Transient Symmetric Key Technology for Zero-Trust Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data security methods, particularly those using public key infrastructure (PKI) and legacy encryption standards like AES-128, are vulnerable to breaches and hacks due to the storage and management of private keys, and reliance on certificate authorities, which can lead to data exposure.
Innovation Solution
A transient symmetric key technology (TSKT) system that generates and destroys encryption and decryption keys on demand, utilizing a distributed, zero-trust, end-to-end encryption architecture, eliminating the need for certificate authorities and storing private keys, and ensuring keys exist only for a short time to prevent hacking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If private keys are stored on devices for PKI encryption, then data can be decrypted when needed, but the system becomes vulnerable to breaches and hacks that expose sensitive user data
Solution Approach 1:
The patent extracts the private key from permanent storage and replaces it with transient keys that are generated on-demand and automatically destroyed after use. This removes the vulnerable stored private key while maintaining decryption capability through temporary key generation.
Solution Approach 2:
The system transitions from static stored private keys to dynamic transient keys that are continuously generated and destroyed. Keys exist only momentarily during encryption/decryption operations, making the system adaptive and resistant to traditional key extraction attacks.
2Reliability
If certificate authorities issue private keys for trusted access, then users can securely access data, but the CAs themselves can be breached leading to counterfeit certificates and data theft
Solution Approach 1:
The patent removes the certificate authority from the key issuance process entirely. Instead of relying on external CAs, the system generates keys locally on user devices, eliminating the single point of failure that CA breaches represent.
Solution Approach 2:
Users generate and manage their own encryption keys locally on their devices without external intervention. This self-service approach to key management eliminates dependency on vulnerable certificate authorities while maintaining security.
3Reliability
If AES-128 encryption is used for data protection, then data can be encrypted with reasonable computational overhead, but the encryption can theoretically be discovered or hacked with sufficient resources
Solution Approach 1:
The system implements dynamic key lengths that adapt to security requirements. Rather than fixed AES-128, the patent generates transient keys with sufficient complexity for each operation, balancing security strength with computational efficiency on a per-operation basis.
Solution Approach 2:
The patent changes the fundamental parameter of key persistence from permanent to transient. This transformation increases effective security without requiring proportionally higher computational complexity, as the security comes from key ephemerality rather than just key length.
Data Source
AI summary
A method includes logging into a server and sending geolocation information to the server by a first device. The first device requests rights to decrypt a secure data file, and in response, the server sends a machine-readable optical label to the first device. The first device displays the machine-readable optical label. A second device logs into the server, and scans the machine-readable optical label displayed by the first device to create a scanned image. The second device decodes data from the scanned image to form decoded data. Geolocation information of the second device and the decoded data are submitted to the server. The decoded data and the geolocation information are validated by the server, and in response to successfully validating the geolocation information, a link completion status indicator is sent to the second device, and information to decrypt the secure data file is sent to the first device.


