Secure Key Distribution in Network Coding Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key distribution schemes for network coding systems are insecure and require additional resources or infrastructure, and they assume prior knowledge of network capacity and adversary channels, which is restrictive and costly to estimate.

Innovation Solution

A method for generating and transmitting a k-bit key using random matrices of selected rank, where each bit is represented by a matrix, allowing secure key distribution without requiring knowledge of network capacity or adversary channels, using a universal secure network code and rank distance metric for decoding.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing information theoretic key distribution schemes are used, then secure key distribution is achieved, but prior knowledge on network capacity and adversary channels is required which is costly and restrictive to estimate

Engineering Contradiction:
Improvesecure key distributionVSAvoidestimation of network capacity and adversary channels
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameters required for key distribution from exact network capacity and adversary channel knowledge to simplified parameters: an upper bound on the number of compromised links and a field size parameter q. This transformation makes the scheme practical while maintaining security, as these simplified parameters are much easier to obtain and update dynamically in real networks.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of requiring complete knowledge of network capacity and all adversary channels (excessive action), the patent only requires partial information: an upper bound on compromised links and the field size parameter. This partial action approach is sufficient for secure key distribution without the computational burden of full network analysis.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If PKI or trusted third party key distribution schemes are used, then key distribution is achieved, but additional resources or infrastructure are required

Engineering Contradiction:
Improvekey distributionVSAvoidadditional resources or infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key distribution function from external infrastructure (PKI authorities, trusted third parties) and embeds it directly into the network coding system itself. The encoder and decoder use random matrices and rank metrics to achieve key distribution autonomously, eliminating the need for separate infrastructure while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network coding system performs key distribution as part of its normal operation without requiring external services. The encoder generates keys using random matrices, transmits them through the network, and the decoder recovers them using rank metrics - all self-contained operations that eliminate dependency on PKI or TTP infrastructure.

Inventive Principle:
Principle #25Self-service

3Reliability

If existing key distribution schemes are used, then key distribution is achieved, but they do not meet the requirements for network coding systems with active adversaries

Engineering Contradiction:
Improvekey distributionVSAvoidadaptability to network coding requirements
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal key distribution scheme that works within the specific constraints of network coding systems with active adversaries. By using random matrices of fixed size and rank, combined with the network coding linear operations, the scheme achieves both key distribution and security against active adversaries simultaneously, making it universally applicable to this class of systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11728977B2Method for efficient and practical key distribution in network coding systems
Publication Date: 2023.08.15 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11728977B2 patent drawing
  • US11728977B2 patent drawing
  • US11728977B2 patent drawing

AI summary

An encoder includes a computer readable storage medium storing program instructions, and a processor executing the program instructions, the processor configured to generate a key, estimate a network capacity, and encode each bit of the key using a random matrix of a selected rank and the estimated network capacity for secure transmission of the key through a network.