Qwyit Authentication Service Unbreakable Encryption TLS Replacement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure communication protocols, such as Transport Layer Security (TLS), face limitations in performance, complexity, flexibility, and security, particularly in supporting widespread secure communication across multiple platforms and applications, and fail to provide efficient key distribution and management for provably secure, private, and authentic communication.

Innovation Solution

The Qwyit Authentication and Encryption Service (QAES) offers a direct replacement for TLS, providing authenticated and encrypted message traffic with unbreakable encryption, using a Qwyit Directory Service key store, and enabling Perfect Forward Secrecy, authentication, encryption, and replay prevention without degrading network performance, and can be easily integrated into existing systems, including small Internet of Things devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TLS protocol is used for secure communication, then authentication and encryption are provided, but performance degrades and complexity increases

Engineering Contradiction:
Improveauthentication and encryption securityVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent changes the cryptographic parameters by using a custom cipher based on the Vernam one-time pad with a specific key derivation function that processes keys in blocks of 16 bytes. This parameter change enables faster encryption/decryption operations while maintaining security, directly addressing the performance degradation issue of TLS without sacrificing authentication and encryption reliability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If TLS protocol is used for secure communication, then security is provided, but device complexity increases

Engineering Contradiction:
Improvesecure communicationVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex key management and certificate verification processes from TLS by implementing a simplified authentication mechanism where the server proves knowledge of a secret key without requiring digital certificates. This extraction reduces implementation complexity while maintaining secure communication reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of the traditional TLS approach where the server presents a certificate to prove identity, this patent inverts the approach by having the server send a challenge and the client respond with an authentication token. This inversion simplifies the authentication process and reduces the complexity of implementing secure communication.

Inventive Principle:
Principle #13The other way round (Inversion)

3Extent of automation

If traditional key distribution methods are used, then key exchange is enabled, but flexibility and adaptability are reduced

Engineering Contradiction:
Improvekey exchange capabilityVSAvoidplatform compatibility
Core Design Contradiction:
Extent of automationVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal authentication mechanism where any client can authenticate to any server using the same simplified challenge-response protocol. This multi-functionality enables flexible key distribution across different platforms and applications without requiring platform-specific implementations, directly improving adaptability while maintaining automated key exchange capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12192356B2Method and apparatus for authentication and encryption service employing unbreakable encryption
Publication Date: 2025.01.07 HST GLOBAL INC
  • US12192356B2 patent drawing
  • US12192356B2 patent drawing
  • US12192356B2 patent drawing

AI summary

Qwyit® Authentication and Encryption Service serves as a direct replacement of Transport Layer Security. Applications can place a small code segment within their communications protocol, resulting in authenticated and encrypted message traffic with the features of TLS while adding additional improvements as set forth herein. QAES provides a direct next generation replication and enhancement of the current, only global secure communications framework. QAES provides the same features, benefits, authentication (embedded) and data security (stream cipher) for communications traffic using the Qwyit® Directory Service key store. The combination of features and properties provide a simple, straightforward way for any application to incorporate secure communications. The unique, superior Qwyit® protocol delivers where TLS fails: embedded security without any need for additional bandwidth, processing power or cumbersome user requirements. QAES shows Qwyit® can provide secure communications within the network tolerances for insecure communications. QAES easily allows any client/server or cloud-based application to add TLS-like authentication and encryption. The present invention includes a Qwyit® Directory Server application that can be run on, or added to, any current communications server (web, file, comms, app, DB, etc.), as well as client code for easy insertion into the communications protocol/processing of a connected device/app.