DNS-Based Key Distribution for Trusted AI Data Streams

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity systems in IoT, IIoT, and OT environments face challenges with PKI-based certificate management, asymmetric key protection, and symmetric key distribution, leading to scalability issues, high costs, and complex workflows, especially for resource-constrained devices, and lack a mechanism for secure, automated, and scalable key exchange and device authentication.

Innovation Solution

A system and method for symmetric pre-shared key distribution using a key distribution service (KDS) that leverages DNS-based authentication and domain validation, eliminating the need for PKI certificates and asymmetric keypairs, and enabling secure communications through DNS-based device authentication and group membership validation, with automated key lifecycle management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PKI-based certificate management is used for device authentication, then security is improved, but device complexity and operational complexity increase significantly

Engineering Contradiction:
Improvedevice authentication securityVSAvoidcertificate management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex PKI certificate management functionality from the resource-constrained devices and consolidates it into a centralized Key Distribution Service. Devices no longer need to store, manage, or process certificates locally - instead, they authenticate through simplified token-based mechanisms while the KDS handles all certificate validation and key management operations centrally, eliminating the burden of PKI complexity from edge devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a Key Distribution Service as an intermediary between devices and the certificate authority infrastructure. This mediator handles all complex PKI operations including certificate validation, key distribution, and authentication token generation, allowing devices to interact with a simplified interface while maintaining security through the intermediary's backend PKI system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If asymmetric keypairs are generated and stored on devices, then authentication security is improved, but private key protection becomes extremely difficult on resource-constrained devices

Engineering Contradiction:
Improveauthentication securityVSAvoidprivate key protection
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts private key storage and management from resource-constrained devices entirely. Instead of generating and storing asymmetric keypairs on devices with limited secure storage, the system uses a centralized Key Distribution Service to generate and manage all cryptographic materials, distributing only ephemeral authentication tokens to devices for each session.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs all cryptographic key generation and validation operations in advance through the Key Distribution Service before devices need to authenticate. The KDS pre-validates device identities, pre-generates authentication tokens, and pre-establishes security associations, so devices receive ready-to-use credentials without needing to perform complex cryptographic operations or store sensitive key material.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If short-lived certificates are issued by commercial CAs, then security is improved, but recurring costs increase significantly

Engineering Contradiction:
Improvecertificate securityVSAvoidrecurring licensing costs
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements a self-service Key Distribution Service that operates as an internal certificate authority within the organization. Instead of repeatedly purchasing certificates from external commercial CAs, the system runs its own trusted CA infrastructure, allowing devices to obtain authentication credentials from an internal service that does not require external licensing or recurring fees.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal Key Distribution Service that can issue authentication credentials to any number of devices within the organization without additional per-device licensing costs. The internal CA infrastructure serves multiple devices and applications simultaneously, replacing the need for individual commercial CA certificates for each device with a single internal PKI system that scales without recurring costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If certificate chain verification is performed on resource-constrained devices, then authentication reliability is improved, but computational load and bandwidth consumption increase

Engineering Contradiction:
Improveauthentication verificationVSAvoidcomputational energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the computationally intensive certificate chain verification operations from resource-constrained devices and relocates them to the centralized Key Distribution Service. The KDS performs all certificate validation, chain verification, and cryptographic operations centrally, then returns simplified authentication tokens to devices that require minimal processing power to validate.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs all authentication verification operations in advance through the Key Distribution Service before devices need to authenticate. The KDS pre- validates device identities, pre-generates authentication tokens with embedded verification data, and pre-establishes security associations, so devices receive ready-to-use credentials that can be validated with simple local checks rather than full certificate chain verification.

Inventive Principle:
Principle #10Preliminary action

5Reliability

If symmetric keys are distributed to multiple devices, then secure communication is improved, but key management complexity and synchronization requirements increase

Engineering Contradiction:
Improvecommunication securityVSAvoidkey lifecycle management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Key Distribution Service as an intermediary that manages all symmetric key generation, distribution, rotation, and revocation operations. Instead of devices manually managing their own keys or coordinating key exchanges, the KDS automatically generates session keys, distributes them to authorized devices, and handles key renewal and rotation transparently, eliminating the complexity of peer-to-peer key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements automated key lifecycle management through the Key Distribution Service that operates autonomously without requiring manual intervention. The system automatically generates cryptographic keys, distributes them to devices based on group memberships and access policies, rotates keys on schedule, and revokes access when needed, allowing the key management infrastructure to service itself without operator involvement.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12476793B2System and method to securely distribute authenticated and trusted data streams to AI systems
Publication Date: 2025.11.18 SYMMERA INC
  • US12476793B2 patent drawing
  • US12476793B2 patent drawing
  • US12476793B2 patent drawing

AI summary

The method provides for securely harvesting and distributing trusted metadata from devices to artificial intelligence (AI) systems. It enables use of cryptographic hashes and signatures on data for supply chain provenance. It is an agentless method to enhance application security by design, and data protection with data authenticity and confidentiality in device to upstream services communications and data sharing. It helps securely harvest, filter, and forward device metadata to webhooks for AI/ML driven data analytics.