms, including assigning a predetermined portion of the resulting selection code to a cryptographic key position in an associated list of cryptographic keys for a receiving secure device, a starting number or bit in such a cryptographic key, and transformations performed to generate a message cryptographic key, a message decryption cryptographic key, a handshake message cryptographic key, and a handshake message decryption cryptographic key. The complexity of such techniques and algorithms may be based on the desired level of computer security required by the intended application of such secure communication between devices. A typical simple circuit increments the position of the cryptographic key in the list, and the starting number or bit at such a cryptographic key position, using corresponding transformations of alternating forward or reverse bit sequence transformations to generate a selection code sequence for a communication session between such secure devices. The cryptographic selection circuit may also include a hardware lookup table for associating the selection code with the corresponding cryptographic key, starting character, and transformations.

[0064] One of the countless techniques and algorithms that can be performed by cryptographic selection circuits 170, 172, and 175 involves an exemplary nine-digit decimal selection code. Such nine-digit decimal numbers represent the message encryption key, message decryption key, handshake message encryption key, and handshake message decryption key, which are transmitted as a handshake message using an address, such as the 12-digit hexadecimal MAC address of the receiving secure device. For these encryption keys, the selection code indicates the positions of four encryption keys in the respective lists of encryption keys in the memory modules of the initiating and receiving secure devices, the positions of the starting numbers at those positions, and the steps between each number in the key at those positions, as well as whether the number sequence is arranged in a forward or reverse sequence to generate the message encryption key, message decryption key, handshake message encryption key, and handshake message decryption key.

[0065] According to such techniques or algorithms, if the selection code is a 9-digit decimal number represented as a forward sequence X=N1 to N9 and a reverse sequence Y=N9 to N1, then the location of the key position in the memory module can be represented as follows:

[0066] Location L1 = [ABS(XY)*SQRT(X) / (X)] (when generating a message encryption key)

[0067] Location L2 = [ABS(XY)*SQRT(Y) / (X)] (when generating a message decryption encryption key)

[0068] Location L3=[ABS(XY)* SQRT(X) / (Y) (When generating an encryption key for the handshake message)

[0069] Location L4=[ABS(XY)* SQRT(Y) / (Y)] (When generating a decryption key for the handshake message)

[0070] Next, the first key number of the resulting cryptographic key can be taken from location [LM+1], where M = 1, 2, 3, or 4, and the step between each cryptographic key digit at such locations to form a specific cryptographic key used in communication is, for example, the number of digit N5. Finally, the forward or reverse step direction is based on the selected code digit location N9, where, for example, if N9 is odd, the step direction is forward, and if N9 is even, the step direction is reverse. It should immediately become clear that many other techniques and algorithms can be used in generating and decrypting the selected code to initiate a message session.

[0071] In addition, the cryptographic selection circuits 170, 172, and 175 can be advantageously employed as part of an algorithmic re-randomizer, for example, by employing the re-randomizer technique described above with respect to Figure 3, or other re-randomizer techniques. The use of re-randomizer techniques by the cryptographic selection circuits 170, 172, and 175 can dramatically increase the number of random cryptographic keys that can be generated from the number of cryptographic keys contained in the list of cryptographic keys in any of the memory modules 180, 182, and 185 available between the two secure devices.

[0072] In accordance with this embodiment, as described below with respect to Figure 6, the selection code transmitted by the initiating secure device and received by the secure device is intended to be used as follows: Since the initiating and receiving secure devices are pre-approved to communicate with each other, i.e., as mutually known secure devices, they include corresponding selection circuits and a common list of cryptographic keys in their memory modules. Once the receiving secure device receives the selection code and an indicator of the initiating secure device's identity and / or address in the initiating handshake message from the initiating secure device, it can use such selection code and the selection circuits and indicators for its memory modules based on the initiating secure device's identity and / or address to generate a message encryption key, a message decryption key, a handshake message encryption key, and a handshake message decryption key, as in the initiating secure device. Once the receiving secure device has generated such an identical set of cryptographic keys, it generates and transmits a response handshake message, among other things, including two data sequence segments. The first segment of such a segment is a data sequence corresponding to the message encryption key encrypted by the handshake message encryption key, and the second segment is a data sequence corresponding to the message decryption key encrypted by the handshake message encryption key.

[0073] Figure 6 is an illustrative flowchart of Method 600 relating to the operation of secure devices 101, 102, and 108 for establishing secure communication for a communication session. The following description of Figure 6 will be made with reference to the devices and components shown in Figure 5. If a secure user device 101 wishes to initiate a communication session with, for example, a secure device 102, the processor 140 initiates Method 600 by performing step 610, which involves activating the cryptographic selection circuit 170 and providing at least an identifier of the secure device 102 for the generation of a selection code.

[0074] In step 620, the processor 140 generates a handshake message containing the generated selection code and the unencrypted network addresses of secure device 101 and other secure devices, namely secure device 102. The generated handshake message may optionally include a timestamp indicating the time the handshake message is sent. Next, in step 630, the processor 140 sends the generated handshake message to secure device 102 via network interface 160 and network 510.

