Physical Key Exchange for Secure Data Checking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data encryption systems, such as RSA, are vulnerable to key theft and tampering, especially when keys are shared over networks, and users cannot reliably verify if their requests have been compromised, leading to potential financial and personal information leakage.
Innovation Solution
A data checking device that physically connects with another device to share and generate identical encryption/decryption keys, using a key identifier generated from known keys and random numbers, ensuring secure key exchange without network transmission, and includes a protection unit to detect abnormal actions and delete keys if necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If keys are shared over networks for data encryption/decryption, then data transmission capability is improved, but security against key theft deteriorates
Solution Approach 1:
A connection unit is introduced as an intermediary physical medium between the data checking device and another device. This physical connection unit acts as a mediator that enables secure key sharing through direct physical contact (e.g., USB connection, contactless communication), preventing network-based key theft while maintaining data transmission capability.
Solution Approach 2:
The patent replaces the electronic/network-based key sharing system with a physical connection-based system. By substituting the mechanical/physical connection method for electronic network transmission, the system achieves secure key exchange that cannot be intercepted remotely, thus improving security while maintaining adaptability.
2Reliability
If RSA asymmetric key system is used for encryption, then data security is improved, but vulnerability to mathematical attacks deteriorates
Solution Approach 1:
The patent extracts the key sharing process from the public network environment and relocates it to a secure physical connection channel. By separating the key exchange function from the data transmission function and implementing it through a dedicated physical connection unit, the system eliminates the mathematical vulnerability of RSA while maintaining its encryption security.
Solution Approach 2:
The system segments the cryptographic functions into separate components: the data checking device holds one set of keys, and another device holds corresponding keys. This segmentation allows each device to maintain secure local key storage while enabling verification through physical connection, reducing the impact of mathematical attacks on the overall system security.
3Reliability
If security media such as OTP are utilized, then authentication security is improved, but protection against malicious code infection deteriorates
Solution Approach 1:
The patent implements preliminary verification by checking whether the another device possesses the corresponding keys before allowing data transmission or authentication. This preliminary action through physical connection verification ensures that even if devices are infected with malicious code, the attacker cannot compromise the system without the physical presence of the key-holding device.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
A data checking device that is connected to a communication entity includes: a port unit configured to communicate with the communication entity; a key storage unit configured to store predetermined keys; an encryption/decryption unit configured to encrypt or decrypt data transmitted from the communication entity through the port unit by using a first key among the predetermined keys; an output unit configured to output decrypted data; and a connection unit configured to physically connect the data checking device with another device storing keys which are identical to the predetermined keys. The predetermined keys stored in the key storage unit are generated and stored when the data checking device is connected to the another device by the connection unit.