Elliptic Curve Symmetric Key Generation for Secure Server Initialization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic systems using Public Key Infrastructure (PKI) are limited by the size of the key modulus, restricting the amount of data that can be encrypted and requiring a trusted relationship for symmetric key sharing, which is insecure and inconvenient.

Innovation Solution

A system that generates a 32-byte symmetric key using elliptic curve functions, allowing secure decryption and initialization of a server without relying on PKI, by creating fake client and server key pairs and using them to derive symmetric encryption keys for secure data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PKI asymmetric key systems are used for secure data encryption, then data confidentiality is improved, but the key size is limited by the modulus size which restricts the amount of data that can be encrypted

Engineering Contradiction:
Improvedata confidentialityVSAvoiddata encryption capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the encryption function into two parts: PKI asymmetric keys for securing the symmetric key exchange, and symmetric keys for the actual data encryption. This allows the system to benefit from both the security of asymmetric keys and the large data capacity of symmetric keys.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces symmetric keys as an intermediary mechanism that bridges the security requirements of PKI and the data capacity requirements. The asymmetric keys serve as intermediaries to securely establish and exchange the symmetric keys between client and server.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If symmetric keys are shared between client and server for data encryption, then data encryption capacity is improved, but the need for trusted relationship establishment and key management increases system complexity

Engineering Contradiction:
Improvedata encryption capacityVSAvoidkey management complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent implements self-service key management where the client device autonomously generates symmetric keys using its private key and the server's public key. The client then encrypts these symmetric keys with the server's public key and stores them locally, eliminating the need for complex centralized key management infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary key generation and encryption actions on the client side before data transmission. Symmetric keys are generated and encrypted in advance, and the encrypted keys are stored on the client device, ready for immediate use without requiring real-time key management server interactions.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If PKI private keys are lost, then security is compromised requiring public key revocation, but this creates inconvenience and potential security gaps

Engineering Contradiction:
Improvesecurity integrityVSAvoidkey loss recovery
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates encrypted copies of symmetric keys that are stored locally on the client device. These encrypted copies serve as backup security credentials that can be used if the original private keys are lost or compromised, eliminating the need for complex revocation and reissuance procedures.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11917056B1System and method of securing a server using elliptic curve cryptography
Publication Date: 2024.02.27 SAFEMOON US LLC
  • US11917056B1 patent drawing
  • US11917056B1 patent drawing

AI summary

A system for generating a symmetric key to allow the sharing of information between two entities, wherein the shared information is used to start a server and the symmetric key is established from the private key of a first client and the public key of a second client and for use in a symmetric encryption methodology to encrypt information for transport to the second entity, allowing the second entity to form the same symmetric key to decrypt information with no key transport required.