Wireless Key Agreement via Path-Key Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network error correction codes fail to ensure secure and secret key transmission in wireless networks when one or more nodes are corrupted or untrustworthy, as they do not adequately address adversarial eavesdropping and corruption attacks.

Innovation Solution

The implementation of path key establishment and key pool bootstrapping methods, which utilize error correction codes to securely transmit keys over node-disjoint paths and distribute subsets of keys among intermediate nodes, ensuring secure and secret key agreement between source and receiver nodes, even in the presence of compromised nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If error correction codes are used to transmit keys through intermediate nodes, then key transmission reliability is improved, but security against corrupted nodes deteriorates

Engineering Contradiction:
Improvekey transmission reliabilityVSAvoidadversarial eavesdropping and corruption attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The key transmission path is segmented into multiple node-disjoint paths, and the key material is divided into multiple shares distributed across different intermediate nodes. This segmentation ensures that no single corrupted node can compromise the entire key transmission, as each node only holds a portion of the encoded key material.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Trusted intermediate nodes act as mediators that forward encoded key shares between source and receiver. These intermediaries use information-theoretic network error correction codes to protect the key material during transmission, ensuring that even if some intermediaries are corrupted, the key remains secure through the use of redundant encoding across multiple paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple intermediate nodes are used to transmit keys, then transmission security is improved through node-disjoint paths, but system complexity increases

Engineering Contradiction:
Improvetransmission securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The error correction code structure is designed to simultaneously provide both error correction and secrecy protection functions. The same encoding mechanism that ensures reliable key recovery also guarantees information-theoretic security, eliminating the need for separate security protocols and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system allows flexible adjustment of the number of intermediate nodes and paths based on security requirements. By changing parameters such as the code rate and number of shares, the system can adapt to different security levels without fundamentally altering the underlying architecture, thus managing complexity through parameterization.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If key pool bootstrapping is implemented, then key distribution efficiency is improved, but the risk of key pool compromise increases

Engineering Contradiction:
Improvekey distribution efficiencyVSAvoidkey pool compromise risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The master key pool is segmented into multiple independent shares that are distributed to different intermediate nodes. Each node holds only a subset of the key pool shares, and no single node possesses the complete key pool. This segmentation allows efficient key distribution through bootstrapping while limiting the impact of any single node compromise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Intermediate nodes receive and store more key shares than strictly necessary for any single key derivation, creating redundancy. This excessive distribution of shares ensures that even if some nodes are compromised, sufficient shares remain at other nodes to reconstruct and protect the key pool, thereby reducing the overall risk of compromise.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9544136B2Key agreement in wireless networks with active adversaries
Publication Date: 2017.01.10 CALIFORNIA INST OF TECH
  • US9544136B2 patent drawing
  • US9544136B2 patent drawing
  • US9544136B2 patent drawing

AI summary

A network and related methods for transmitting processes in a network secretly and securely is described. The network use keys, through path-key establishment and a key pool bootstrapping, to ensure that packets are transmitted and received properly and secretly in the presence of one or more adversarial nodes.