[0075] Next, in step 640, the processor 140 determines whether the secure device 101 has received a response handshake message sent by the secure device 102 over the network 510. If such a message is not received within a specific time interval after the initial handshake message is sent, method 600 terminates and secure communication is not initiated. In such a case, the processor 140 may preferably wait for a certain period before executing method 600 again in an attempt to establish secure communication with the secure device 102. It is appropriate to include a timestamp in the handshake message so that the receiving secure device 102 can determine whether a security threat exists by evaluating the time elapsed between the time indicated in the timestamp and the time the handshake message was received. If it is determined that an excessive amount of time has elapsed, the secure device 102 does not send a response handshake message back to the secure device 101.

[0076] If the response handshake message is received in a timely manner by the secure device 101 in step 640, the processor 140 begins processing the response handshake message in step 650. If the response handshake message from the secure device 102, which has properly interpreted the received selection code, is valid, the response handshake message should consist of at least two segments, as described above with respect to Figure 5. The first segment is a data sequence corresponding to the message encryption key, encrypted by the handshake message encryption key, and the second segment is a data sequence corresponding to the message decryption key, encrypted by the handshake message decryption key. The processing performed by the processor 140 in step 650 is to decrypt the first and second segments using the handshake message encryption key and the handshake message decryption key, respectively, to generate the first and second data sequences, which should be the message encryption key and the message decryption key, respectively.

[0077] In step 660, the processor 140 compares the first and second data sequences with the expected message encryption key and message decryption key, and if no match is found, terminates method 600 so as to indicate a potential cyber threat and does not allow the secure device to enter the message transmission phase. However, if in step 660 the processor 140 finds a match with the message encryption key and a message decryption key is found, the method proceeds to step 670.

[0078] In step 670, secure device 101 generates an encrypted message that operates in the transmission phase of the communication session and is sent to secure device 102 via network interface 160 and network 510 by encrypting the message received from data source 150 with a message encryption encryption key. Optionally, secure device 101 may initiate by sending a verification or acknowledgment message to secure device 102 indicating that the response handshake exchange contained information that may occur for a communication session in which secure communication between devices has been initiated.

[0079] Conversely, during the transmission phase, the secure device 102 may use the message encryption encryption key to decrypt the received encrypted message and then use the message decryption encryption key to encrypt the message before sending the resulting encrypted message to the secure device 101.

[0080] Those skilled in the art should understand that the specific encryption method using each encryption key is not important for implementing the embodiments described herein. Suitable encryption techniques include, for example, existing encryption techniques of displacement or substitution ciphers, Advanced Encryption Standard ("AES") techniques, Rivest-Shamir-Adleman ("RSA") encryption, Triple Data Encryption Standard ("Triple DES"), Blowfish, and other known and non-standard encryption techniques. In another embodiment of the present invention, the cipher encrypts the message by substitution using a non-ASCII character set.

[0081] The present invention provides a system and method for transmitting computationally secure encrypted information, where the likelihood of such transmitted information being decrypted in a reasonable amount of time or using the processing power of a typical computer is extremely low. The system and method advantageously utilize (1) a memory module containing a separate but shared list of cryptographic keys that are approved, i.e., known, and usable to generate secure encrypted communications between secure devices, and (2) a combination of cryptographic key selection and corresponding code generation techniques implemented partially or entirely in hardware. Such a combination facilitates the implementation of unpredictable or nearly unpredictable cryptographic keys, because even if a hacker somehow knows which cryptographic keys were used in a previous communication session, such hacker cannot predict which cryptographic keys will be used in future communication sessions based on those known cryptographic keys.

[0082] The systems and methods of these embodiments also, advantageously, do not require the intermittent software updates required by software-based encryption techniques, thus preventing an increasing ability of hackers to hack into communications of software-based secure devices. A hacker would need to access and reverse engineer the secure device, and somehow determine which specific other secure devices the list of cryptographic keys in the memory module can be used for secure communication with in order to hack the systems and methods of the embodiments described herein, as well as, in embodiments using an encrypted data bus, the encryption method and cryptographic keys used to encrypt such data bus.

[0083] To prevent access to and reverse engineering attempts on these components of the secure device, additional components may be included in embodiments of the present invention to prevent X-rays, micro-drilling, or any other mechanical or optical means aimed at revealing the contents of such components, including, for example, the cryptographic selection circuits 170, 172, and 175, memory modules 180, 182, and 185, and / or processors 140, 142, and 145 shown in the embodiment of Figure 5.

[0084] For this purpose, it is advantageous to use a mechanism having such components, which can detect and / or otherwise prevent reverse engineering efforts to render the contents of the circuit and memory unreadable and / or undiscernible. For example, metal shielding of these components can be used to prevent the acquisition of X-ray images. In addition, the components reside in an enclosure containing pressurized inert gas and may include a tamper sensor, such as the tamper sensor 190 shown in the secure device 101 of Figure 5, and an associated battery or power supply. Such a tamper sensor 198, for example a pressure sensor, detects a mechanical attempt to access the components, such as micro-drilling, which causes the release of such gas, and based on the corresponding pressure drop detected by the tamper sensor 198, the battery is connected to the components in such a way that the components are destroyed to some extent, becoming unreadable and / or unerasable. The pressure sensor and battery 215 described above with respect to Figure 2 are suitable for use as the tamper sensor 198 and associated battery (not shown) of Figure 5.

[0085] To further enhance the security level of such systems, it would be advantageous for the cryptographic keys in the list of cryptographic keys to have a bit length and / or character length at least equivalent to the length of the largest (or typical) message transmitted by the secure device during a communication session, and preferably at least five times the length of the largest (or typical) message, or most preferably at least 10,000 characters. It is possible to use cryptographic keys with shorter bit lengths using conventional techniques, such as cryptographic padding or wrapping to at least extend to the length of the message being transmitted, but this reduces security.

