Proxy Server Key Retrieval via Broker-Mediated Quantum-Secure Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securely distributing encryption keys to proxy servers are laborious, time-consuming, and expensive, especially as they rely on manual keyfill and are vulnerable to quantum computer attacks, making them inefficient for large-scale distributed computing systems.
Innovation Solution
A method for distributing encryption keys to proxy servers using a third-party service to agree common encryption keys and IDs between a client device and a broker device, storing these at both ends, and enabling secure key retrieval via a shared memory, database, or pipes, without manual keyfill or asymmetric-primitive exchanges, ensuring quantum security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual keyfill is used to distribute encryption keys to proxy servers, then security is maintained, but the process becomes laborious, time-consuming, and expensive
Solution Approach 1:
The system performs preliminary key agreement between the client device and broker device before the actual communication session. The encryption keys are established in advance through quantum key distribution, stored securely, and made available for rapid retrieval during proxy server operations, eliminating the need for manual keyfill at the time of deployment
Solution Approach 2:
A broker device is introduced as an intermediary between the client device and proxy server. The broker facilitates automatic key distribution by receiving key requests from the proxy server, verifying them against pre-agreed keys, and automatically providing the appropriate encryption keys, thereby replacing manual key management operations
2Reliability
If manual keyfill is used for key distribution, then security is maintained, but device complexity and operational difficulty increase as systems scale
Solution Approach 1:
The proxy server is configured to automatically request and receive encryption keys from the broker device without human intervention. The system performs self-service key management by automatically initiating key requests, verifying key IDs, and retrieving appropriate keys, thereby reducing operational complexity and eliminating manual keyfill operations even in large-scale distributed systems
3Ease of operation
If asymmetric-primitive key-exchange protocols are used between proxy server and client, then key distribution is simplified, but quantum security is compromised
Solution Approach 1:
Quantum key distribution is performed in advance between the client device and broker device to establish encryption keys before any asymmetric-primitive key exchange would occur. This preliminary quantum key agreement ensures that when the proxy server needs keys, they are already securely established through quantum-resistant methods, allowing the system to avoid vulnerable asymmetric protocols entirely
Solution Approach 2:
The broker device acts as a quantum-secure intermediary that receives key requests from the proxy server and provides keys that were pre-established through quantum key distribution. This intermediary architecture allows the proxy server to obtain quantum-secure keys automatically without needing to implement asymmetric-primitive key exchange protocols, maintaining both simplicity and quantum security
Data Source
AI summary
A system and method for distributing an encryption key to a proxy server configured to operate as a proxy for a third-party, including agreeing, between a client device (CD) and a broker device (BD), a common encryption key (CEK) using a third party service and a key ID corresponding to the CEK; storing, at the CD and the BD, respective copies of the encryption keys and the key IDs; transmitting, from the CD to the proxy server, a request, based on one of the key IDs, to establish a secure connection between the CD and the proxy server; transmitting, from the proxy server to the BD, a request for an encryption key based on the key ID associated with the request transmitted from the CD to the BD; verifying that the key ID corresponds to CEK; and after successful verification, receiving, at the proxy server, the corresponding CEK.


