Providing random numbers over an insecure channel using disguised cyphertexts
Methods, systems, apparatuses, and computer program products for providing random numbers over an insecure channel using disguised cyphertexts are disclosed. A secure access portal application receives a first cyphertext from a key deliver center (KDC), decrypts the first cyphertext using paired keys shared between the first SAP application and the KDC to obtain a transformed second cyphertext, de-transforms the transformed second cyphertext using a transformation function based on the paired keys to obtain a second cyphertext, decrypts the second cyphertext using the paired keys to obtain first a random number generated by the KDC, and generates a delivery key based at least on the first random number. The SAP application may use the delivery key to securely receive a symmetric key from the KDC, and securely communicate with another secure access portal application using the symmetric key.
1 . A system comprising:
a processor; and
a memory device that stores program structured to cause the processor to:
receive, by a first secure access portal (SAP) application, a first cyphertext from a key deliver center (KDC);
decrypt, by the first SAP application, the first cyphertext using paired keys shared between the first SAP application and the KDC to obtain a transformed second cyphertext;
de-transform, by the first SAP application, the transformed second cyphertext using a transformation function based on the paired keys to obtain a second cyphertext;
decrypt, by the first SAP application, the second cyphertext using the paired keys to obtain first a random number generated by the KDC; and
generate, by the first SAP application, a delivery key based at least on the first random number.
2 . The system of claim 1 , wherein the program code is structured to further cause the processor to:
receive, by the first SAP application, a third cyphertext from the KDC;
decrypt, by the first SAP application, the third cyphertext using the delivery key to obtain a symmetric key;
encrypt, by the first SAP application, a message using the symmetric key to obtain an encrypted message; and
transmit, by the first SAP application, the encrypted message to a second SAP application.
3 . The system of claim 1 , wherein the program code is structured to further cause the processor to:
receive, by the first SAP application, a third cyphertext from the KDC;
decrypt, by the first SAP application, the third cyphertext using the delivery key to obtain a symmetric key;
receive, by the first SAP application, a cyphertext message from a second SAP application; and
decrypt, by the first SAP application, the cyphertext message using the symmetric key to obtain a cleartext message.
4 . The system of claim 1 , wherein, to generate the delivery key, the program code is structured to further cause the processor to:
perform an exclusive-or (XOR) operation on the first random number and a second random number generated by the KDC.
5 . The system of claim 1 , wherein the paired keys comprise at least one of:
pre-paired keys;
a paired encryption key;
a paired initiation vector nonce; or
an input for the transformation function.
6 . The system of claim 1 , wherein the transformation function comprises at least one of:
a bit rotation function where the number of bits rotated are based on the paired keys;
a block shuffle function where the number of bits shuffled are based on the paired keys;
a square shuffle function where the number of bits shuffled are based on the paired keys; or
a cube shuffle function where the number of bits shuffled are based on the paired keys.
7 . The system of claim 1 , wherein, to receive the first cyphertext from the KDC, the program code is structured to cause the processor to:
receive the first cyphertext from the KDC over an insecure channel subject to eavesdropping.
8 . A method comprising:
receiving, by a first secure access portal (SAP) application, a first cyphertext from a key deliver center (KDC);
decrypting, by the first SAP application, the first cyphertext using paired keys shared between the first SAP application and the KDC to obtain a transformed second cyphertext;
de-transforming, by the first SAP application, the transformed second cyphertext using a transformation function based on the paired keys to obtain a second cyphertext;
decrypting, by the first SAP application, the second cyphertext using the paired keys to obtain first a random number generated by the KDC; and
generating, by the first SAP application, a symmetric key based at least on the first random number.
9 . The method of claim 8 , further comprising:
encrypting, by the first SAP application, a message using the symmetric key to obtain an encrypted message; and
transmitting, by the first SAP application, the encrypted message to a second SAP application.
10 . The method of claim 8 , further comprising:
receiving, by the first SAP application, a cyphertext message from a second SAP application; and
decrypting, by the first SAP application, the cyphertext message using the symmetric key to obtain a cleartext message.
11 . The method of claim 8 , wherein said generating, by the first SAP application, a symmetric key comprises:
performing an exclusive-or (XOR) operation on the first random number and a second random number generated by the KDC.
12 . The method of claim 8 , wherein the paired keys comprise at least one of:
pre-paired keys;
a paired encryption key;
a paired initiation vector nonce; or
an input for the transformation function.
13 . The method of claim 8 , wherein the transformation function comprises at least one of:
a bit rotation function where the number of bits rotated are based on the paired keys;
a block shuffle function where the number of bits shuffled are based on the paired keys;
a square shuffle function where the number of bits shuffled are based on the paired keys; or
a cube shuffle function where the number of bits shuffled are based on the paired keys.
14 . The method of claim 8 , wherein said receiving, by a first secure access portal (SAP) application, a first cyphertext from a key deliver center (KDC) comprises:
receiving the first cyphertext from the KDC over an insecure channel subject to eavesdropping.
15 . A computer-readable storage medium comprising program instructions that, when executed by a processor, cause the processor to:
receive, by a first secure access portal (SAP) application, a first cyphertext from a key deliver center (KDC);
decrypt, by the first SAP application, the first cyphertext using paired keys shared between the first SAP application and the KDC to obtain a transformed second cyphertext;
de-transform, by the first SAP application, the transformed second cyphertext using a transformation function based on the paired keys to obtain a second cyphertext;
decrypt, by the first SAP application, the second cyphertext using the paired keys to obtain first a random number generated by the KDC; and
generate, by the first SAP application, a delivery key based at least on the first random number.
16 . The computer-readable storage medium of claim 15 , wherein the program instructions, when executed by the processor, further cause the processor to:
receive, by the first SAP application, a third cyphertext from the KDC;
decrypt, by the first SAP application, the third cyphertext using the delivery key to obtain a symmetric key;
encrypt, by the first SAP application, a message using the symmetric key to obtain an encrypted message; and
transmit, by the first SAP application, the encrypted message to a second SAP application.
17 . The computer-readable storage medium of claim 15 , wherein the program instructions, when executed by the processor, further cause the processor to:
receive, by the first SAP application, a third cyphertext from the KDC;
decrypt, by the first SAP application, the third cyphertext using the delivery key to obtain a symmetric key;
receive, by the first SAP application, a cyphertext message from a second SAP application; and
decrypt, by the first SAP application, the cyphertext message using the symmetric key to obtain a cleartext message.
18 . The computer-readable storage medium of claim 15 , wherein, to generate the delivery key, the program instructions, when executed by the processor, further cause the processor to:
perform an exclusive-or (XOR) operation on the first random number and a second random number generated by the KDC.
19 . The computer-readable storage medium of claim 15 , wherein the paired keys comprise at least one of:
pre-paired keys;
a paired encryption key;
a paired initiation vector nonce; or
an input for the transformation function.
20 . The computer-readable storage medium of claim 15 , wherein the transformation function comprises at least one of:
a bit rotation function where the number of bits rotated are based on the paired keys;
a block shuffle function where the number of bits shuffled are based on the paired keys;
a square shuffle function where the number of bits shuffled are based on the paired keys; or
a cube shuffle function where the number of bits shuffled are based on the paired keys.