[0086] To provide further enhanced security using the secure communication systems and methods described herein, it is advantageous not to reuse cryptographic keys, particularly random cryptographic keys, once they have been used in a secure communication session between secure devices. This is because it makes it impossible or extremely difficult for hackers or cryptoanalysts to use any statistical analysis or pattern matching. If the acceptable level of security for communication between secure devices is lower, reusing cryptographic keys used for communication between devices may only be acceptable after a long time interval, for example, on the order of months or years, and / or after a sufficient number of communication sessions have occurred, depending on the acceptable level of security for the application.

[0087] Furthermore, it is desirable to provide a list of different cryptographic keys in the memory module for communicating with specific other devices, in a list of at least 1 million, preferably 100,000,000 or more, and most preferably 250,000,000 or more. Those skilled in the art will understand that for a secure device, there are a considerable number of ways to track the use of cryptographic keys, including, for example, a list of used cryptographic keys in the non-volatile memory within the secure device, or some other indicator.

[0088] Depending on the required level of security, it may be appropriate to use a single handshake encryption key to initiate communication between secure devices in a communication session. Here, the handshake message encryption key and the handshake message decryption encryption key are the same key. Similarly, if a lower level of security is acceptable, it may be appropriate to use a single encryption encryption key for messages exchanged between two secure devices. Here, such a single encryption encryption key may be used symmetrically for message encryption and message decryption. Furthermore, to significantly enhance security, a selection code generated by a secure device may instruct other secure devices to use different message ciphers, such as through encryption key hopping, to encrypt individual messages sent during the transmission phase of a single communication session. Here, the selection circuit establishes a sequence of encryption encryption keys to be used during such a communication session.

[0089] Random cryptographic keys, such as those included in a list provided within a memory module, can be generated using techniques, including well-known techniques, based on monitoring at least one random property of the time-dependent counting of elements of physical properties. For example, as described in "Hardware Key Generation" by Roger R. Dube, and "Hardware-based Computer Security Techniques to Defeat Hackers: From Biometrics to Quantum Cryptography" by John Wiley & Sons, pp. 47-50 (2008). ISBN 978-0-470-42547-3. In one embodiment, random data usable for cryptographic keys can be derived by hardware access to data generated by processes of a truly nondeterministic nature, such as data representing radioactive decay and electron tunneling in electronic components, both of which are nondeterministic phenomena generated by events occurring at the quantum subatomic level. Random data usable for such encryption keys can be obtained additionally or alternatively by collecting and processing the output from a Geiger counter or Zener diode. Furthermore, for the highest level of security, it is desirable for the memory module to contain a list of random encryption keys, but for many applications, it is possible to use random encryption keys within the memory module, or a combination of random and pseudo-random encryption.

[0090] To further enhance the security of secure devices, it would be advantageous to encrypt the data bus or signals transmitted over the data bus, thereby preventing any reverse engineering efforts that would involve probing the signals to gain an understanding and predictability of the encryption / decryption keys for any given communication session.

[0091] Furthermore, to further enhance security, the response handshake message sent by the receiving secure device may include a third data sequence segment containing a predetermined encrypted identifier that characterizes the receiving secure device and / or its associated user or operator, which would be anticipated by the initiating secure device. Such identifiers of the secure device and / or user may be arbitrary codes, numbers or data sequences, or may be generated by the execution of an algorithm known to the receiving and initiating secure devices. Such referenced algorithms may be, for example, mathematical formulas implemented in hardware or a combination of hardware and software, which generate a unique identifier for the receiving secure device. Alternatively, such unique identifiers may be a pre-selected cryptographic key sequence at a pre-selected position in a list of cryptographic keys for the receiving secure device, for example, the last cryptographic key in such a list of cryptographic keys, either alone or transformed in a predetermined manner. Next, in the execution of method 600, steps 640 to 660 further include (a) decoding a third segment of a response handshake message in order to obtain a third data sequence; (b) comparing such third data sequence with a default identifier; and (c) if the data sequence corresponds to a default identifier, allowing the system to enter the transmit phase.

[0092] In another embodiment, once the initiating secure device confirms that the response handshake message contains the expected information, the two communication secure devices can use multiple message encryption and decryption keys. Here, different message encryption keys are selected to encrypt different messages during the transmission phase of the communication session by performing a symmetric selection algorithm, which may be implemented in the selection circuit.

[0093] While many of the embodiments described herein are intended for secure communication between an initiating secure device and individual or single receiving devices, the systems and methods may also apply to use in broadcast mode, where the initiating secure device sends secure messages in a secure message session to a group, i.e., multiple receiving secure devices. According to such embodiments, the initiating device sends a handshake message, which is an initial broadcast alert message, without an expected response message from the intended recipient secure device. Such a handshake message or initial broadcast alert message may include, for example, a broadcast group number GN (instead of a single receiving secure device address) and a selection code based on a message encryption key encrypted by a handshake message encryption key. As described above, such an initial broadcast alert message does not need to include a decryption message encryption key encrypted by a handshake message decryption key.

