Key Exchange Device Using Bilinear Mappings for Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing deniable authentication and key exchange systems face increased load and communication traffic due to the need for multiple communication sessions and high arithmetic loads, particularly when obtaining public keys from companion parties, which hampers execution rate and efficiency.
Innovation Solution
A key exchange apparatus and method utilizing a storage and arithmetic controller that performs key exchange through a network by generating session numbers and hash values based on initial session numbers, random numbers, and private keys, with only two communication sessions required, leveraging bilinear mappings for authentication and reducing communication loads.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple communication sessions are used for deniable authentication and key exchange, then authentication integrity is maintained, but communication overhead and execution time increase
Solution Approach 1:
The patent performs preliminary key exchange and authentication in advance before the actual communication needs occur. By pre-establishing cryptographic materials and performing authentication sequences beforehand, the system reduces the time required during actual key exchange operations while maintaining security integrity through the pre-computed authentication mechanisms.
Solution Approach 2:
The patent divides the key exchange process into distinct segments: an initial key exchange phase using traditional multi-session authentication, and a subsequent phase using the optimized two-session method with bilinear mappings. This segmentation allows the system to maintain authentication integrity through the initial thorough authentication while achieving faster subsequent key exchanges.
2Reliability
If traditional public key cryptography is used for key exchange, then authentication is achieved, but arithmetic load and processing complexity increase
Solution Approach 1:
The patent replaces traditional public key cryptography arithmetic operations with bilinear mapping-based computations. By substituting the mechanical arithmetic operations of conventional public key systems with the mathematical properties of bilinear mappings, the system achieves comparable authentication capability with reduced computational complexity and processing load.
Solution Approach 2:
The patent changes the mathematical parameters and structures used in key exchange from traditional public key cryptography to bilinear mapping parameters. This parameter change involves using pairing-based cryptography with specific group elements and mapping functions that provide equivalent security with more efficient computation, thereby reducing arithmetic processing load.
3Reliability
If comprehensive authentication protocols are implemented, then security is enhanced, but communication traffic and processing load increase
Solution Approach 1:
The patent extracts and separates the essential authentication elements from the complete traditional authentication protocol. By identifying and utilizing only the critical authentication components through bilinear mappings, the system maintains security levels while removing redundant communication steps and data exchanges that contribute to excessive traffic volume.
Solution Approach 2:
The patent applies partial authentication action by using a simplified two-session protocol that performs only the necessary authentication checks required for security. Rather than implementing excessive or comprehensive authentication protocols, the system performs the minimal sufficient actions needed to maintain security while reducing overall communication traffic.
Data Source
AI summary
A key exchange apparatus according to the present invention includes storage 250 and arithmetic controller 260 and performs a key exchange process with an external companion apparatus through a network, as follows: When arithmetic controller 260 is supplied with a random number, a private key, an own public key, a companion public key, an initial session number, and a start command, the arithmetic controller generates a starter message including a first session number and a first hash value, and sends the starter message to the companion apparatus. When the arithmetic controller receives a responder message including a second session number and a third hash value from the companion apparatus, if a generated fourth hash value and the third hash value are in agreement with each other, the arithmetic controller generates and stores a fifth hash value as a key in storage 250.


