256-Bit Key Update Protocol for Quantum-Resistant Transport Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptographic key update protocols, such as the AUTomotive Open System Architecture (AUTOSAR) secure hardware extension, are inadequate for updating cryptographic keys to 256-bit lengths, which are necessary for post-quantum security, as they do not provide sufficient transport security and are vulnerable to quantum computers.
Innovation Solution
A cryptographic key update system that employs a series of transmissions using advanced encryption standard (AES) and hash functions to securely update cryptographic keys to 256-bits, including symmetric key encryption, message authentication codes, and cryptographic validation operations, ensuring compatibility with existing systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the current AUTOSAR secure hardware extension key update protocol is used, then the system maintains compatibility with existing protocols and networks, but the transport security is weaker than required for 256-bit key updates
Solution Approach 1:
The key update protocol is divided into multiple distinct transmission stages (first transmission for parameters, second transmission for encrypted key, third transmission for authentication). Each transmission serves a specific security function, allowing the system to achieve 256-bit security requirements while maintaining modularity and manageable complexity in each individual protocol step.
2Reliability
If cryptographic keys are updated to 256-bit length for post-quantum security, then resistance against quantum and classical attacks is enhanced, but the current protocol infrastructure becomes insufficient
Solution Approach 1:
The protocol transitions from 128-bit key parameters to 256-bit key parameters across multiple transmission stages. The first transmission carries 256-bit parameters, the second transmission encrypts 256-bit keys, and the third transmission provides 256-bit authentication, systematically upgrading the cryptographic parameter strength to achieve quantum resistance while adapting the existing protocol framework.
3Reliability
If simple updates of the current secure hardware extension key update protocol are implemented, then the system maintains ease of implementation, but the transport security remains insufficient for 256-bit keys
Solution Approach 1:
The first transmission pre-establishes security parameters and authentication mechanisms before the actual key update occurs. By preparing the cryptographic context, parameters, and authentication keys in advance through the first transmission, the protocol ensures that subsequent key transmissions are protected with adequate 256-bit security without requiring complex real-time cryptographic operations during the key update itself.
Data Source
AI summary
Methods for updating 256-bit cryptographic keys by a cryptographic key update system include transmitting a first transmission, a second transmission, and a third transmission. The second transmission is a symmetric key encryption under a key encryption key of a concatenation of a plurality of parameters and a new cryptographic key. The sender derives the key encryption key by transforming an authentication key and a bit string of constant values based on a one-way compression function that is one of the following: a modification detection code 2 (MDC-2) cryptographic hash function with a 128-bit advanced encryption standard (AES-128) as the underlying block cipher, a modification detection code 4 (MDC-4) cryptographic hash function with the 128-bit advanced encryption standard (AES-128) as the underlying block cipher, the Hirose compression function with the 256-bit advanced encryption standard (AES-256) as the underlying block cipher, and a 256-bit hash function.


