Multi-party Session Key Agreement via Segmented Test and Original Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for managing session keys in blockchain networks lack robustness against collusion attacks and do not ensure complete forward secrecy, particularly in peer-to-peer environments where key theft and unauthorized access are risks.

Innovation Solution

A multi-party session key agreement method is introduced, comprising a test session for exchanging short-term keys and an original session for exchanging long-term keys, utilizing the Federated Byzantine Agreement (FBA) protocol to ensure secure key exchange among peers, with a hybrid approach combining low-level security confirmation using short-term keys and high-level security confirmation using long-term keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a central management server is used to manage keys, then key management is simplified and centralized, but the system becomes vulnerable to collusion attacks and intensive attacks on the central server

Engineering Contradiction:
Improvekey managementVSAvoidsecurity against collusion attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized key management function into distributed key generation and management across multiple peers. Each peer generates their own keys locally and participates in group key establishment through cryptographic protocols, eliminating the single point of failure while maintaining operational simplicity through standardized interfaces

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic intermediaries (cryptographic protocols and algorithms) that mediate between peers during key exchange and establishment. These intermediaries enable secure key agreement without requiring direct trust between peers or a central authority, resolving the contradiction by providing both security and ease of operation through protocol automation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If short-term keys are used for session establishment, then key exchange speed is improved, but forward secrecy and long-term security are compromised

Engineering Contradiction:
Improvekey exchange speedVSAvoidforward secrecy
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the key management process into two distinct phases: a fast test session using short-term keys for initial communication and key exchange, followed by a secure original session using long-term keys for sustained communication. This segmentation allows each phase to optimize for its specific requirements—speed for setup, security for operation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary key exchange and authentication during the test session using short-term keys before establishing the actual communication channel. This preliminary action enables peers to verify each other's credentials and establish initial security parameters quickly, then transitions to more secure long-term key usage for the main session

Inventive Principle:
Principle #10Preliminary action

3Reliability

If long-term keys are used for all sessions, then security and forward secrecy are maintained, but key exchange overhead and computational cost increase

Engineering Contradiction:
Improvesecurity and forward secrecyVSAvoidkey exchange efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides communication sessions into test sessions and original sessions, using appropriate key types for each. Test sessions use lightweight short-term keys for rapid establishment and verification, while original sessions use robust long-term keys for secure communication, optimizing both security and efficiency for different operational phases

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes key parameters (key length, key type, cryptographic algorithm strength) based on the session phase and security requirements. Test sessions use shorter, faster keys while original sessions use longer, more secure keys, dynamically adjusting parameters to match operational needs and reduce unnecessary computational overhead

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If hash chain-based key recovery mechanism is used, then self-recovery capability is provided, but the system cannot resist collusion attacks between revoked and new users

Engineering Contradiction:
Improveself-recovery capabilityVSAvoidresistance to collusion attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces cryptographic intermediaries (secure multi-party computation protocols and trusted execution environments) that mediate the key recovery process. These intermediaries enable users to recover their session keys through cryptographic verification without directly sharing sensitive information, preventing collusion attacks while maintaining self-recovery capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical hash chain-based recovery mechanism with cryptographic substitution methods. Instead of relying on sequential hash computations that can be exploited, the system uses cryptographic protocols that provide security against collusion while enabling recovery, substituting a vulnerable mechanical process with a secure cryptographic one

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12034839B2Multi-party session key agreement method
Publication Date: 2024.07.09 THE IND & ACADEMIC COOP IN CHUNGNAM NAT UNIV (IAC)
  • US12034839B2 patent drawing
  • US12034839B2 patent drawing
  • US12034839B2 patent drawing

AI summary

A multi-party session key agreement method includes: a test session for exchanging a short-term key between parties of 3 to n peers; and an original session for exchanging a long-term key between the parties who have exchanged the short-term key. Peer (n) that has conducted the test session and the original session has cluster (n) that manages the keys as a result of conducting the sessions, and cluster (n) agrees with a result of the session conducted in peer (n) by communicating with cluster (n+1) of another peer (n+1).