Hierarchical Key Distribution System for Secure Financial Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure communication protocols, such as DUKPT, are computationally expensive and lack scalability, making them inadequate for the increasing demands of electronic financial transactions, particularly in the financial services industry.

Innovation Solution

A hierarchal symmetric key distribution system (HKDS) that uses Keccak-based message authentication codes and extended output functions to derive unique symmetric keys for secure communication, providing forward secrecy and predictive resistance, and is scalable to meet the demands of future transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DUKPT protocol is used for secure communication, then security is provided, but computational cost increases and scalability is limited

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the key management into a hierarchical structure with master keys at the top level and derived session keys at lower levels. This allows the system to maintain strong security through the master key while improving computational efficiency by using smaller, derived session keys for actual transactions, avoiding the need to repeatedly process with large master keys.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic key derivation where session keys are generated on-demand based on transaction requirements rather than using static master keys for all operations. This dynamic approach allows the system to adapt key sizes and management overhead to actual transaction needs, improving computational efficiency while maintaining security.

Inventive Principle:
Principle #15Dynamics

2Reliability

If DUKPT protocol is used for secure communication, then security is provided, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex key management functions from the transaction processing logic and places them in a separate key management server. This separation allows the core transaction system to operate with simpler protocols while the complexity of key derivation, rotation, and management is isolated in a dedicated service that handles these operations asynchronously.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a key management server as an intermediary between client systems and transaction processing systems. This intermediary handles the complex hierarchical key distribution and derivation operations, allowing client and server applications to use simplified interfaces while the complexity is managed centrally by the intermediary service.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If electronic payment transactions increase, then transaction volume grows, but existing infrastructure costs increase

Engineering Contradiction:
Improvetransaction volumeVSAvoidinfrastructure cost
Core Design Contradiction:
ProductivityVSEase of manufacture

Solution Approach 1:

The patent creates a universal key management server that serves multiple functions: key derivation, key rotation, transaction authentication, and security protocol management. This multi-functional approach consolidates what would otherwise require separate infrastructure components, reducing overall system cost while supporting high transaction volumes through efficient resource utilization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service key derivation where client systems can independently generate session keys using cryptographic operations performed locally rather than requiring constant server intervention. This reduces server workload and infrastructure requirements while maintaining security, allowing the system to scale transaction volume without proportionally increasing infrastructure costs.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240161104A1Method and system for performance enhanced hierarchical key distribution system
Publication Date: 2024.05.16 UNDERHILL JOHN GREGORY
  • US20240161104A1 patent drawing
  • US20240161104A1 patent drawing
  • US20240161104A1 patent drawing

AI summary

A “hierarchical symmetric key distribution” method, system, and apparatus (“HKDS”) is provided for a scalable and fundamentally secure solution for a security protocol for financial transactions, including the electronic payment industry. The security protocol can be used in conjunction with various message authentication code generators and extended output functions to derive unique symmetric keys which can be used to protect messaging and communications in the financial services industry. The security protocol, for example, provide a distributed key management protocol that generates unique transaction keys from a base terminal key, such that the terminal does not retain information that could be used to reconstruct the key once the transaction has been completed, the capture of the terminals state does not provide enough information to construct future derived keys, and the server can reconstruct the transaction key using a bonded number of cryptographic operations.