One-Time Pad Provisioning via Trusted Server Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

One-time pad (OTP) cryptographic systems face challenges in efficiently sharing and replenishing secret random data, especially in applications requiring high security, due to the need for frequent physical transport or vulnerable encryption methods, which can compromise security and are costly.

Innovation Solution

A device and method for managing multiple one-time pads with varying security ratings, using a provisioning process to obtain new secret random data and match it with a pad and process to ensure the security rating is maintained, allowing flexible sharing and use of OTP data in systems with less than highest security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If OTP data is physically transported in a storage medium to share new secret random data between two parties, then security is maintained, but cost and feasibility deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidcost and feasibility
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

A trusted third party server acts as an intermediary to distribute OTP data to multiple parties simultaneously. The server generates or obtains secret random data and securely transmits it to all authorized parties through communication channels, eliminating the need for physical transport between each pair of parties while maintaining security through controlled distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical approach of physical storage medium transport with an electronic/digital distribution system. Instead of physically moving encrypted storage media between parties, the system uses electronic transmission of OTP data through communication networks, significantly reducing cost and improving feasibility while maintaining security through proper authentication and encryption protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If OTP data is shared frequently to replenish consumed data, then security is maintained, but cost and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted third party server provides a universal OTP distribution service that can serve multiple parties and multiple applications simultaneously. Instead of implementing separate OTP management systems for each party or application, the single server handles authentication, generation, and distribution of OTP data to multiple clients, reducing overall system complexity while maintaining security through centralized control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary actions by pre-generating and storing OTP data in the trusted third party server before it is needed by the parties. When parties need OTP data, they simply request it from the server which already has it prepared and authenticated, eliminating the need for complex real-time generation and distribution processes and reducing system complexity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If OTP data is stored in a highly secure manner, then security is maintained, but accessibility and flexibility deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidaccessibility and flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The trusted third party server serves as a secure intermediary that maintains OTP data in a highly secure manner while providing controlled access to authorized parties. The server implements authentication mechanisms to verify party identities and authorization levels, allowing parties to access OTP data through secure communication channels without compromising the overall security of the stored data. This resolves the contradiction by decoupling storage security from access convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8842839B2Device with multiple one-time pads and method of managing such a device
Publication Date: 2014.09.23 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8842839B2 patent drawing
  • US8842839B2 patent drawing
  • US8842839B2 patent drawing

AI summary

A device is arranged to carry out security-related tasks using one-time pad data. The device has a memory for holding multiple one-time pads, each pad having a different security rating and being intended for use by the device in executing a task to that security rating. Provisioning of the pads with one-time pad data involves carrying out a process for obtaining new secret random data. This process has a security rating with the value of this rating varying according to the nature and parameters of the process concerned. The security rating of the process used to obtain the new secret random data is matched to that of the pad to be provisioned with one-time data, or the other way around, such that the security rating of the process is as least as good as that of the pad to be provisioned.