Distributed Session Resumption via Deterministic Symmetric Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed server systems, the existing methods for session resumption across multiple servers are resource-intensive due to the need for full authentication processes, which consume significant computing resources and can be inefficient when re-establishing secure connections.

Innovation Solution

Implementing a deterministic process that allows each server to independently generate the same symmetric key for encryption and decryption of session tickets, using a combination of kernel data and temporal elements like clock or counter values, ensuring synchronization without the need for explicit key sharing across servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full authentication process is used for session resumption in distributed server systems, then security is maintained, but computing resources are excessively consumed

Engineering Contradiction:
ImprovesecurityVSAvoidcomputing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by generating session tickets with encrypted session data during the initial full authentication process. These pre-generated tickets allow subsequent abbreviated authentication processes, eliminating the need to repeat costly cryptographic operations while maintaining security. The session ticket contains all necessary authentication data encrypted with a symmetric key, enabling fast verification without re-executing the full authentication ceremony.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention extracts the essential authentication data from the full authentication process and places it into a session ticket. This extracted data can be verified through a simplified abbreviated authentication process, separating the costly cryptographic operations (performed once during full authentication) from the lightweight verification process (performed during session resumption). This extraction eliminates redundant computing while preserving security guarantees.

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If session tickets are encrypted with symmetric keys for efficient verification, then authentication speed improves, but key synchronization complexity increases in distributed systems

Engineering Contradiction:
Improveauthentication speedVSAvoidkey synchronization
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Each server in the distributed system independently generates its own symmetric authentication key without requiring coordination with other servers. The session ticket encryption key is derived deterministically from server-specific identifiers and shared secret data, allowing each server to self-generate consistent encryption keys. This eliminates the need for complex key distribution and synchronization mechanisms while enabling fast authenticated session resumption across the distributed system.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The invention creates a universal mechanism where a small set of shared secret data can be used by all servers in the distributed system to generate consistent symmetric keys independently. This universal approach allows any server to verify session tickets from any other server without requiring pairwise key exchanges or complex synchronization protocols, achieving both fast authentication and simplified key management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If abbreviated authentication process is used for session resumption, then computing cost is reduced to less than 5%, but session ticket decryption reliability may be compromised

Engineering Contradiction:
Improvecomputing efficiencyVSAvoidsession restoration reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements beforehand cushioning by incorporating forward secrecy mechanisms and secure key rotation. Session tickets are encrypted with symmetric keys that are periodically rotated and bound to specific time periods or session contexts. This preparatory security measures ensure that even if an abbreviated authentication is compromised, the damage is limited, and session restoration reliability is maintained through pre-established security boundaries and key lifecycle management.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11606193B2Distributed session resumption
Publication Date: 2023.03.14 ORACLE INT CORP
  • US11606193B2 patent drawing
  • US11606193B2 patent drawing
  • US11606193B2 patent drawing

AI summary

Techniques for re-establishing secure application sessions using an abbreviated authentication process are disclosed. A plurality of servers each use a deterministic process to independently generate a symmetric key. A client initiates an application session with one of the servers using a full authentication process. Before the connection is terminated, the server generates a session ticket, including security parameters negotiated during the full authentication process, and encrypts the session ticket with the symmetric key. Another server receives the session ticket and decrypts the session ticket using the symmetric key to initiate an abbreviated authentication process that is less costly than the full authentication process. The client and the server establish a secure communication channel based on successful completion of the abbreviated authentication process.