Elliptic Curve Symmetric Key Generation for Secure Server Initialization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptographic systems using Public Key Infrastructure (PKI) are limited by the size of the key modulus, restricting the amount of data that can be encrypted and requiring a trusted relationship for symmetric key sharing, which is insecure and inconvenient.
Innovation Solution
A system that generates a 32-byte symmetric key using elliptic curve functions, allowing secure decryption and initialization of a server without relying on PKI, by creating fake client and server key pairs and using them to derive symmetric encryption keys for secure data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If PKI asymmetric key systems are used for secure data encryption, then data confidentiality is improved, but the key size is limited by the modulus size which restricts the amount of data that can be encrypted
Solution Approach 1:
The patent segments the encryption function into two parts: PKI asymmetric keys for securing the symmetric key exchange, and symmetric keys for the actual data encryption. This allows the system to benefit from both the security of asymmetric keys and the large data capacity of symmetric keys.
Solution Approach 2:
The patent introduces symmetric keys as an intermediary mechanism that bridges the security requirements of PKI and the data capacity requirements. The asymmetric keys serve as intermediaries to securely establish and exchange the symmetric keys between client and server.
2Quantity of substance
If symmetric keys are shared between client and server for data encryption, then data encryption capacity is improved, but the need for trusted relationship establishment and key management increases system complexity
Solution Approach 1:
The patent implements self-service key management where the client device autonomously generates symmetric keys using its private key and the server's public key. The client then encrypts these symmetric keys with the server's public key and stores them locally, eliminating the need for complex centralized key management infrastructure.
Solution Approach 2:
The patent performs preliminary key generation and encryption actions on the client side before data transmission. Symmetric keys are generated and encrypted in advance, and the encrypted keys are stored on the client device, ready for immediate use without requiring real-time key management server interactions.
3Reliability
If PKI private keys are lost, then security is compromised requiring public key revocation, but this creates inconvenience and potential security gaps
Solution Approach 1:
The patent creates encrypted copies of symmetric keys that are stored locally on the client device. These encrypted copies serve as backup security credentials that can be used if the original private keys are lost or compromised, eliminating the need for complex revocation and reissuance procedures.
Data Source
AI summary
A system for generating a symmetric key to allow the sharing of information between two entities, wherein the shared information is used to start a server and the symmetric key is established from the private key of a first client and the public key of a second client and for use in a symmetric encryption methodology to encrypt information for transport to the second entity, allowing the second entity to form the same symmetric key to decrypt information with no key transport required.

