One-Time Pad Key Provisioning Using Local Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyber-security measures for one-time pad symmetric key encryption are vulnerable to hacking due to the difficulty in generating truly random numbers and secure delivery of keys, leading to potential breaches in security.
Innovation Solution
Utilizing a quantum random number generator to create globally-unique random numbers, which are physically delivered via tamper-evident packages or devices, and employing a one-time pad symmetric key system for secure communication, ensuring perfect secrecy by avoiding wireless transmission and using biometric authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional key generation and delivery methods are used, then the system is easier to implement, but security is compromised due to vulnerability to hacking and inability to generate truly random numbers
Solution Approach 1:
The patent uses tamper-evident packages as an intermediary physical medium to deliver keys securely. These packages act as a trusted mediator between key generation and key usage, providing physical security and tamper detection capabilities that wireless or electronic transmission cannot provide, thereby resolving the contradiction between security and implementation simplicity.
Solution Approach 2:
The patent replaces electronic/wireless key transmission with physical mechanical delivery via tamper-evident packages. This substitution eliminates vulnerabilities to cyber attacks and hacking associated with electronic transmission, achieving higher security despite increased physical logistics complexity.
2Reliability
If wireless transmission is used for key delivery, then the process is faster and more convenient, but security is compromised due to potential interception and hacking
Solution Approach 1:
The patent employs disposable tamper-evident packages that are used once for key delivery and then discarded or destroyed. This approach ensures that even if the package is compromised, the keys inside cannot be extracted or reused, providing security without requiring complex reusable security infrastructure, thus balancing security with practicality.
Solution Approach 2:
The tamper-evident packages are designed with built-in security features before delivery, including tamper detection mechanisms and secure containment. This beforehand preparation ensures that any attempt to intercept or compromise the keys during transit is detected, providing security assurance without requiring real-time monitoring or complex active defense systems.
3Reliability
If pseudo-random number generators are used, then the system is easier to implement, but security is weakened due to predictability and vulnerability to cracking
Solution Approach 1:
The patent changes the fundamental parameter of randomness generation from algorithmic (pseudo-random) to physical/quantum (truly random). By using quantum mechanical phenomena or physical processes that are inherently unpredictable, the system achieves true randomness that cannot be predicted or reproduced, resolving the contradiction between security and ease of implementation.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Ensures secure and efficient delivery of symmetric keys, preventing unauthorized access and maintaining perfect security by using quantum-generated, globally-unique random numbers and one-time pad encryption.
Implementation Method 1
Utilizing a quantum random number generator to create globally-unique random numbers
Data Source
AI summary
Techniques are disclosed for the provisioning of secure keys to an application. A first globally-unique value of a plurality of globally-unique values is received via a user interface of the application. The first globally-unique value and an application identifier of the application is provided to a computing system via a network. The computing system is configured to determine a second globally-unique value and a third globally-unique value associated with the first globally-unique value based on the application identifier. The second globally-unique value is then received via the user interface. The second globally-unique value is designated as a first secure key. The first secure key is stored in a first location of a memory of the computing device allocated for the application. A third globally-unique value is received via the user interface. The third globally-unique value is designated as a buffer key.


