Key Proxy Server Secure Communication Instance Allocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication systems face challenges in adopting Public Key Infrastructure (PKI) for person-to-person and person-to-group communications due to cumbersome usage and vulnerabilities, such as reliance on server-owned encryption keys that can be compromised.

Innovation Solution

A method and system for automatically disseminating private keys across devices, utilizing a key proxy server to allocate key proxy instances and manage symmetric keys, ensuring secure transfer and storage without breaking cryptography, and allowing users to de-authorize devices remotely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If server-owned encryption keys are used to secure communications, then communication security is improved, but the system becomes vulnerable to server compromise and key leakage

Engineering Contradiction:
Improvecommunication securityVSAvoidserver compromise vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the encryption key management from the server by introducing client-side key pairs. Each client generates and retains their own private key locally, while only public keys are stored on the server. This extraction eliminates the vulnerability of server-owned keys while maintaining secure communication through cryptographic operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces public keys as an intermediary between the client's private key and the communication data. The public key serves as a mediator that allows encryption without exposing the private key, thus preventing key leakage even if the server is compromised. The server acts as an intermediary for key distribution but never possesses the sensitive private keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If private key infrastructure is implemented for person-to-person communications, then communication security is improved, but the complexity of key management increases

Engineering Contradiction:
Improvecommunication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by automatically generating key pairs on each client device and managing the private keys locally without requiring manual intervention. The system automatically handles key distribution, storage, and usage, reducing the complexity burden on users while maintaining strong cryptographic security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent segments the key management system into distinct components: local key generation on each client, separate public key storage on the server, and automated key distribution protocols. This segmentation distributes the complexity across multiple independent modules rather than concentrating it in a single complex system.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If encryption keys are stored on the service provider's server, then key management is simplified, but the security risk increases due to potential breaches

Engineering Contradiction:
Improvekey management simplicityVSAvoidbreach risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the private key storage from the server environment and places it locally on each client device. Only non-sensitive public keys are stored on the server, which simplifies key management operations while eliminating the security risk of storing sensitive private keys on the provider's server.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent inverts the traditional key management model by having clients generate and retain their own keys rather than receiving keys from the server. This inversion reverses the security risk relationship: instead of the server holding vulnerable keys, the clients hold their own secure keys locally, and the server only manages public information.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS12238205B1Method of providing secure communications to multiple devices and multiple parties
Publication Date: 2025.02.25 CYBER IP HLDG LLC
  • US12238205B1 patent drawing
  • US12238205B1 patent drawing
  • US12238205B1 patent drawing

AI summary

Systems and methods for automatically disseminating a private key are presented. A first message requesting a key proxy instance is received from a first user device. The first message comprises a first symmetric key. A key proxy server is directed to allocate a key proxy instance for communication with the first user device based on a device public key that corresponds to the first user device. A unique URL corresponding to the key proxy instance is received from the key proxy server. A second message comprising the unique URL is sent to the first user device. The second message is encrypted using the first symmetric key and signed using a server private key. A third message comprising the URL of the key proxy instance is received from the first user device and forwarded to a second user device.