[0094] In such embodiments, a group number may be associated by a service provider with a specific set of secure receiving devices. For example, an automobile manufacturer may assign secure devices in vehicles manufactured for sale in a given region of a country to a specific group number for wireless software updates. Such a group number may consist of six digits with six padded zeros to be used, for example, in place of a 12-digit MAC address for an initial broadcast warning message. Also, for use in such an initial broadcast warning message, the selection code may be generated by a cryptographic selection circuit in a manner similar to that of the embodiments described above with respect to initiating secure device and single receiving device communication. As described above, the cryptographic selection circuit may include a hardware lookup table for associating the selection code with the corresponding cryptographic key, start character, and transformation. According to another representative technique or algorithm, a nine-digit decimal selection code can be represented as a forward sequence X=N1 to N9 and a reverse sequence Y=N9 to N1, and then the memory module location can be represented as follows:

[0095] Location L1 = [ABS(XY)*SQRT(X) / (X)] (when generating a message encryption key)

[0096] Location L2 = [ABS(XY) * SQRT(X) / (Y)] (when generating an encryption key for the handshake message)

[0097] Next, the first key number or character of the key can be taken from the location [LM+(GN*2,999)], where M=1 or 2. Then, the step between each digit in the key is S=N5. Finally, the forward or reverse step direction is based on the selection code digit position N9, where, for example, if N9 is odd, the step direction is forward, and if N9 is even, the step direction is reverse. It should immediately become clear that many other techniques and algorithms can be used in generating and decoding selections to initiate a broadcast message session.

[0098] The present invention has been shown and described herein with reference to preferred embodiments and specific examples thereof, but it will be immediately apparent to those skilled in the art that other embodiments and examples can perform similar functions and / or achieve similar results. All such equivalent embodiments and examples are in the spirit and scope of the present invention, are considered thereby, and are intended to be covered by subsequent claims. In particular, the present invention has been described herein as including individual and distinct components in a secure device, namely a processor, cryptographic selection circuit, and memory module as distinct components, but it is possible to combine such components and / or their functions into fewer components or a single security component.

[0099] The present invention is further explained by the following numbered paragraphs.

[0100] 1. A secure device system for transmitting encrypted communications over a network, comprising the following:

[0101] a. A processor having an input for receiving at least one message to send to a first other secure device, and coupled to at least one data bus.

[0102] b. A memory module that is communicatively coupled to the processor and stores a list of at least one cryptographic keys for use in communication with the first other secure device, wherein the first other secure device has a memory module having a memory in which a copy of the list of at least one cryptographic keys is stored.

[0103] c. A cryptographic selection circuit coupled to the processor, wherein the cryptographic selection circuit is applied to generate a selection code indicating a message encryption key, a message decryption key, a handshake message encryption key, and a handshake message decryption key based on at least one list of cryptographic keys, and the corresponding cryptographic selection circuit of the first other secure device is applied to process the selection code to generate copies of the message encryption key, the message decryption key, the handshake message encryption key, and the handshake message decryption key from a stored copy of at least one list of cryptographic keys in the memory of the first other secure device.

[0104] d. A network interface that is communicatively coupled to the processor and is applied to transmit digital information over a network to and receive from the first other secure device.

[0105] The processor operates in the initialization phase by activating the cryptographic selection circuit to generate the selection code, and is configured to generate a handshake message and send it to the first other secure device via the network interface, the handshake message including the unencrypted network addresses of the secure device and the first other secure device, and the selection code.

[0106] The processor, upon receiving a response handshake message transmitted by the first other secure device, operates in the confirmation phase and applies the first and second segments of the response handshake message to process them, respectively, using the handshake message encryption key and the handshake message decryption key, to obtain a first data sequence and a second data sequence, compare the first data sequence with the message encryption key and compare the second data sequence with the message decryption key to confirm that the first data sequence and the second data sequence correspond to the message encryption key and the message decryption key, respectively, associated with the selection code.

[0107] Once the acquired first data sequence and second data sequence are confirmed to correspond to the message encryption key and message decryption key, respectively, associated with the selection code, the processor further operates in the transmission phase by encrypting at least one message received at input based on the message encryption key, and is applied to transmit the resulting encrypted at least one message to the first other secure device via the network interface.

[0108] 2. The system according to paragraph 1, wherein the processor is further adapted to operate in the receiving phase by decrypting at least one message received from the first other secure device based on the message decryption encryption key.

[0109] 3. The system described in paragraph 1, wherein the message encryption encryption key is at least the same length as a predetermined length of the message to be encrypted.

[0110] 4. The system according to paragraph 1, wherein the cryptographic selection circuit is applied to generate the selection code based on the cryptographic key positions of four cryptographic keys in at least one list of cryptographic keys.

[0111] 5. The system according to paragraph 1, wherein the cryptographic selection circuit is further applied to the selection code corresponding to at least one of the four cryptographic keys, together with the list of at least one cryptographic key, to generate a transformation of at least one cryptographic key at the cryptographic key position.

[0112] 6. Such transformation of at least one cryptographic key is the method described in paragraph 5, which is the re-randomization of at least one cryptographic key.

[0113] 7. The system according to paragraph 1, wherein the processor is applied to retrieve a data bus cipher code from the memory module for at least one of encrypting or decrypting signals received and transmitted over the at least one data bus.

[0114] 8. The system described in paragraph 1, wherein the system is applied to send encrypted messages to at least a second other secure device, and at least one list of cryptographic keys stored in the memory module includes a list of cryptographic keys useful for encrypting the messages to the second other secure device.

