DNS-Based Symmetric-Key Infrastructure for Quantum-Resistant Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional internet-scale symmetric-key infrastructures face challenges in securing communications due to vulnerabilities from quantum computing and cryptanalytic advances, and existing solutions either rely on insecure public-key cryptosystems or are not scalable for internet use.
Innovation Solution
A DNS-based symmetric-key infrastructure (SKI) is introduced, where client and server computers obtain a shared symmetric key through a network of key servers, with key servers interacting via the DNS to ensure both entities share a common symmetric key for secure communication, using techniques like key wrapping, derivation, and secure channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional public-key cryptosystems are used for key distribution, then key exchange can be achieved, but security is compromised due to vulnerabilities from quantum computing and cryptanalytic advances
Solution Approach 1:
The patent introduces DNS servers as intermediaries in the key distribution process. Instead of direct peer-to-peer key exchange using vulnerable public-key cryptosystems, the invention uses DNS-based key distribution where DNS servers act as trusted mediators to distribute symmetric keys between clients and servers, thereby eliminating the need for insecure public-key operations while maintaining security
Solution Approach 2:
The invention fundamentally changes the cryptographic parameter from public-key cryptography to symmetric-key cryptography. By using symmetric keys distributed through DNS infrastructure, the system achieves quantum-resistant security without requiring the mathematical complexity of public-key cryptosystems, thus improving reliability while reducing cryptographic complexity
2Reliability
If existing symmetric-key infrastructure solutions are implemented, then security can be improved, but scalability for internet use is limited
Solution Approach 1:
The patent makes the DNS infrastructure serve multiple functions: its traditional role in domain name resolution plus a new role in symmetric key distribution. By embedding key distribution capabilities within the existing universal DNS infrastructure, the invention achieves both improved security and internet-scale scalability without requiring a separate dedicated key distribution network
Solution Approach 2:
The invention enables the DNS infrastructure to serve itself by distributing keys through the same distributed hierarchical structure that DNS uses for domain resolution. Each DNS server can independently participate in key distribution, and the system automatically scales as the DNS infrastructure scales, achieving versatility and adaptability for internet-wide deployment
3Ease of operation
If a centralized key distribution system is used, then key management can be simplified, but single points of failure and security risks increase
Solution Approach 1:
The patent segments the key distribution function across multiple distributed DNS servers rather than using a single centralized authority. Each DNS server operates independently to distribute keys, eliminating single points of failure. The hierarchical segmentation of DNS infrastructure naturally provides redundancy and fault tolerance while maintaining operational simplicity through standardized protocols
Data Source
AI summary
Techniques for distributing a symmetric key using the Domain Name System (DNS) are presented. The techniques can include receiving, at a first key server and from a first computer, a request for first information sufficient for the first computer to obtain, and second information sufficient for a second computer to obtain, a symmetric key for securing at least one communication sent from the first computer to the second computer, and providing, by the first key server and to the first computer, the first information and the second information, such that the first computer secures at least one communication sent from the first computer to the second computer using at least the symmetric key for securing at least one communication sent from the first computer to the second computer.


