Dynamic Key Selection for Secure Transaction Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Networked computer environments face downtime and usability issues due to compromised encryption keys, network latency, and failures, with existing solutions lacking efficiency in managing these conditions to maintain secure message exchange.

Innovation Solution

Implementing a system where card readers store multiple keys and a point of sale system dynamically selects one based on a rule set, allowing for redundancy, latency minimization, flexibility, and scalability by switching between transaction networks and updating keys without replacing hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single encryption key is used for securing transaction messages, then the system is simple to operate, but the reliability deteriorates when the key is compromised

Engineering Contradiction:
Improvesecurity continuityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the encryption key management by dividing keys into multiple key groups, where each group contains multiple encryption keys. This allows the system to switch between different keys within a group or between groups, maintaining security continuity even when individual keys are compromised, without requiring complete system replacement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes encryption key parameters by selecting different keys from available key groups based on monitored conditions such as network latency, security status, and hardware availability. This dynamic parameter change enables continuous secure operation while adapting to changing system conditions.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple encryption keys are stored and dynamically selected, then the reliability improves, but the device complexity increases

Engineering Contradiction:
Improvesystem availabilityVSAvoidkey selection mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements a universal key management architecture where a single key management mechanism handles multiple key groups and selection criteria. The point of sale device and card readers can universally use any key from the available groups, and the system monitors multiple conditions (network latency, security status, hardware availability) through a unified monitoring framework, reducing the complexity burden of managing multiple keys.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system employs automated key selection and switching mechanisms that operate autonomously based on monitored conditions. The point of sale device automatically selects appropriate keys from key groups without manual intervention, and can automatically switch between keys when conditions change, reducing the operational complexity for users while maintaining high reliability.

Inventive Principle:
Principle #25Self-service

3Reliability

If hardware is replaced when keys are compromised, then security is restored, but the loss of time increases due to the replacement process

Engineering Contradiction:
Improvesecurity restorationVSAvoiddowntime during key compromise
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring multiple key groups in advance within the card readers and point of sale devices. When a key compromise is detected, the system can immediately switch to a pre-configured alternative key from the same or different key groups, restoring security continuity without requiring hardware replacement or lengthy reconfiguration processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous secure transaction processing by implementing automated key switching mechanisms. When one encryption key becomes compromised, the system seamlessly transitions to an alternative key from the key groups, ensuring that transaction processing continues uninterrupted without downtime or hardware replacement, thus maintaining the continuity of useful action.

Inventive Principle:
Principle #20Continuity of useful action

4Adaptability or versatility

If network latency increases, then message exchange is delayed, but the system can adapt by switching networks

Engineering Contradiction:
Improvenetwork switching capabilityVSAvoidtransaction processing delay
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system implements dynamic network selection by continuously monitoring network latency and automatically switching between available transaction networks based on current conditions. The point of sale device can dynamically change which network path is used for message exchange, adapting to changing network conditions in real-time to minimize delays while maintaining adaptability to different network environments.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11354659B1Securing transaction messages based on a dynamic key selection
Publication Date: 2022.06.07 AMAZON TECH INC
  • US11354659B1 patent drawing
  • US11354659B1 patent drawing
  • US11354659B1 patent drawing

AI summary

Systems and methods for securing transaction messages are described. In an example, a rule set may be accessed. The rule set may specify a selection of a key from a plurality of keys or an obfuscation process from a plurality of obfuscation processes. The selection may be based on a condition associated with securing transaction messages. The keys or the obfuscation processes may be stored at a card reader. An instruction about the selection may be provided to the card reader based on the rule set and a determination that the condition is satisfied. In turn, a secure transaction message may be received from the card reader. The secure transaction message may have been secured based on the key or the obfuscation process. The secure transaction message may be provided to a transaction system that includes a management system associated with the key or the obfuscation process.