[0115] 9. The system described in paragraph 8, wherein at least one list of cryptographic keys stored in the memory module includes a list of cryptographic keys usable with respect to the first secure device and at least the second secure device.

[0116] 10. The system described in paragraph 9, wherein the indicators of the first secure device and at least the second secure device are stored in the memory module and associated with the respective lists of cryptographic keys available for use on the first secure device and at least the second secure device.

[0117] 11. The system described in paragraph 1, wherein the at least one cryptographic key list includes at least 1,000,000 cryptographic keys.

[0118] 12. The system described in paragraph 1, wherein the list of at least one cryptographic key includes a number of cryptographic keys corresponding to at least one number of bits of the message to be sent to the second other secure device.

[0119] 13. The system described in paragraph 11, wherein the at least one cryptographic key list contains a large number of cryptographic keys, and as a result, such a system does not repeat the use of any cryptographic key over a sufficiently long period of time.

[0120] 14. The system as described in paragraph 1, wherein the processor is configured not to proceed to the transmission phase if, during the verification phase, it is not possible to verify that the acquired first and second data sequences correspond to the respective message encryption and decryption encryption keys associated with the selection code.

[0121] 15. The system described in paragraph 1, wherein the processor is applied to generate a handshake message that further includes an unencrypted timestamp indicating the time of transmission of the unencrypted handshake message.

[0122] 16. The system according to paragraph 1, wherein the processor is further applied to generate a handshake message that includes an encrypted predetermined identifier indicating at least the characteristics of the first other secure device or the user of the first other secure device.

[0123] 17. The system according to paragraph 16, wherein the processor is further configured to (a) decode a third segment of a response handshake message to obtain a third data sequence, (b) compare the third data sequence with a predetermined identifier, and (c) enter the transmission phase if the data sequence corresponds to the predetermined identifier.

[0124] 18. The system for storing at least one list of cryptographic keys used for communication, the system described in paragraph 1, which includes at least one randomly generated key.

[0125] 19. The system described in paragraph 18, in which at least one randomly generated key is generated based on monitoring over time at least one random characteristic of the counting of elements of physical characteristics.

[0126] 20. The system according to paragraph 19, wherein the stored at least one randomly generated key is generated based on monitoring at least one random characteristic relating to the counting of at least one of the decay characteristics of an energized or nuclear atom.

[0127] 21. The system for storing at least one list of cryptographic keys used for communication, the system described in paragraph 1, wherein the system includes at least one pseudo-randomly generated key.

[0128] 22. The system described in paragraph 1, wherein the encryption selection circuit is applied to use a selection algorithm for selecting different message ciphers to encrypt different messages transmitted during the transmission phase of a communication session.

[0129] 23. The system as described in paragraph 1, wherein the cryptographic selection circuit is applied to generate selection codes that prevent the repetition of previously selected cryptographic codes for the four cryptographic codes used in the pre-communication session with the first other secure device.

[0130] 24. The system according to paragraph 1, further comprising a material that at least partially surrounds at least one of the processor, memory module, and cryptographic selection circuit, wherein the material can prevent X-ray images generated from at least one of the processor, memory module, and cryptographic selection circuit.

[0131] 25. The system described in paragraph 1 further includes the following:

[0132] A battery coupled to at least one of the processor and memory modules.

[0133] An inert gas placed in a cavity that at least partially surrounds at least one of the processor and memory.

[0134] A pressure sensor disposed within the cavity and coupled to the processor, wherein when the processor detects a signal from the pressure sensor indicating a sufficient pressure drop, the pressure sensor is configured to couple sufficient energy from the battery to at least one of the processor, memory module, and cryptographic selection circuit in order to prevent reading of at least one of the processor, memory module, and cryptographic selection circuit.

[0135] 26. The system according to paragraph 25, wherein the inert gas is selected to further provide heat dissipation.

[0136] 27. The system described in paragraph 1, wherein the encryption key for the handshake message and the encryption key for the handshake message are the same encryption key.

[0137] 28. The system described in paragraph 1, wherein the message encryption key and the message decryption key are the same encryption key.

[0138] 29. A secure device comprising a processor having an input for receiving at least one message to be transmitted to a first other secure device, and coupled to at least one data bus; a memory module for storing at least one list of cryptographic keys; a cryptographic selection circuit for generating a selection code based on the at least one list of cryptographic keys; and a network interface applied to transmit and receive digital information to and from the first other secure device, the secure device being implemented by a method comprising the following steps:

[0139] a. The processor invokes the cryptographic selection circuit to generate a selection code indicating a message encryption key, a message decryption key, a handshake message encryption key, and a handshake message decryption key based on at least one list of cryptographic keys, wherein the corresponding cryptographic selection circuit in the first other secure device is applied to process the selection code to generate copies of the message encryption key, a message decryption key, a handshake message encryption key, and a handshake message decryption key from the stored copy of the at least one list of cryptographic keys in the memory of the first other secure device.

[0140] b. The processor generates a handshake message including the unencrypted network addresses of the secure device and the first other secure device, and a selection code.

[0141] c. The step of sending the handshake message to the first other secure device.

[0142] d. The step of receiving a response handshake message from the aforementioned other secure device.

[0143] e. A step of processing the first segment and the second segment of the response handshake message, respectively, using the handshake message encryption key and the handshake message decryption key, thereby obtaining the first data sequence and the second data sequence.

