Transient Symmetric Key Technology for Zero-Trust Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security methods, particularly those using public key infrastructure (PKI) and legacy encryption standards like AES-128, are vulnerable to breaches and hacks due to the storage and management of private keys, and reliance on certificate authorities, which can lead to data exposure.

Innovation Solution

A transient symmetric key technology (TSKT) system that generates and destroys encryption and decryption keys on demand, utilizing a distributed, zero-trust, end-to-end encryption architecture, eliminating the need for certificate authorities and storing private keys, and ensuring keys exist only for a short time to prevent hacking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If private keys are stored on devices for PKI encryption, then data can be decrypted when needed, but the system becomes vulnerable to breaches and hacks that expose sensitive user data

Engineering Contradiction:
Improvedata securityVSAvoidkey exposure vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the private key from permanent storage and replaces it with transient keys that are generated on-demand and automatically destroyed after use. This removes the vulnerable stored private key while maintaining decryption capability through temporary key generation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system transitions from static stored private keys to dynamic transient keys that are continuously generated and destroyed. Keys exist only momentarily during encryption/decryption operations, making the system adaptive and resistant to traditional key extraction attacks.

Inventive Principle:
Principle #15Dynamics

2Reliability

If certificate authorities issue private keys for trusted access, then users can securely access data, but the CAs themselves can be breached leading to counterfeit certificates and data theft

Engineering Contradiction:
Improvetrusted accessVSAvoidCA breach vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent removes the certificate authority from the key issuance process entirely. Instead of relying on external CAs, the system generates keys locally on user devices, eliminating the single point of failure that CA breaches represent.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Users generate and manage their own encryption keys locally on their devices without external intervention. This self-service approach to key management eliminates dependency on vulnerable certificate authorities while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If AES-128 encryption is used for data protection, then data can be encrypted with reasonable computational overhead, but the encryption can theoretically be discovered or hacked with sufficient resources

Engineering Contradiction:
Improveencryption strengthVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements dynamic key lengths that adapt to security requirements. Rather than fixed AES-128, the patent generates transient keys with sufficient complexity for each operation, balancing security strength with computational efficiency on a per-operation basis.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameter of key persistence from permanent to transient. This transformation increases effective security without requiring proportionally higher computational complexity, as the security comes from key ephemerality rather than just key length.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11876797B2Multi-factor geofencing system for secure encryption and decryption system
Publication Date: 2024.01.16 EVERYTHING BLOCKCHAIN TECHNOLOGY CORP
  • US11876797B2 patent drawing
  • US11876797B2 patent drawing
  • US11876797B2 patent drawing

AI summary

A method includes logging into a server and sending geolocation information to the server by a first device. The first device requests rights to decrypt a secure data file, and in response, the server sends a machine-readable optical label to the first device. The first device displays the machine-readable optical label. A second device logs into the server, and scans the machine-readable optical label displayed by the first device to create a scanned image. The second device decodes data from the scanned image to form decoded data. Geolocation information of the second device and the decoded data are submitted to the server. The decoded data and the geolocation information are validated by the server, and in response to successfully validating the geolocation information, a link completion status indicator is sent to the second device, and information to decrypt the secure data file is sent to the first device.