Trusted Intermediary Key Exchange for Simplified Device Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic communication methods face challenges in establishing secure, authenticated, private communications between parties without initial encrypted channels, particularly due to the need for public key listings and user technical capabilities, leading to limitations in adoption and reliability.
Innovation Solution
A key exchange system that allows a single party to initiate encrypted communication using a shared secret, facilitating the establishment of encrypted communications by encrypting one of the private or public key pairs and utilizing a separate communication channel, without requiring the receiving party to have advanced configuration capabilities, and using a trusted intermediary for key exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If asymmetric key exchange is used to secure communications, then security and forward secrecy are improved, but device complexity and user configuration requirements increase
Solution Approach 1:
The patent introduces a trusted intermediary service that manages asymmetric key pairs and handles the complex key exchange process. Users simply share a secret through the intermediary, which then generates and distributes asymmetric key pairs automatically. This mediator absorbs the configuration complexity while maintaining security benefits.
Solution Approach 2:
The system enables users to initiate encrypted communications without requiring the receiving party to have advanced configuration capabilities. The initiating party can send encrypted messages using only a shared secret, and the intermediary automatically handles key generation and distribution to the receiving party, making the system self-configuring.
2Adaptability or versatility
If public key distribution systems are used, then encrypted communication capability is improved, but key management complexity and user technical requirements increase
Solution Approach 1:
The trusted intermediary service centralizes key management operations, generating asymmetric key pairs and distributing them automatically based on shared secrets. This eliminates the need for users to manually manage public key infrastructure, list public keys in repositories, or configure complex encryption protocols.
Solution Approach 2:
The system performs key generation and distribution in advance through the intermediary service. When users establish a shared secret through the intermediary, the asymmetric key pairs are already generated and ready for use, eliminating the need for users to perform complex setup procedures before communication.
3Reliability
If TLS handshake with public key exchange is used, then message security is improved, but computational overhead increases
Solution Approach 1:
The patent separates the computationally intensive asymmetric key generation and exchange operations from the actual message communication. The trusted intermediary handles the heavy computational lifting of generating and distributing asymmetric key pairs, while users only need to perform lightweight symmetric encryption using shared secrets for actual message exchange.
Solution Approach 2:
The intermediary service absorbs the computational overhead of asymmetric cryptography by generating and managing key pairs centrally. Users benefit from the security of asymmetric encryption without bearing the computational burden, as the intermediary has already prepared the necessary cryptographic materials.
Data Source
AI summary
Key exchange methods, apparati, and computer-readable media for a cryptographic communication system. The system, which employs a novel combination of multiple channel communication, symmetric cryptography, and asymmetric cryptography, allows an entity A to bootstrap the exchange of cryptographic secrets EQB to a second entity B through an alternate communication channel 30 for the transmission of a cryptographically secure message M. The system is secure against various passive and active attacks. The encryption key transfer is briefly vulnerable to man-in-the-middle attacks, but this can be prevented in preferred embodiments.


