Key Proxy Server Secure Communication Instance Allocation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure communication systems face challenges in adopting Public Key Infrastructure (PKI) for person-to-person and person-to-group communications due to cumbersome usage and vulnerabilities, such as reliance on server-owned encryption keys that can be compromised.
Innovation Solution
A method and system for automatically disseminating private keys across devices, utilizing a key proxy server to allocate key proxy instances and manage symmetric keys, ensuring secure transfer and storage without breaking cryptography, and allowing users to de-authorize devices remotely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If server-owned encryption keys are used to secure communications, then communication security is improved, but the system becomes vulnerable to server compromise and key leakage
Solution Approach 1:
The patent extracts the encryption key management from the server by introducing client-side key pairs. Each client generates and retains their own private key locally, while only public keys are stored on the server. This extraction eliminates the vulnerability of server-owned keys while maintaining secure communication through cryptographic operations.
Solution Approach 2:
The patent introduces public keys as an intermediary between the client's private key and the communication data. The public key serves as a mediator that allows encryption without exposing the private key, thus preventing key leakage even if the server is compromised. The server acts as an intermediary for key distribution but never possesses the sensitive private keys.
2Reliability
If private key infrastructure is implemented for person-to-person communications, then communication security is improved, but the complexity of key management increases
Solution Approach 1:
The patent implements self-service by automatically generating key pairs on each client device and managing the private keys locally without requiring manual intervention. The system automatically handles key distribution, storage, and usage, reducing the complexity burden on users while maintaining strong cryptographic security.
Solution Approach 2:
The patent segments the key management system into distinct components: local key generation on each client, separate public key storage on the server, and automated key distribution protocols. This segmentation distributes the complexity across multiple independent modules rather than concentrating it in a single complex system.
3Ease of operation
If encryption keys are stored on the service provider's server, then key management is simplified, but the security risk increases due to potential breaches
Solution Approach 1:
The patent extracts the private key storage from the server environment and places it locally on each client device. Only non-sensitive public keys are stored on the server, which simplifies key management operations while eliminating the security risk of storing sensitive private keys on the provider's server.
Solution Approach 2:
The patent inverts the traditional key management model by having clients generate and retain their own keys rather than receiving keys from the server. This inversion reverses the security risk relationship: instead of the server holding vulnerable keys, the clients hold their own secure keys locally, and the server only manages public information.
Data Source
AI summary
Systems and methods for automatically disseminating a private key are presented. A first message requesting a key proxy instance is received from a first user device. The first message comprises a first symmetric key. A key proxy server is directed to allocate a key proxy instance for communication with the first user device based on a device public key that corresponds to the first user device. A unique URL corresponding to the key proxy instance is received from the key proxy server. A second message comprising the unique URL is sent to the first user device. The second message is encrypted using the first symmetric key and signed using a server private key. A third message comprising the URL of the key proxy instance is received from the first user device and forwarded to a second user device.