[0144] f. A step of comparing the first data sequence with the message encryption key and the second data sequence with the message decryption key, wherein the first data sequence and the second data sequence correspond to the message encryption key and the message decryption key, respectively, associated with the selection code.

[0145] g. After confirming that the acquired first data sequence and the second data sequence correspond to the message encryption key and the message decryption key, respectively, associated with the selection code, the step is to operate in the transmission phase by using the message encryption key to encrypt at least one message received at input, and to transmit the resulting encrypted at least one message to the first other secure device via the network interface.

[0146] 30. The method according to paragraph 29, further comprising the step of operating in the receiving phase by decrypting at least one message received from the first other secure device based on the message decryption encryption key.

[0147] 31. The method according to paragraph 29, wherein the step of activating the cryptographic selection circuit includes generating the selection code based on the cryptographic key positions of the four cryptographic keys in at least one list of cryptographic keys.

[0148] 32. The method according to paragraph 29, wherein the message encryption encryption key is at least the same length as a predetermined length of the message to be encrypted.

[0149] 33. The method according to paragraph 29, wherein the step of activating the cryptographic selection circuit includes generating a selection code corresponding to at least one of the four cryptographic keys, which is a transformation of at least one cryptographic key at the cryptographic key position, using at least one list of cryptographic keys.

[0150] 34. The method described in paragraph 33, wherein such transformation of at least one cryptographic key is the re-randomization of such at least one cryptographic key.

[0151] 35. The method according to paragraph 29, further comprising the step of searching from the memory module for a data bus cipher code available for at least one to encrypt or decrypt a signal received and transmitted via the at least one data bus.

[0152] 36. The method according to paragraph 29, further comprising the step of sending an encrypted message to at least a second other secure device, wherein at least one list of cryptographic keys stored in a memory module includes a list of cryptographic keys that can be used to encrypt a message for transmission to the second other secure device.

[0153] 37. The method according to paragraph 36, wherein at least one list of cryptographic keys stored in the memory module includes a list of keys usable with respect to the first secure device and at least the second secure device.

[0154] 38. The method according to paragraph 37, wherein the addresses of the first secure device and at least the other secure devices are stored in the memory module and associated with the respective lists of cryptographic keys available to each of the first secure device and at least the second secure device.

[0155] 39. The method according to paragraph 29, wherein the at least one cryptographic key list includes at least 1,000,000 cryptographic keys.

[0156] 40. The method according to paragraph 29, wherein the list of at least one cryptographic key includes at least one cryptographic key corresponding to at least one bit number of the message to be sent to the second other secure device.

[0157] 41. The method according to paragraph 40, wherein the at least one cryptographic key list contains a large number of cryptographic keys, and as a result, such a system does not repeat the use of any cryptographic key over a sufficiently long period of time.

[0158] 42. The method according to paragraph 29, further comprising the processor preventing input to the transmission phase if, during the verification phase, the processor cannot verify that the acquired data sequence corresponds to a message cipher.

[0159] 43. The method according to paragraph 29, further comprising the step of generating the unencrypted handshake message including a timestamp indicating the time of transmission of the unencrypted handshake message.

[0160] 44. The method according to paragraph 29, wherein the step of a processor generating a handshake message further generates a handshake message that includes at least a predetermined encrypted identifier indicating the characteristics of a first other secure device or the user of a first other secure device.

[0161] 45. The method according to paragraph 44, further comprising: (a) decoding a third segment of a response handshake message to obtain a third data sequence; (b) comparing such third data sequence with a predetermined identifier; and (c) entering a transmission phase if the data sequence corresponds to a predetermined identifier.

[0162] 46. ​​The method described in paragraph 29, wherein at least one stored list of cryptographic keys used in communications includes at least one randomly generated key.

[0163] 47. The system according to paragraph 46, wherein the at least one randomly generated key stored is generated based on monitoring over time at least one random characteristic relating to the counting of the physical characteristics of elements.

[0164] 48. The method according to paragraph 47, wherein the stored at least one randomly generated key is generated based on monitoring at least one random characteristic relating to counting at least one of the elements of energized or nucleated atom decay characteristics.

[0165] 49. The method according to paragraph 29, further comprising the step of generating an unencrypted handshake message, which is to execute a selection algorithm for selecting different message ciphers to encrypt different messages that are sent during the transmission phase of a communication session.

[0166] 50. The method according to paragraph 29, wherein the step of generating an unencrypted handshake message further comprises executing a selection algorithm for selecting a message cipher from a list of at least one cipher code in a memory module, thereby preventing the repetition of a previously selected cipher code for a previous communication session with the first other secure device.

[0167] 51. The method according to paragraph 29, wherein the encryption key for the handshake message and the encryption key for the handshake message are the same encryption key.

[0168] 52. The method according to paragraph 29, wherein the message encryption key and the message decryption key are the same encryption key.

[0169] 53. A secure device for transmitting encrypted communications over a network to multiple other secure devices, comprising:

[0170] a. A processor having an input for receiving at least one message to send to a first other secure device, and coupled to at least one data bus.

[0171] b. A memory module that is communicatively coupled to the processor and stores a list of at least one cryptographic keys for use in communication with the first other secure device, wherein the first other secure device has a memory module having a memory in which a copy of the list of at least one cryptographic keys is stored.

