DNS Key Server Infrastructure for Quantum-Resilient Symmetric Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional public-key cryptosystems are vulnerable to quantum computing and cryptanalytic advances, making secure internet-scale communication challenging, while existing symmetric-key infrastructures are not scalable for internet use and rely on public-key cryptosystems.
Innovation Solution
A DNS-based symmetric-key infrastructure (SKI) is implemented, where clients obtain shared symmetric keys through a network of key servers, using DNS to securely communicate with web servers, enabling secure communication channels without relying on public-key cryptosystems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public-key cryptosystems are used for secure communication, then secure communication channels can be established, but they become vulnerable to quantum computing and cryptanalytic advances
Solution Approach 1:
The patent extracts the key distribution function from public-key cryptosystems and implements it separately using symmetric-key infrastructure. The DNS-based SKI provides a dedicated key distribution mechanism that is independent of public-key cryptography, thereby removing the vulnerability to quantum computing while maintaining secure communication capabilities.
Solution Approach 2:
The patent introduces DNS-based key servers as intermediaries for key distribution. These key servers act as mediators between clients and web servers, providing symmetric keys through DNS queries without requiring public-key cryptosystems. This intermediary layer enables secure communication while avoiding quantum vulnerabilities.
2Reliability
If symmetric-key infrastructures are used for secure communication, then quantum computing vulnerability is avoided, but they are not scalable for internet use
Solution Approach 1:
The patent makes the DNS system multi-functional by enabling it to serve both its traditional domain name resolution function and a new key distribution function. The DNS-based SKI allows existing DNS infrastructure to universally provide key distribution services to any client-web server pair on the internet, achieving internet-scale scalability without requiring dedicated key distribution infrastructure.
Solution Approach 2:
The patent enables clients and web servers to autonomously obtain symmetric keys through DNS queries without requiring manual key distribution or complex key management infrastructure. The system self-services the key distribution need by leveraging the existing DNS infrastructure that is already universally deployed and trusted across the internet.
3Productivity
If DNS-based symmetric-key infrastructure is implemented, then internet-scale scalability is achieved, but key distribution mechanisms must be separated from key usage
Solution Approach 1:
The patent segments the cryptographic infrastructure into distinct functional components: DNS-based key distribution (handled by key servers through DNS queries) and key usage (handled by clients and web servers). This segmentation allows the key distribution mechanism to be independently optimized and scaled through existing DNS infrastructure, while key usage remains at the application layer, reducing overall system complexity.
Data Source
AI summary
Techniques for provisioning a key server to facilitate secure communications between a web server and a client by providing the client with a first data structure including information on how the web server may obtain a target symmetric key are presented. The techniques can include: provisioning the key server with a second data structure including information on how the key server may generate the first data structure; receiving a request on behalf of a web server for a third data structure comprising information on how the client may obtain the first data structure from the key server; and obtaining the third data structure, such that the third data structure is published in association with an identification of the web server, and such that the client uses the third data structure to obtain the first data structure and uses the first data structure to communicate with the web server.


