Dynamic Security Key Hopping via Selection Criteria
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud data security schemes face challenges in providing dynamic and secure key management for authentication and encryption, as static keys can be vulnerable to breaches and do not adapt effectively to changing communication conditions.
Innovation Solution
Implementing a security key hopping system where multiple keys are shared between users and storage systems, with a selection criterion determining which key to use for each communication, ensuring that keys change based on predetermined criteria such as time, location, or session parameters, thereby enhancing security through dynamic key rotation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single static key is used for authentication and encryption, then the system is simple to manage, but the security is vulnerable to breaches and does not adapt to changing conditions
Solution Approach 1:
The patent implements dynamic key selection by maintaining multiple keys in a key ring and selecting different keys based on communication conditions. The key used for encryption changes dynamically based on criteria such as time, counter values, or communication partners, transforming the static key system into a dynamic one that adapts to changing security requirements.
Solution Approach 2:
The patent segments the single key function into multiple keys organized in a key ring structure. Each key in the key ring serves a specific purpose or time period, dividing the monolithic key management into manageable segments. This segmentation allows the system to use different keys for different communication scenarios, enhancing security while maintaining organized management.
2Reliability
If multiple keys are shared between users and storage systems, then security is enhanced through dynamic key rotation, but key management complexity increases
Solution Approach 1:
The patent implements self-service key selection through predetermined selection criteria that automatically determine which key to use from the key ring. Both communication parties independently select the same key based on shared criteria such as time stamps, counter values, or communication identifiers, eliminating the need for manual key coordination or complex key distribution protocols.
Solution Approach 2:
The patent performs preliminary key distribution by sharing the entire key ring and selection criteria between communication parties before actual communication begins. This preliminary action ensures that both parties have the necessary keys and agreed-upon selection rules in advance, enabling seamless and secure communication without real-time key negotiation.
3Adaptability or versatility
If keys change based on predetermined criteria such as time or session parameters, then adaptability to changing conditions is improved, but the system complexity increases
Solution Approach 1:
The patent utilizes parameter changes in the selection criteria (such as time progression, counter increments, or session identifiers) to automatically determine key selection. As these parameters change during communication, the selected key changes accordingly, providing adaptability to different communication conditions without requiring complex decision-making logic.
Data Source
AI summary
A network resource and a user device include secure connection applications that share one or more keys and a key selection criterion. A communication is received from the user utilizing a key selected from the one or more keys. The network resource selects a key based on the key selection criterion. If the keys match, then the user device is authorized and the user is allowed to access data of the network resource. The keys may further be selected and used to encrypt and decrypt data. Different key selections provide security to communications.


