Derived unique key attribute-based translations (dukat)
The arrangements disclosed herein relate to receiving, by a key management node, a first encrypted message element which is encrypted using a first symmetric key established between the key management node and a first node, decrypting, by the key management node, the first encrypted message element using the first symmetric key to obtain a first message element of a message, encrypting, by the key management node, the first message element using a second symmetric key established between the key management node and a second node to obtain a second encrypted message element, and sending, by the key management node, the second encrypted message element.
1 . A method, comprising:
receiving, by a key management node from a second node, a first encrypted message element, wherein the first encrypted message element is encrypted using a first symmetric key established between the key management node and a first node;
decrypting, by the key management node, the first encrypted message element using the first symmetric key to obtain a first message element of a message;
encrypting, by the key management node, the first message element using a second symmetric key established between the key management node and a second node to obtain a second encrypted message element; and
sending, by the key management node to the second node, the second encrypted message element, wherein the second node decrypts the second encrypted message element to obtain the first message element.
2 . The method of claim 1 , wherein
the first symmetric key comprises a Derived Unique Key (DUK) derived by the key management node and the first node using a Derived Unique Key Per Transaction (DUKPT) protocol, and the second symmetric key comprises a DUK derived by the key management node and the second node using the DUKPT protocol;
the first symmetric key comprises a Derived Unique Key (DUK) derived by the key management node and the first node using a Unique Key Per Transaction (UKPT) protocol, and the second symmetric key comprises a DUK derived by the key management node and the second node using the UKPT protocol; or
the first symmetric key comprises a key derived by the key management node and the first node using a distributed Quantum Key Distribution (dQKD) protocol, and the second symmetric key comprises a key derived by the key management node and the second node using the dQKD protocol.
3 . The method of claim 1 , further comprising:
determining, by the key management node, the first symmetric key using an identifier of the first node and a first counter; and
determining, by the key management node, the second symmetric key using an identifier of the second node and a second counter.
4 . The method of claim 1 , further comprising:
determining, base at least in part of an attribute of the first node, that the first node is authorized access the first message element, and in response to determining that authorized access the first encrypted message element, at least one of decrypting the first encrypted message element, encrypting the first message element, or sending the second encrypted message element.
5 . The method of claim 1 , wherein the second node receives a first encrypted message from the first node, the first encrypted message comprises the first encrypted message element.
6 . The method of claim 1 , wherein the second node sends a second encrypted message to a third node, the second encrypted message comprises the second encrypted message element.
7 . The method of claim 1 , further comprising:
receiving, by the key management node from the second node, a third encrypted message element, wherein the third encrypted message element is encrypted using a third symmetric key established between the key management node and a third node;
decrypting, by the key management node, the third encrypted message element using the third symmetric key to obtain a second message element of the message;
encrypting, by the key management node, the second message element using a fourth symmetric key established between the key management node and the second node to obtain a fourth encrypted message element; and
sending, by the key management node to the second node, the fourth encrypted message element, wherein the second node decrypts the fourth encrypted message element to obtain the second message element.
8 . The method of claim 7 , wherein the second node receives a first encrypted message from the first node, the first encrypted message comprises the first encrypted message element and the third encrypted message element.
9 . The method of claim 7 , wherein the second node sends a second encrypted message to a third node, the second encrypted message comprises the second encrypted message element and the fourth encrypted message element.
10 . A system, comprising at least one processor configured to:
receive a first encrypted message element from a second node, wherein the first encrypted message element is encrypted using a first symmetric key established between the key management node and a first node;
decrypt the first encrypted message element using the first symmetric key to obtain a first message element of a message;
encrypt the first message element using a second symmetric key established between the key management node and a second node to obtain a second encrypted message element; and
send the second encrypted message element to the second node, wherein the second node decrypts the second encrypted message element to obtain the first message element.
11 . The system of claim 10 , wherein the one or more processors are to:
determine the first symmetric key using an identifier of the first node and a first counter; and
determine the second symmetric key using an identifier of the second node and a second counter.
12 . At least one non-transitory processor-readable medium comprising processor-readable instructions, such that, when executed, causes at least one processor to:
receive a first encrypted message element from a second node, wherein the first encrypted message element is encrypted using a first symmetric key established between the key management node and a first node;
decrypt the first encrypted message element using the first symmetric key to obtain a first message element of a message;
encrypt the first message element using a second symmetric key established between the key management node and a second node to obtain a second encrypted message element; and
send the second encrypted message element to the second node, wherein the second node decrypts the second encrypted message element to obtain the first message element.
13 . The non-transitory processor-readable medium of claim 12 , wherein
the first symmetric key comprises a Derived Unique Key (DUK) derived by the key management node and the first node using a Derived Unique Key Per Transaction (DUKPT) protocol, and the second symmetric key comprises a DUK derived by the key management node and the second node using the DUKPT protocol;
the first symmetric key comprises a Derived Unique Key (DUK) derived by the key management node and the first node using a Unique Key Per Transaction (UKPT) protocol, and the second symmetric key comprises a DUK derived by the key management node and the second node using the UKPT protocol; or
the first symmetric key comprises a key derived by the key management node and the first node using a distributed Quantum Key Distribution (dQKD) protocol, and the second symmetric key comprises a key derived by the key management node and the second node using the dQKD protocol.