[0172] c. A cryptographic selection circuit coupled to the processor, wherein the cryptographic selection circuit is applied to generate at least one selection code indicating a message encryption cryptographic key and a handshake message encryption cryptographic key based on at least one list of cryptographic keys, and the corresponding cryptographic selection circuit in each of the plurality of other secure devices is applied to process the selection code to generate copies of the message encryption cryptographic key and the handshake message encryption cryptographic key from a stored copy of at least one list of cryptographic keys in each of the plurality of other secure devices.

[0173] d. A network interface that is communicatively coupled to the processor and is applied to transmit digital information over a network to and from the plurality of other secure devices.

[0174] The processor operates in the initialization phase by activating the cryptographic selection circuit to generate the selection code, and is applied to generate a handshake message and send it to the plurality of other secure devices via the network interface, the handshake message including the unencrypted network addresses of the secure device and the first other secure device, and the selection code.

[0175] The processor is further configured to operate in the transmission phase by encrypting at least one message received at input based on the message encryption encryption key, and to transmit the resulting encrypted at least one message to the plurality of other secure devices via the network interface.

[0176] 54. A secure device comprising a processor having an input for receiving at least one message to be transmitted to a plurality of other secure devices, coupled to at least one data bus; a memory module for storing at least one list of cryptographic keys; a cryptographic selection circuit for generating a selection code based on the at least one list of cryptographic keys; and a network interface applied for transmission to the plurality of other secure devices, the secure device being implemented by a method comprising the following steps:

[0177] a. The processor invokes the cryptographic selection circuit to generate a selection code indicating a message encryption key and a handshake message encryption key based on at least one list of cryptographic keys, wherein the corresponding cryptographic selection circuit in each of the plurality of other secure devices is applied to process the selection code to generate copies of the message encryption key and the handshake message encryption key from the stored copies of the at least one list of cryptographic keys in the memory of each of the plurality of other secure devices.

[0178] b. The step of the processor generating a handshake message that includes an unencrypted group number associated with the plurality of other secure devices and the selection code.

[0179] c. The step of sending the handshake message to the plurality of other secure devices.

[0180] d. A step of operating in the transmission phase by encrypting at least one message received at input using the message encryption encryption key, and sending the resulting encrypted at least one message to the plurality of other secure devices via the network interface.

Claims

1. A system of secure devices that transmit encrypted communications over a network, a. A processor having an input for receiving at least one message to send to a first other secure device, It is coupled to at least one data bus. Processor and b. A memory module that is communicatively coupled to the processor, The first device stores a list of at least one cryptographic key for use in communication with other secure devices. Memory module and, c. A cryptographic selection circuit coupled to the processor, The cryptographic selection circuit is applied to generate a selection code that indicates a message encryption key, a message decryption key, a handshake message encryption key, and a handshake message decryption key, based on at least one list of cryptographic keys. Cryptographic selection circuit, d. A network interface that is communicatively coupled to the processor and is applied to transmit digital information over the network to and receive from the first other secure device, The aforementioned processor, In order to generate the aforementioned selection code, the cryptographic selection circuit is activated during the initialization phase, and It is applied to generate a handshake message and send it to the first other secure device via the network interface. The handshake message includes the unencrypted network addresses of the secure device and the first other secure device, and the selection code. The aforementioned processor further, Upon receiving a response handshake message transmitted by the first other secure device, the system operates in the confirmation phase and applies the first and second segments of the response handshake message to process them using the handshake message encryption key and the handshake message decryption key, respectively. Obtain a first data sequence and a second data sequence, compare the first data sequence with the message encryption key, and compare the second data sequence with the message decryption key to confirm that the first data sequence and the second data sequence correspond to the message encryption key and message decryption key, respectively, associated with the selection code, and Upon confirming that the acquired first data sequence and second data sequence correspond to the message encryption key and message decryption key, respectively, associated with the selection code, the processor further: It operates in the transmission phase by encrypting at least one message received at input based on the aforementioned message encryption encryption key, and, As a result, at least one encrypted message is applied to be sent to the first other secure device via the network interface. Network interface and A system that includes this.

2. The aforementioned processor further, Based on the message decryption encryption key, it is applied to operate in the receiving phase by decrypting at least one message received from the first other secure device. The system according to claim 1.

3. The processor is applied to retrieve data bus encryption codes from the memory module for at least one of encrypting or decrypting signals received and transmitted over the at least one data bus. The system according to claim 1.

4. The system is configured to send encrypted messages to at least a second secure device, and The list of at least one cryptographic key stored in the memory module includes a list of cryptographic keys useful for encrypting the message against the second other secure device. The system according to claim 1.

5. During the verification phase, if the processor cannot confirm that the acquired first data sequence and second data sequence correspond to the message encryption key and message decryption key associated with the selection code, respectively, the processor is configured not to proceed to the transmission phase. The system according to claim 1.

6. The list of at least one of the stored cryptographic keys for use in communication includes at least one randomly generated key. The system according to claim 1.

7. The list of at least one of the stored cryptographic keys for use in communication includes at least one pseudo-randomly generated key. The system according to claim 1.

8. The cryptographic selection circuit is configured to generate a selection code for the four cryptographic keys used in the pre-communication session with the first other secure device, preventing the repetition of previously selected cryptographic keys. The system according to claim 1.

9. The encryption key for the handshake message and the encryption key for the handshake message are the same encryption key. The system according to claim 1.

