Asymmetric Key Exchange for Secure Request Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computing infrastructure faces challenges in securely communicating requests, particularly due to unauthorized access and eavesdropping, especially when using symmetric key cryptography and shared encryption keys, which can compromise password reset processes.
Innovation Solution
Implementing a system that uses a public key and private key pair generated by agent software in the customer environment for encrypting communications between a client device and a customer environment through an intermediate provider environment, ensuring that the private key remains inaccessible within the provider environment, and utilizing multiple layers of encryption, such as transport encryption (e.g., SSL or TLS), to secure data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If symmetric key cryptography and shared encryption keys are used for communication, then communication simplicity is improved, but security is worsened due to unauthorized access and eavesdropping risks
Solution Approach 1:
The patent applies asymmetric cryptography (public-private key pairs) to replace symmetric key cryptography. The agent software generates a public-private key pair where the public key is shared with the provider environment for encrypting requests, while the private key remains securely stored in the customer environment for decryption. This asymmetric approach eliminates the need to securely share secret keys while maintaining communication simplicity.
Solution Approach 2:
The patent extracts the private key from the provider environment and keeps it exclusively in the customer environment. By removing the private key from the provider environment, the system eliminates the security risk of key compromise at the provider side while still allowing the provider to process encrypted requests. Only the public key is taken out and shared with the provider environment.
2Ease of operation
If encryption keys are stored in the provider environment for decryption, then decryption capability is improved, but security is worsened due to potential unauthorized access to keys
Solution Approach 1:
The patent extracts the private key from the provider environment and stores it exclusively in the customer environment. The provider environment only retains the public key, which cannot decrypt the encrypted requests. This extraction eliminates the security vulnerability of storing private keys in the provider environment while maintaining the ability to decrypt requests through the securely stored private key in the customer environment.
Solution Approach 2:
The patent introduces encrypted request data as an intermediary between the public key and private key. The provider environment encrypts requests using the public key, and the encrypted data serves as the intermediary that can only be decrypted by the private key in the customer environment. This intermediary mechanism allows decryption capability without requiring the provider to store or access the private key.
3Reliability
If multiple layers of encryption are implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent segments the encryption system into two distinct components: transport encryption (e.g., TLS/SSL) for protecting communication channels, and asymmetric encryption (public-private key pairs) for protecting request data. Each encryption layer operates independently with its own key management, simplifying the overall system architecture compared to a single complex encryption mechanism while providing layered security.
Data Source
AI summary
Securely communicating requests may include transmitting an encrypted response including an encryption library and a public key to a client device, the encrypted response encrypted using transport encryption established between a router device and the client device, receiving an encrypted request including data encrypted using the encryption library and the public key, the encrypted request encrypted using transport encryption established between the client device and router device, and transmitting an encrypted agent message to agent software in a customer environment, the encrypted agent message including the data encrypted using the encryption library and the public key, the encrypted agent message encrypted using transport encryption established between the router device and agent software, wherein the encrypted agent message is decryptable by the agent software using a private key inaccessible within the provider environment.


