A key management system with key recovery

The key management system addresses the balance between security and availability by using computing servers and multi-party computation to generate cryptographic keys on demand, ensuring secure and rapid key generation without storing decryption keys, thus enhancing both security and availability.

WO2026115155A1PCT designated stage Publication Date: 2026-06-04PARTISIA INFRASTRUCTURE APS

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
PARTISIA INFRASTRUCTURE APS
Filing Date
2025-11-28
Publication Date
2026-06-04

Smart Images

  • Figure EP2025084784_04062026_PF_FP_ABST
    Figure EP2025084784_04062026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention presents a key management system for handling cryptographic keys. The key management system comprises a computer device. The key management system is configured to be in data communication with at least one identity provider, IdP, server and at least one group of computing servers. The IdP servers is configured to send an authentication token to the key management system upon an authentication request from the key management system. The key management system is configured to generate an access ID related to said IdP servers. The key management system is configured to perform one or both of following: a) generate an encryption key from said access ID, b) send a decryption request to the group of computing servers, wherein the group of computing servers is configured to generate a decryption key and sending the decryption key or shares of the decryption key to the computer device or a selected device different from the computer device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] A key management system with key recovery.

[0002] Field of invention

[0003] The present invention relates to a key management system, for generating, distributing, and managing cryptographic keys for devices and applications in a secure manner.

[0004] Background of the invention

[0005] Secrets, such as encryption keys, API credentials, and passwords, are commonly securely stored on computers or servers, such as secure storage solutions like encrypted databases etc. The secret information are preferably encrypted when being in transit or in rest when stored. In an ideal system these secure storage solutions ensure that the secret is only available for the intended people, such that the secrets remain confidential while allowing authorized access when needed. But as it is well known, the ideal system does not exist.

[0006] For example; US 2020 / 034550 Al discloses a system for improving data privacy using blockchain and MPC to secure a data transfer from an loT device and, if preferred, a data recipient. The data privacy is provided using a blockchain to generate and send a symmetric key to the MPC and the loT device. The MPC is used for distributing the symmetric key to a data recipient, such that the data is securely distributed via the MPC process to a selected data recipient.

[0007] WO 2019 / 143849 Al discloses a system that communicates with a customer device and a trusted third party for using or restoring a customer wallet. The system verifies the identity data for the customer received from the customer device. A network interface communicates a request for a first key associated with the customer wallet to a key repository for the trusted third party. The system restore the customer wallet using the first key associated with the customer wallet and a second key associated with the customer wallet. The system restores the costumer wallet based on stored information in the customer wallet.

[0008] US 2022 / 166616 Al discloses a method and a system to generate a plurality of keys based on and encryption key and convert the plurality of keys into a plurality of key shares based on a secret input value. The encrypted private key is stored on a blockchain, and a network interface distributes the plurality of key shares to a plurality of blockchain peers of the blockchain. The system transmits a different key share from among the plurality of key shares to each blockchain peer among the plurality of blockchain peers. The user may recover a private key and reconstruct the encrypted key by requesting key shares from a plurality of blockchain peers.

[0009] There is an essential balance between security and availability when managing secret information. Security and availability affects each other in opposite directions. When maximizing security, the secret information may become more inaccessible to unauthorized users, but the availability for the user will become more complicated, and in worst case inaccessible. Maximizing availability, on the other hand, the secret information risks getting compromised, i.e., the secret information becomes available to the wrong people.

[0010] A key management system refers to a management system handling cryptographic keys. The key management system protect keys and metadata that the key management system supports. Key management systems are designed to securely manage keys throughout their lifecycle, including generation, distribution, and destruction. The key management follows a lifecycle of operations, which are needed to ensure the key is created, stored, used, and rotated securely. The key should only be used by authorized users, to make certain the key is not misused, copied, etc. When the key is used to encrypt data, the key must then be stored for later decryption. KMS ensures that keys remain confidential and accessible only to authorized users.

[0011] One problem related to secret keys handled by a key management system is that the key must be stored and rotated in a secure manner to ensure safety. A further problem, which may be mentioned, is that as long as the key is stored in a memory storage unit, there will always be a risk that security fails, and also allowing attackers to access the keys stored therein.

