Physical Connection Key Exchange for Secure Encryption Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional encryption/decryption systems, such as those using the RSA algorithm, are vulnerable to hacking as symmetric keys are transmitted over shared networks, allowing malicious actors to potentially discover private keys from public keys, compromising data security, especially in financial transactions and electronic money systems.
Innovation Solution
An encryption/decryption device and method where keys are generated and shared only when devices are physically connected, using a key storage unit, processing unit, and connection unit to encrypt and decrypt data with identifiers known to both devices, ensuring secure key distribution and eliminating the risk of key leakage or hacking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If symmetric keys are transmitted using RSA over shared networks, then data can be encrypted and transmitted between communication entities, but the private key may be discovered by malicious actors, compromising security
Solution Approach 1:
The patent extracts the key generation and sharing process from the network communication channel and relocates it to a physical connection channel. Keys are generated locally in each encryption/decryption device and shared only through physical connection, completely removing keys from network transmission where they could be intercepted or discovered by hackers.
Solution Approach 2:
The patent introduces a physical connection unit as an intermediary medium for key sharing. Instead of transmitting keys directly over networks, the physical connection unit serves as a secure mediator that enables key exchange only when devices are physically connected, blocking unauthorized access while allowing legitimate key sharing.
2Adaptability or versatility
If keys are shared over networks, then encryption/decryption can be performed between communication entities, but the possibility of hacking exists during key distribution
Solution Approach 1:
The patent extracts the vulnerable key distribution process from the network communication environment and relocates it to a physically connected environment. This separation removes keys from the attack surface of network-based hacking while preserving the ability to perform encryption/decryption operations over networks.
Solution Approach 2:
The patent applies preliminary anti-action by preventing key sharing before any network transmission occurs. Keys are generated and shared through physical connection first, establishing secure encryption/decryption capabilities before any data is transmitted over networks, thereby preemptively blocking hacking risks during key distribution.
3Reliability
If physical connection is required for key sharing, then key security is enhanced, but device complexity increases
Solution Approach 1:
The patent makes the physical connection unit serve multiple functions: it acts as both a physical connector for device linkage and a secure key exchange channel. This multi-functionality reduces the need for separate dedicated key distribution hardware, thereby limiting the increase in device complexity while maintaining enhanced security through physical connection requirements.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An encryption/decryption device connected to a communications entity includes: a key storage unit configured to store predetermined keys; a processing unit configured to receive a first key among the predetermined keys from the key storage unit and to encrypt data based on the received first key; a data port unit configured to receive data to be encrypted from the communications entity, to transfer the received data to the processing unit, if the data transferred to the processing unit is encrypted by the processing unit based on the first key, to receive the encrypted data from the processing unit, and to transfer the encrypted data received from the processing unit to the communications entity; and a connection unit configured to physically connect the encryption/decryption device with another encryption/decryption device. The predetermined keys are generated when the connection unit is connected to a connection unit included in the another encryption/decryption device.