Custodial TRNG Disk Key Segmentation for Quantum-Resistant Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic systems for securing data are vulnerable to quantum computing, hardware flaws, and side-channel attacks, particularly due to the use of small encryption keys, which can lead to exposure of sensitive information during transmission and storage, and existing methods lack robustness and security assurance.

Innovation Solution

A system and method utilizing a custodial true random number generator (TRNG) disk to encrypt data with dynamically generated, long encryption keys, where the encryption key is split and stored on separate media, requiring multiple key components for decryption, thereby enhancing security against quantum cryptanalysis and side-channel attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a single 256-bit encryption key is used to secure data, then the encryption process is simple and efficient, but the system becomes vulnerable to quantum computing attacks and hardware flaws

Engineering Contradiction:
Improveencryption efficiencyVSAvoidsecurity against quantum attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides the encryption key into multiple separate key components stored on different physical media. Each component is encrypted with a unique key, and all components must be combined to decrypt the data. This segmentation prevents a single point of failure and makes quantum attacks ineffective as they would need to compromise multiple independent key components simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single-dimensional key (one 256-bit key) to a multi-dimensional key structure where multiple key components are distributed across different physical media and locations. This dimensional expansion increases the security landscape from a single vulnerability point to multiple distributed security layers.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Device complexity

If a single encryption key is stored on one device, then key management is simple, but the system is susceptible to hardware attacks and side-channel leaks

Engineering Contradiction:
Improvekey management simplicityVSAvoidhardware attacks and side-channel leaks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The encryption key is segmented into multiple components distributed across different physical media (e.g., hardware security modules, separate storage devices, cloud-based key management systems). This distribution eliminates the risk of hardware attacks on a single device and prevents side-channel leaks that could occur if all key material resided in one location.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary systems such as hardware security modules (HSMs) and key management services that act as mediators between the encryption operations and the actual key material. These intermediaries provide secure key storage and distribution while isolating the main system from direct exposure to hardware vulnerabilities and side-channel attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If traditional symmetric encryption is used for data transport, then the encryption process is fast and efficient, but the security is compromised by quantum computing advancements

Engineering Contradiction:
Improvedata transmission speedVSAvoidsecurity against quantum cryptanalysis
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the encryption approach by combining traditional symmetric encryption for fast data transmission with a distributed key management system using multiple key components. The actual data encryption maintains high speed through efficient symmetric algorithms, while the key components are distributed across multiple secure locations to provide quantum-resistant security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic key management where the encryption system can adaptively combine different key components from multiple sources depending on the specific encryption operation. This dynamic approach allows the system to maintain optimal performance while providing quantum-resistant security through flexible key composition.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11562081B2Method and system for controlling access to secure data using custodial key data
Publication Date: 2023.01.24 QUANTUM PROPERTIES TECHNOLOGY LLC
  • US11562081B2 patent drawing
  • US11562081B2 patent drawing
  • US11562081B2 patent drawing

AI summary

Methods and systems for controlling access to secure data use a custodial TRNG disk. Source data is encrypted using first key data from a first TRNG disk to generate encrypted data which is stored at a first location by a first entity. A second TRNG disk has second key data which is stored at a second location by a second entity. A first TRNG disk copy and a second TRNG disk copy are made identical to the first TRNG disk and the second TRNG disk, respectively, and are stored at one or more locations by a custodial entity. The first key data and the second key data are encoded together, and then transmitted to one or more of the first or second entities. The first quantity of encrypted data is decryptable using the encoded first key data and the second key data.