Non-PKI Key Delivery Using Split Relay Servers for Secure Messaging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing asymmetric cryptographic systems, such as SSL and TLS, face challenges in managing digital certificates for secure communications, especially in IoT devices, leading to high costs and resource-intensive administration, and are vulnerable to attacks like compromised certificate authorities and man-in-the-middle attacks.
Innovation Solution
A key delivery system utilizing a streaming encryption scheme without PKI, employing a double-blind configuration and geographic separation of cryptographic key segments across relay servers in a cloud network, ensuring secure transmission of one-time pad keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If asymmetric cryptographic schemes (SSL/TLS) are used for secure message transmission, then cryptographic security is provided, but digital certificate installation and administration becomes costly and resource-intensive
Solution Approach 1:
The cryptographic key is divided into multiple segments that are distributed across different relay servers in a cloud network. Each relay server holds only a portion of the key, making it impossible to compromise the entire key by attacking a single server. This segmentation eliminates the need for digital certificates while maintaining security.
Solution Approach 2:
A cloud-based key delivery system acts as an intermediary between the message sender and receiver. The system automatically manages key distribution and retrieval without requiring manual certificate installation or administration on endpoint devices. This intermediary handles the complexity of key management centrally.
2Reliability
If digital certificates are installed on each IoT device for asymmetric cryptographic communications, then secure communications are enabled, but the cost and difficulty of installation and management increases significantly
Solution Approach 1:
The system enables automated key management where the key delivery system itself handles key distribution, retrieval, and rotation without human intervention. Devices automatically receive their cryptographic keys through the cloud-based system, eliminating manual certificate installation and simplifying operations for large-scale IoT deployments.
3Adaptability or versatility
If asymmetric cryptographic deployments are implemented, then encryption capability is provided, but vulnerability to attacks (compromised certificate authorities, man-in-the-middle attacks) increases
Solution Approach 1:
By segmenting the cryptographic key across multiple geographically distributed relay servers, the system eliminates single points of failure and vulnerability. Even if some servers are compromised, the attacker cannot obtain the complete key without compromising all servers simultaneously, which is computationally infeasible.
Solution Approach 2:
The system moves from traditional endpoint-based security to a distributed cloud-based security model. By adding the spatial dimension of geographic distribution across multiple cloud servers, the system creates multiple layers of defense that make traditional attacks like man-in-the-middle and certificate authority compromise ineffective.
Data Source
AI summary
An embodiment of an automatic key delivery system is described, An automatic key delivery system comprises the following operations. Herein, a first token is generated and provided to a first network device. Thereafter, a first key value pair, including the first token and a first key segment of a cryptographic key, is received by a first relay server and a second key value pair, including the first token and a second key segment of the cryptographic key, is received from a second relay server. In response, a second token to be provided to the first relay server and the second relay server. Thereafter, the first and second key segment are returned from the first and second relay servers based on usage of the second token as a lookup in order to recover the cryptographic key for decryption of an encrypted content from the first network device.


