Derived unique key per hash encapsulated encrypted transaction (DUKPHEET)
The arrangements disclosed herein relate to generating, by a first server, a first seed using a Hash-Based Message Authentication Code (HMAC) based at least in part on a Hash Key (HK), providing, by the first server to each of a first device and a second device, the first seed, providing, by a second server to each of the first device or the second device, a second seed. The second seed is based at least in part on a stream of photons. Each of the first device or the second device generates a Derived Key (DK) based at least in part on the first seed and the second seed. Each of the first device or the second device generates a first key based at least in part on the DK and a first random number generated by a Quantum Random Number Generator (QRNG). The first device encrypts first data using the first key to obtain first ciphertext and provides the first ciphertext to the second device. The second device derives the first key and decrypts the first ciphertext using the first key.
1 . A method, comprising:
generating, by a first server, a first seed using a Hash-Based Message Authentication Code (HMAC) based at least in part on a Hash Key (HK);
providing, by the first server to each of a first device and a second device, the first seed;
providing, by a second server to each of the first device or the second device, a second seed, wherein the second seed is based at least in part on a stream of photons, wherein
each of the first device or the second device generates a Derived Key (DK) based at least in part on the first seed and the second seed, each of the first device or the second device generates a first key based at least in part on the DK and a first random number generated by a Quantum Random Number Generator (QRNG), the first device encrypts first data using the first key to obtain first ciphertext and provides the first ciphertext to the second device, and the second device derives the first key and decrypts the first ciphertext using the first key;
generating, by the first server, a Master Key (MK);
generating, by the first server, the HK;
encrypting, by the first server, the HK with the MK to obtain an encrypted key; and
providing, by the first server to each of the first device or the second device, the encrypted key;
destroying, by the first server, the HK; and
retaining, by the first server, the MK.
2 . The method of claim 1 , further comprising:
receiving, by the first server from the first device, a first encrypted key, the first encrypted key comprises the HK encrypted using a Master Key (MK); and
receiving, by the first server from the second device, a second encrypted key, the second encrypted key comprises the HK encrypted using the MK, the first encrypted key is the same as the second encrypted key.
3 . The method of claim 2 , further comprising at least one of:
decrypting, by the first server, the first encrypted key using the MK to obtain the HK; or decrypting, by the first server, the second encrypted key using the MK to obtain the HK.
4 . The method of claim 1 , wherein generating the first seed comprises applying as inputs to the HMAC the HK and an identifier of a domain of the first device and the second device, the HMAC outputs the first seed.
5 . The method of claim 1 , wherein the second server comprises a Quantum Key Distribution (QKD) service, the QKD service distributes the stream of photons to each of the first device or the second device, each of the first device or the second device measures the stream of photons to determine random key bits, and the first device or the second device resolve metrics to determine shared key bits corresponding to the second seed.
6 . The method of claim 1 , further comprising:
generating, by the first server, an identifier of a domain of the first device and the second device;
providing, by the first server to each of the first device or the second device, the identifier of the domain.
7 . A method, comprising:
receiving, by a first device from a first server, a first seed, wherein the first seed is generated using a Hash-Based Message Authentication Code (HMAC) based at least in part on a Hash Key (HK);
receiving, by the first device from a second server, a second seed, wherein the second seed is based at least in part on a stream of photons;
generating, by the first device, a Derived Key (DK) based at least in part on the first seed and the second seed;
generating, by the first device, a first key based at least in part on the DK and a first random number generated by a Quantum Random Number Generator (QRNG);
encrypting, by the first device, first data using the first key to obtain first ciphertext; and
providing, by the first device to the second device, the first ciphertext, wherein the second device derives the first key and decrypts the first ciphertext using the first key, wherein
generating the DK comprises applying as inputs to a Key Derivation Function (KDF) the first seed and the second seed, the KDF outputs the DK, and generating the first key comprises applying as inputs to a Pseudo Random Function (PRF) the DK and a first random number, the PRF outputs the first key.
8 . The method of claim 7 , further comprising:
reading, by the first device, a first encrypted key from a database of the first device, wherein the first encrypted key comprises the HK encrypted using a Master Key (MK); and
providing, by the first device to the first server, the first encrypted key.
9 . The method of claim 7 , wherein the first seed is generated by applying as inputs to the HMAC the HK and an identifier of a domain of the first device and the second device, the HMAC outputs the first seed.
10 . The method of claim 7 , wherein the second server comprises a Quantum Key Distribution (QKD) service, the QKD service distributes the stream of photons to the first device, the first device measures the stream of photons to determine random key bits, and the first device resolves metrics with the second device to determine shared key bits corresponding to the second seed.
11 . The method of claim 7 , further comprising:
generating, by the first device, a second key based at least in part on the DK and a second random number generated by the QRNG;
encrypting, by the first device, second data using the second key to obtain second ciphertext; and
providing, by the first device to the second device, the second ciphertext, wherein the second device derives the second key and decrypts the second ciphertext using the second key.
12 . A method, comprising:
receiving, by a second device from a first server, a first seed, wherein the first seed is generated using a Hash-Based Message Authentication Code (HMAC) based at least in part on a Hash Key (HK);
receiving, by the second device from a second server, a second seed, wherein the second seed is based at least in part on a stream of photons;
generating, by the second device, a Derived Key (DK) based at least in part on the first seed and the second seed;
receiving, by the second device from the first device, a first ciphertext and a first random number, the first random number is generated by a Quantum Random Number Generator (QRNG);
generating, by the second device, a first key based at least in part on the DK and the first random number;
decrypting, by the second device, the first ciphertext using the first key to obtain first data, wherein generating the DK comprises applying as inputs to a Key Derivation Function (KDF) the first seed and the second seed, the KDF outputs the DK, and generating the first key comprises applying as inputs to a Pseudo Random Function (PRF) the DK and a first random number, the PRF outputs the first key.
13 . The method of claim 12 , further comprising:
reading, by the second device, a second encrypted key from a database of the second device, wherein the second encrypted key comprises the HK encrypted using a Master Key (MK); and
providing, by the second device to the first server, the second encrypted key.
14 . The method of claim 12 , further comprising:
receiving, by the second device from the first device, a second ciphertext and a second random number, the second random number is generated by the QRNG;
generating, by the second device, a second key based at least in part on the DK and the second random number;
decrypting, by the second device, the second ciphertext using the second key to obtain second data.