DNS Tunneling for Fast Symmetric Session Key Establishment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current asymmetric cryptography methods in e-commerce are vulnerable to quantum computing and require multiple round trips for encryption-key establishment, consuming significant bandwidth and resources.
Innovation Solution
Utilize DNS tunneling to exchange symmetric session encryption-keys using shared-secret key-derivation keys, eliminating reliance on PKI and reducing round trips by up to 70%, leveraging quantum-immune symmetric-key cryptography.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If asymmetric cryptography (PKI) is used for key exchange, then security is provided, but multiple round trips are required and quantum vulnerability increases
Solution Approach 1:
The patent introduces DNS tunneling as an intermediary mechanism to establish symmetric encryption keys. Instead of direct asymmetric key exchange between parties, the system uses DNS queries as a mediator to securely provision pre-shared keys and symmetric session keys, reducing the number of round trips while maintaining security through quantum-immune symmetric cryptography
Solution Approach 2:
The patent changes the cryptographic parameter from asymmetric keys (vulnerable to quantum attacks) to symmetric keys (quantum-immune). By using symmetric session encryption keys provisioned through DNS tunneling, the system achieves both quantum resistance and reduced communication overhead, eliminating the need for multiple asymmetric key exchange round trips
2Ease of operation
If asymmetric cryptography is used, then key exchange is possible, but network bandwidth and compute resources are consumed
Solution Approach 1:
The patent employs symmetric session encryption keys that are short-lived and used only for the duration of a single communication session. These disposable keys are provisioned through DNS tunneling and discarded after use, eliminating the need for complex asymmetric key management and reducing both network bandwidth consumption and computational overhead for key exchange operations
3Reliability
If symmetric-key cryptography is used, then quantum resistance is achieved, but key provisioning complexity increases
Solution Approach 1:
The patent makes the DNS system multi-functional by using it not only for its traditional purpose of resolving domain names to IP addresses but also for provisioning symmetric encryption keys. This universal use of existing DNS infrastructure eliminates the need for separate key management systems, reducing overall system complexity while achieving quantum-resistant symmetric key provisioning
Data Source
AI summary
A method, system, and machine-readable recording medium for accelerated exchange and secure provisioning of symmetric session encryption-keys between systems by tunneling over the public Internet domain name service (DNS) to establish an encrypted communication session, a method referred to as DNS Fast Open (DFO), which improves on the speed of the prior-art by routing data more efficiently across the internet with fewer round trips, thereby reducing time, bandwidth and network computing resources, as well as improving security by utilizing shared-secret key-derivation keys to generate symmetric encryption-keys which may provide quantum-safe confidentiality protection to information in electronic communications, particularly for use in an e-commerce environment.


