User Device Key Synchronization Using Multi-Server Shares
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing encrypted communication systems face challenges in securely sharing a common initial solution among a large number of communication devices, as the control device managing synchronization information can potentially tap the communication if it has malicious intent.
Innovation Solution
A method involving user devices and server devices that generate and share synchronized solutions using unique synchronization information from multiple servers, ensuring that no single server or administrator can derive the initial solution, thus enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single control device generates synchronization information for all user devices, then the system is easier to manage and initialize, but the security is compromised because a malicious control device or administrator can tap into encrypted communications by generating the initial solution
Solution Approach 1:
The system divides the centralized control function into multiple independent server devices. Each server device generates only a portion of the synchronization information, and no single server device possesses the complete information needed to generate the initial solution. This segmentation prevents any single point of failure or malicious control while maintaining system manageability through distributed architecture.
Solution Approach 2:
User devices act as intermediaries that combine synchronization information from multiple server devices. The user device receives partial synchronization information from different servers, combines them locally, and generates the initial solution without any single server device having access to the complete information. This intermediary role distributes trust and prevents centralized security vulnerabilities.
2Reliability
If multiple server devices generate synchronization information, then security is improved by preventing single-point compromise, but the complexity of the system increases
Solution Approach 1:
Each server device performs multiple functions: generating synchronization information, transmitting it to user devices, and maintaining independence from other servers. The user devices universally handle reception from multiple servers, combination of information, and initial solution generation. This multi-functionality reduces the need for specialized components and simplifies the overall system architecture despite the distributed nature.
Solution Approach 2:
The system uses identical synchronization information structures and generation algorithms across multiple server devices. Each server device creates copies of the synchronization information format, ensuring consistency and interoperability. This copying approach with standardized formats reduces complexity by eliminating the need for custom integration logic between different server types.
3Reliability
If synchronization information is transmitted to user devices from multiple servers, then unauthorized access is prevented, but the time and overhead for information distribution increases
Solution Approach 1:
Synchronization information is generated and made available from multiple server devices in advance, before the user device needs to generate the initial solution. This preliminary distribution allows user devices to retrieve the information when needed without causing delays in the encryption setup process. The information is prepared and staged ahead of time for efficient retrieval.
Data Source
AI summary
A secure technology for allowing two communication devices intending to execute encrypted communication to have a common initial solution. A large number of user devices all have a function of generating the same solution under the same condition when the user devices have the same initial solution, and can execute encrypted communication through use of a synchronized solution successively generated from the same initial solution. Each of two server devices generates synchronization information which is not the initial solution itself and which is required by the two user devices intending to execute the communication to generate the same initial solution, and transmits the synchronization information to the two user devices each of which executes predetermined calculation on the two pieces of synchronization information, to thereby generate the same initial solution. After that, the two user devices execute the encrypted communication based on the same initial solution.


