Physical Key Exchange for Secure Data Checking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data encryption systems, such as RSA, are vulnerable to key theft and tampering, especially when keys are shared over networks, and users cannot reliably verify if their requests have been compromised, leading to potential financial and personal information leakage.

Innovation Solution

A data checking device that physically connects with another device to share and generate identical encryption/decryption keys, using a key identifier generated from known keys and random numbers, ensuring secure key exchange without network transmission, and includes a protection unit to detect abnormal actions and delete keys if necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If keys are shared over networks for data encryption/decryption, then data transmission capability is improved, but security against key theft deteriorates

Engineering Contradiction:
Improvedata transmission capabilityVSAvoidsecurity against key theft
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A connection unit is introduced as an intermediary physical medium between the data checking device and another device. This physical connection unit acts as a mediator that enables secure key sharing through direct physical contact (e.g., USB connection, contactless communication), preventing network-based key theft while maintaining data transmission capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the electronic/network-based key sharing system with a physical connection-based system. By substituting the mechanical/physical connection method for electronic network transmission, the system achieves secure key exchange that cannot be intercepted remotely, thus improving security while maintaining adaptability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If RSA asymmetric key system is used for encryption, then data security is improved, but vulnerability to mathematical attacks deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidvulnerability to mathematical attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the key sharing process from the public network environment and relocates it to a secure physical connection channel. By separating the key exchange function from the data transmission function and implementing it through a dedicated physical connection unit, the system eliminates the mathematical vulnerability of RSA while maintaining its encryption security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system segments the cryptographic functions into separate components: the data checking device holds one set of keys, and another device holds corresponding keys. This segmentation allows each device to maintain secure local key storage while enabling verification through physical connection, reducing the impact of mathematical attacks on the overall system security.

Inventive Principle:
Principle #1Segmentation

3Reliability

If security media such as OTP are utilized, then authentication security is improved, but protection against malicious code infection deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidprotection against malicious code
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary verification by checking whether the another device possesses the corresponding keys before allowing data transmission or authentication. This preliminary action through physical connection verification ensures that even if devices are infected with malicious code, the attacker cannot compromise the system without the physical presence of the key-holding device.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3236631B1Data checking device and data checking method using the same
Publication Date: 2021.04.21 IND ACADEMIC COOP FOUND DANKOOK UNIV
  • EP3236631B1 patent drawingFigure 1
  • EP3236631B1 patent drawingFigure 2
  • EP3236631B1 patent drawingFigure 3~4

AI summary

A data checking device that is connected to a communication entity includes: a port unit configured to communicate with the communication entity; a key storage unit configured to store predetermined keys; an encryption/decryption unit configured to encrypt or decrypt data transmitted from the communication entity through the port unit by using a first key among the predetermined keys; an output unit configured to output decrypted data; and a connection unit configured to physically connect the data checking device with another device storing keys which are identical to the predetermined keys. The predetermined keys stored in the key storage unit are generated and stored when the data checking device is connected to the another device by the connection unit.