Decoy Cryptographic Key for Network Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing data networks against intrusion by protecting cryptographic keys are either costly or limit flexibility, and fail to detect or react to intrusions if physical safeguards are breached.

Innovation Solution

Implementing a decoy cryptographic key system where each network device has both a decoy and an authentic key, with the decoy key being used to detect unauthorized data transmission, allowing for alert generation and isolation of compromised devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical safeguards (locking mechanisms, physical monitoring) are added to network devices, then security against intrusion is improved, but manufacturing expense increases and deployment flexibility is limited

Engineering Contradiction:
Improvesecurity against intrusionVSAvoidmanufacturing expense and deployment flexibility
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a copy of the cryptographic key system by implementing a decoy key that mimics the structure and location of the authentic key. This virtual copy allows intrusion detection without requiring physical safeguards, resolving the contradiction between security reliability and device complexity

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces mechanical physical safeguards (locks, physical monitoring) with a cryptographic software-based solution. The decoy key system uses cryptographic mechanisms instead of mechanical security features, eliminating the need for expensive physical safeguards while maintaining security effectiveness

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If physical safeguards are used to protect cryptographic keys, then key disclosure is prevented, but detection and reaction to intrusion is not provided if safeguards fail

Engineering Contradiction:
Improveprevention of key disclosureVSAvoiddetection and reaction to intrusion
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The decoy key system implements feedback by monitoring whether the decoy key is being used. When the decoy key is detected as active, the system immediately generates an alert and isolates the compromised device, providing real-time detection and reaction to intrusion attempts

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent prepares for potential intrusion by pre-configuring the decoy key and establishing detection mechanisms before any attack occurs. The system is ready to immediately detect and respond to intrusions without requiring additional detection infrastructure when safeguards fail

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8719938B2Detecting network intrusion using a decoy cryptographic key
Publication Date: 2014.05.06 LANDIS GYR TECH INC
  • US8719938B2 patent drawing
  • US8719938B2 patent drawing
  • US8719938B2 patent drawing

AI summary

Systems and methods for detecting intrusion into a data network are disclosed. Such intrusion can be detected, for example, by providing at least two network devices in a data network. Each of the network devices has a decoy cryptographic key that is used to detect unauthorized data and an authentic cryptographic key that is used to encrypt authorized data. The first network device receives data from the second network device that is encrypted using the decoy cryptographic key. The first network device determines that the data is encrypted using the decoy cryptographic key. The first network device deletes or otherwise discards the data encrypted using the decoy cryptographic key. The first network device can generate an alert message instructing other network devices that the second network device is generating the unauthorized data. The alert message also instructs the other network devices to ignore data originating from the second network device.