Qwyit Authentication Service Unbreakable Encryption TLS Replacement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure communication protocols, such as Transport Layer Security (TLS), face limitations in performance, complexity, flexibility, and security, particularly in supporting widespread secure communication across multiple platforms and applications, and fail to provide efficient key distribution and management for provably secure, private, and authentic communication.
Innovation Solution
The Qwyit Authentication and Encryption Service (QAES) offers a direct replacement for TLS, providing authenticated and encrypted message traffic with unbreakable encryption, using a Qwyit Directory Service key store, and enabling Perfect Forward Secrecy, authentication, encryption, and replay prevention without degrading network performance, and can be easily integrated into existing systems, including small Internet of Things devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TLS protocol is used for secure communication, then authentication and encryption are provided, but performance degrades and complexity increases
Solution Approach 1:
The patent changes the cryptographic parameters by using a custom cipher based on the Vernam one-time pad with a specific key derivation function that processes keys in blocks of 16 bytes. This parameter change enables faster encryption/decryption operations while maintaining security, directly addressing the performance degradation issue of TLS without sacrificing authentication and encryption reliability.
2Reliability
If TLS protocol is used for secure communication, then security is provided, but device complexity increases
Solution Approach 1:
The patent extracts the complex key management and certificate verification processes from TLS by implementing a simplified authentication mechanism where the server proves knowledge of a secret key without requiring digital certificates. This extraction reduces implementation complexity while maintaining secure communication reliability.
Solution Approach 2:
Instead of the traditional TLS approach where the server presents a certificate to prove identity, this patent inverts the approach by having the server send a challenge and the client respond with an authentication token. This inversion simplifies the authentication process and reduces the complexity of implementing secure communication.
3Extent of automation
If traditional key distribution methods are used, then key exchange is enabled, but flexibility and adaptability are reduced
Solution Approach 1:
The patent implements a universal authentication mechanism where any client can authenticate to any server using the same simplified challenge-response protocol. This multi-functionality enables flexible key distribution across different platforms and applications without requiring platform-specific implementations, directly improving adaptability while maintaining automated key exchange capability.
Data Source
AI summary
Qwyit® Authentication and Encryption Service serves as a direct replacement of Transport Layer Security. Applications can place a small code segment within their communications protocol, resulting in authenticated and encrypted message traffic with the features of TLS while adding additional improvements as set forth herein. QAES provides a direct next generation replication and enhancement of the current, only global secure communications framework. QAES provides the same features, benefits, authentication (embedded) and data security (stream cipher) for communications traffic using the Qwyit® Directory Service key store. The combination of features and properties provide a simple, straightforward way for any application to incorporate secure communications. The unique, superior Qwyit® protocol delivers where TLS fails: embedded security without any need for additional bandwidth, processing power or cumbersome user requirements. QAES shows Qwyit® can provide secure communications within the network tolerances for insecure communications. QAES easily allows any client/server or cloud-based application to add TLS-like authentication and encryption. The present invention includes a Qwyit® Directory Server application that can be run on, or added to, any current communications server (web, file, comms, app, DB, etc.), as well as client code for easy insertion into the communications protocol/processing of a connected device/app.


