Out-of-Band Encryption Key Exchange via Audio Tones

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing short-range wireless communication technologies like Bluetooth and UWB face security vulnerabilities due to the derivation of encryption keys on the same channel they are intended to protect, making them susceptible to attacks, especially when devices share the same pre-set PIN/passkey, and users are reluctant to enter longer, more secure codes.

Innovation Solution

Implementing an out-of-band encryption key exchange using alternate data transfer mechanisms such as audio tones or embedded images displayed on devices, leveraging existing hardware like speakers, microphones, and cameras to transmit and validate stronger encryption keys without requiring additional hardware, allowing for longer and more secure keys to be used.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption keys are derived on the same communication channel, then the key exchange process is simple, but the security is compromised because vulnerable devices can derive the same key

Engineering Contradiction:
ImprovesecurityVSAvoidkey exchange process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary out-of-band channel (separate from the vulnerable communication channel) to exchange encryption keys. This mediator channel allows devices to securely share keys without relying on the potentially compromised primary communication path, thereby improving security while maintaining a relatively simple implementation by leveraging existing alternative transmission paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transitions from a single-dimensional key exchange (over the communication channel alone) to a multi-dimensional approach by utilizing an additional out-of-band channel. This dimensional shift allows keys to be exchanged through a separate path, preventing attackers who compromise one channel from automatically deriving the encryption keys.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If longer PIN/passkey codes are used, then the security strength increases, but user convenience decreases as users are reluctant to enter lengthy codes

Engineering Contradiction:
Improvesecurity strengthVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical manual entry process with automated key exchange mechanisms. Instead of requiring users to physically type long PINs, the system uses automated out-of-band channel transmission to exchange cryptographic keys, thereby maintaining high security strength while eliminating the inconvenience of manual entry for lengthy codes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs self-service by automatically generating and exchanging encryption keys without requiring user intervention for entering long codes. The devices autonomously handle the complex key exchange process through the out-of-band channel, freeing users from the burden of memorizing and typing lengthy PINs while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8688986B2Method for exchanging strong encryption keys between devices using alternate input methods in wireless personal area networks (WPAN)
Publication Date: 2014.04.01 INTEL CORP
  • US8688986B2 patent drawing
  • US8688986B2 patent drawing
  • US8688986B2 patent drawing

AI summary

A method for exchanging strong encryption keys between devices using alternate input methods. At least two devices that want to communicate with one another are set in key exchange mode. The at least two devices are to communicate with one another using a short range radio or personal area network. The at least two devices negotiate with one another to determine which of the at least two devices will generate an encryption key, wherein device A represents the negotiated device and device B represents the non-negotiated device. Device A generates the encryption key and transmits the encryption key to device B using an out-of band transmission channel. The out-of-band transmission channel may be transmitting the encryption key via audio tones. A validation process determines whether the transmission of the encryption key via the out-of-band transmission channel was successful. If the encryption key has been successfully validated, the at least two devices are enabled to automatically accept communications between them over the short range radio or personal area network.