Organizations rely on key distribution to exchange and protect highly sensitive data. But legacy key management processes can be error-prone, expensive to manage – and breakable. Distributed Symmetric Key Establishment (DSKE) is a modern key distribution technology. It fully automates the creation and distribution of symmetric keys, without relying on computational complexity or asymmetric encryption. DSKE is the industry’s first scalable symmetric key technology, combining the scalability of PKI, the security of quantum key distribution (QKD) and the simplicity of pre-shared keys.
DSKE is the industry’s first key distribution technology that delivers future-proofed security at scale without the use of any asymmetric cryptography.
Each security hub generates data for each DSKE client. Activation data include high quality random numbers, also called pre-shared random data (PSRD)
A DSKE client can request a key with any other DSKE client over IP networks via the security hubs. Key requests include information about the DSKE client destination and other metadata.
Key requests are encrypted and authenticated using PSRD.
Security Servers forward the key instructions to the DSKE Client destination.
The DSKE Client destination is the only one that can rebuild the key as its the only one in possession of the PSRD required for reconstruction.
The two DSKE Clients now share the same key, which can be used in any symmetric cryptographic algorithm.
The key is not known in the security hubs, thanks to the secrete sharing algorithm used to build the key.
DSKE relies on pre-shared random numbers between DSKE clients and a group of Security Hubs. Any group of DSKE clients can use the DSKE protocol to distill from the pre-shared numbers a secret key. The clients are protected from Security Hub compromise via a secret sharing scheme that allows the creation of the final key without the need to trust individual Security Hubs. Read our DSKE White Paper and Security Proof.