Segmented Symmetric Key Distribution for Secure Real-Time Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for distributing encoding/decoding programs and symmetric keys in a security domain environment are inadequate for real-time data processing in narrow-bandwidth networks and are vulnerable to exposure and fake attacks, especially when devices across different security levels manage confidential information.
Innovation Solution
A method involving a highest-level security domain dividing and distributing an encoding/decoding program and symmetric key into pieces, which can only be combined and executed by devices in lower-level security domains, using a data divider and injector to ensure secure operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If public key is used for distributing encoding/decoding program and key, then security is improved, but real-time data processing capability deteriorates due to tremendous mathematical calculations
Solution Approach 1:
The patent segments the symmetric key into multiple pieces (first key piece, second key piece, etc.) and distributes them to different lower-level security domains. This allows the system to use efficient symmetric key encryption for real-time data processing while maintaining security through distributed key pieces that require combination to reconstruct the full key.
2Productivity
If symmetric key is stored in encoder/decoder for authentication, then real-time data processing is improved, but security deteriorates due to vulnerability to de-capping and man-in-the-middle attacks
Solution Approach 1:
The symmetric key is divided into multiple pieces stored in different security domains rather than keeping the complete key in one location. This segmentation prevents exposure through de-capping attacks and mitigates man-in-the-middle attacks, as the complete key cannot be reconstructed from individual pieces stored separately in secured environments.
Solution Approach 2:
The patent introduces an intermediary mechanism where key pieces are distributed through a data divider and combined through a data injector in the encoder/decoder. This intermediary process ensures secure key distribution and combination, maintaining both security and real-time processing capability.
3Ease of operation
If encoding/decoding program and key are distributed as complete files, then ease of operation is improved, but security deteriorates due to exposure risk in lower-level security domains
Solution Approach 1:
The complete encoding/decoding program and symmetric key are segmented into multiple pieces before distribution to lower-level security domains. Each piece alone is insufficient for operation, providing security while maintaining ease of distribution through automated assembly processes using the data injector.
Solution Approach 2:
The patent merges multiple key pieces and program segments through the data injector in the encoder/decoder to reconstruct the complete functional system. This combining process occurs in a controlled environment, ensuring security while achieving operational simplicity.
Data Source
AI summary
A method of distributing an encoding/decoding program and a symmetric key in a security domain environment, and a device divider and data injector therefor are provided. The method includes selecting, at a highest-level security domain, an encoding/decoding program and a symmetric key to be distributed to a plurality of lower-level security domains; dividing the selected encoding/decoding program and the symmetric key into pieces as many as the number of lower-level security domains; and distributing the divided encoding/decoding program pieces and the symmetric key pieces to devices belonging to the lower-level security domains.


