Hybrid Key Exchange for Double-Hull Quantum-Safe Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network communication security technologies face challenges in keeping up with evolving malicious attacks and ensuring compatibility with both classical and quantum-safe cryptographic techniques, requiring significant resources for updates and maintenance.

Innovation Solution

Implementing double-hull encryption, which uses a hybrid cryptographic key exchange combining quantum-safe and classical cryptographic algorithms to provide robust security through two layers of encryption, ensuring compatibility with existing protocols and standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hybrid cryptographic key exchange combining quantum-safe and classical algorithms is implemented, then security against both traditional and quantum computing threats is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcryptographic system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines quantum-safe cryptographic algorithms (such as lattice-based cryptography) with classical cryptographic algorithms (such as RSA or ECC) into a hybrid key exchange system. This merging allows the system to leverage the security strengths of both algorithm types, providing protection against both traditional and quantum computing threats simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cryptographic system uses composite cryptographic structures where multiple cryptographic primitives are integrated together. The key exchange mechanism employs composite key pairs and multi-layer encryption schemes that combine different cryptographic methodologies, analogous to using composite materials to achieve superior properties.

Inventive Principle:
Principle #40Composite materials

2Reliability

If double-hull encryption with two layers of encryption is applied, then security against malicious attacks is improved, but computational resources and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The encryption process is segmented into two distinct layers: an outer encryption layer using one cryptographic algorithm and an inner encryption layer using another algorithm. This segmentation allows each layer to be optimized independently and provides defense in depth, where compromising one layer does not necessarily compromise the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies encryption beyond what a single algorithm would provide by implementing double-hull encryption. This excessive action in terms of encryption layers ensures that even if one cryptographic algorithm is broken or compromised, the data remains protected by the second layer of encryption.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If hybrid cryptographic schemes are implemented to ensure compatibility with both classical and quantum-safe standards, then adaptability to future threats is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovecompatibilityVSAvoidimplementation complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The hybrid cryptographic system is designed to be universal by supporting multiple cryptographic algorithms and key exchange mechanisms within a single framework. It can operate with both classical and quantum-safe algorithms, making it adaptable to different security requirements and future technological changes while maintaining a unified interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4614871A1Hybrid key exchanges for double-hulled encryption
Publication Date: 2025.09.10 AMAZON TECH INC
  • EP4614871A1 patent drawingFigure 1
  • EP4614871A1 patent drawingFigure 2
  • EP4614871A1 patent drawingFigure 3

AI summary

A first computing system establishes a cryptographically protected communication session with a second computing system by proposing a hybrid cryptographic scheme. In response to the proposed hybrid cryptographic scheme, a second computing system transmits cryptographic materials to the first computing system, and the first computing system transmits cryptographic materials to the second computing system. Using the cryptographic materials, two or more cryptographic keys are derived. One cryptographic key is used to perform an inner cryptographic operation on one or more data items, and another cryptographic key is used to perform an outer cryptographic operation on the one or more data items that have been cryptographically protected by the inner cryptographic operation.