10. The message encryption key and the message decryption key are the same encryption key. The system according to claim 1.

11. It is a secure device, A processor having an input for receiving at least one message to send to another secure device, and coupled to at least one data bus, A memory module to store at least one list of encryption keys, A cryptographic selection circuit for generating a selection code based on at least one list of the aforementioned cryptographic keys, A network interface is applied to transmit digital information to and receive from the first other secure device, A method by which a secure device performs, a. The processor activates the cryptographic selection circuit to generate a selection code indicating a message encryption key, a message decryption key, a handshake message encryption key, and a handshake message decryption key based on at least one list of cryptographic keys. b. The processor generates a handshake message including the unencrypted network addresses of the secure device and the first other secure device, and a selection code. c. The step of sending the handshake message to the first other secure device, d. The step of receiving a response handshake message from the first other secure device, e. A step of processing the first segment and the second segment of the response handshake message, respectively, using the handshake message encryption key and the handshake message decryption key. Steps include obtaining the first data sequence and the second data sequence, f. A step of comparing the first data sequence with the message encryption key and comparing the second data sequence with the message decryption key, The steps include: confirming that the first data sequence and the second data sequence correspond to the message encryption key and the message decryption key, respectively, associated with the selection code; g. Once it is confirmed that the acquired first data sequence and the second data sequence correspond to the message encryption key and the message decryption key, respectively, associated with the selection code, The process involves: operating in the transmission phase by encrypting at least one message received at input using the message encryption encryption key, and then transmitting the resulting encrypted at least one message to the first other secure device via the network interface; Methods that include...

12. The above method further, The receiving phase includes the step of decrypting at least one message received from the first other secure device based on the message decryption encryption key, The method according to claim 11.

13. The above method further, The steps include sending an encrypted message to at least a second secure device, The list of at least one cryptographic key stored in the memory module includes a list of cryptographic keys that can be used to encrypt a message for transmission to the second other secure device. The method according to claim 11.

14. The above method further, The step includes preventing input to the transmission phase if the processor cannot confirm during the verification phase that the acquired data sequence corresponds to message encryption. The method according to claim 11.

15. The at least one list of the stored cryptographic keys used for communication includes at least one randomly generated key. The method according to claim 11.

16. The step of generating the aforementioned unencrypted handshake message further includes: The step includes executing a selection algorithm to choose different message ciphers for encrypting different messages sent during the transmission phase of a communication session, The method according to claim 11.

17. The step of generating the aforementioned unencrypted handshake message further includes: The step of executing a selection algorithm for selecting a message cipher from at least one list of cryptographic keys in the memory module, and preventing the repetition of a cryptographic key previously selected for a previous communication session with the first other secure device, The method according to claim 11.

18. The encryption key for the handshake message and the encryption key for the handshake message are the same encryption key. The method according to claim 11.

19. The message encryption key and the message decryption key are the same encryption key. The method according to claim 11.

20. A secure device for transmitting encrypted communications over a network to multiple other secure devices, a. A processor having an input for receiving at least one message to send to a first other secure device, It is coupled to at least one data bus. Processor and b. A memory module that is communicatively coupled to the processor, The first secure device stores a list of at least one cryptographic key for use in communication with other secure devices. Memory module and, c. A cryptographic selection circuit coupled to the processor, The cryptographic selection circuit is applied to generate at least one selection code that indicates a message encryption key and a handshake message encryption key, based on at least one list of the encryption keys. Cryptographic selection circuit, d. A network interface that is communicatively coupled to the processor and is applied to transmit digital information over the network to and from the plurality of other secure devices, The aforementioned processor, In order to generate the aforementioned selection code, the cryptographic selection circuit is activated during the initialization phase, and It is applied to generate a handshake message and send it to the multiple other secure devices via the network interface, The handshake message includes the unencrypted network addresses of the secure device and the first other secure device, and the selection code. The aforementioned processor further, It operates in the transmission phase by encrypting at least one message received at input based on the aforementioned message encryption encryption key, and, As a result, at least one encrypted message is applied to be sent to the plurality of other secure devices via the network interface. Network interface and A secure device, including one.

21. It is a secure device, A processor having an input for receiving at least one message to send to multiple other secure devices, and coupled to at least one data bus, A memory module to store at least one list of encryption keys, A cryptographic selection circuit for generating a selection code based on at least one list of the aforementioned cryptographic keys, A network interface applied for transmission to the aforementioned multiple other secure devices, A method by which a secure device performs, a. The processor activates the cryptographic selection circuit to generate a selection code indicating a message encryption cryptographic key and a handshake message encryption cryptographic key based on at least one list of cryptographic keys. b. The processor generates a handshake message including an unencrypted group number associated with the plurality of other secure devices and the selection code, c. The step of sending the handshake message to the multiple other secure devices, d. A step of operating in the transmission phase by encrypting at least one message received at input using the message encryption encryption key, and transmitting the resulting encrypted at least one message to the plurality of other secure devices via the network interface. Methods that include...

Citation Information

Patent Citations

  • Reprogrammable security for restricting piracy and making interactive content usable

    JP2011086313A

  • Determining the encryption key

    JP2015521003A

  • Secure communication method and system

    JP2018064268A

  • Dynamic Encryption Method, Terminal, and Server

    JP2018510592A

  • Systems and methods for decrypting network traffic in a virtualized environment

    JP2019516294A