[0012] Summary of the invention

[0013] It is an object of the present invention to overcome these problems by providing an agile key management system and a method, which increases both availability and security, such that a secret information is handled in a secure manner.

[0014] The present invention addresses this by providing a key management system for handling cryptographic keys, wherein said key management system comprises a computer device, wherein the key management system is configured to be in data communication with at least one identity provider, IdP, server and at least one group of computing servers, wherein said IdP server is configured to send at least an authentication token to said key management system upon an authentication request from said key management system, wherein said key management system is configured to generate an access identifier, access ID, based on said authentication token related to said IdP server, wherein said key management system is configured to perform one or both of following: a) generate an encryption key from at least said access ID, b) send a decryption request to said group of distributed computing servers, wherein said group of computing servers is configured to generate a decryption key from on said access ID and sending said decryption key or shares of said decryption key to said computer device or a selected device different from said computer device.

[0015] A key management system may be a critical part of data security and encryption. The key management system may provide a protection of sensitive data, such as keys, certificates, and operational secret information. The key management system provides a system for handling cryptographic keys, e.g., generating, distributing, and managing cryptographic keys for devices and applications. The key management system may generate cryptographic keys when the keys are requested. The key management system does not need to store decryption keys. Because the key management system does not need to store the decryption keys, the key management system increases both availability and safety, such that a secret information may be handled in a more agile and secure manner.

[0016] The complexity of a key generating algorithm may increase, when increasing a key’s security level. The security of a key generating algorithm may be increased by using a group or groups of computing servers to run the key management system.

[0017] The key management system may comprise at least one identity provider server, IdP server. The key management system may for example be configured to be in data communication with at least one identity provider, IdP, located on an identity provider server, IdP server. Each of the IdPs on the IdP servers are configured to send at least an authentication token to said key management system upon an authentication request from said key management system. Each of the IdPs on the IdP servers may send further IdP information to key management system, e.g. identification related to the IdP etc. The key management system is configured to generate an access identifier, access ID, based on respective authentication token related to one or more IdPs on at least one IdP server.

[0018] It shall be understood that the term IdP server related to a server, which is configured to run an IdP protocol and the IdP server is configured to comprise IdP information related to the IdP. The server may handle a plurality of IdP’ s comprising different IdPs having different IdP information. The server is configured to provide an authentication token for one or more of the respective IdPs. When referring to the IdP server and the IdP information related to the IdP server, it shall be understood, that the information is related to the respective IdP on the server, and not necessary the server information as such.

[0019] The key management system provides for example an encryption key or a decryption key in a secure and rapid manner, when requested by a user. The user uses the decryption key when decrypting encrypted secret information, which has been encrypted using the encryption key. Since the decryption key is not stored, the decryption key may be generated at another time than the encryption key. Alternatively, the decryption key may differ from the encryption key provided by the key generating algorithm, which is used for the purpose of generating the keys.

[0020] The key managing system may be deployed anywhere, such on a device or in an external server solution. The key managing system provides a simple and intuitive solution for generating, managing, and orchestrating encryption and decryption keys. The term orchestration should be understood as a coordinated execution of multiple tasks or processes. An orchestration may be applied across multiple computer systems, applications, and services to ensure that deployment, configuration management, and / or other processes are performed in the proper sequence. Orchestration coordinates automated tasks, for example across multiple systems, into a workflow, so that each individual task or tasks can work together to serve a specific function or process. The key management system may comprise a computer device, which may be handled by a user via a user interface. The key management system or part of the key management system may run as an application on the computer device. The key management system or part of the key management system may run on an external server. For example, as a cloud solution or similar. The key management system may be in data communication with at least one computer device. The computer device may comprise a user interface. The key management system may be in data communication with at least one electronic device other than a computer device. The key management system is in data communication with one or a plurality of identity provider servers, referred to IdP servers in the following description. The IdPs, which are running on the IdP server, may ensure a valid verification of the user based on unique user information like usernames, passwords, phone number, user access codes etc. Different authentication protocols may be used for this purpose. For example, OpenlD or W3C-VCs or similar. The authentication protocol provided on the IdP server, which relates to a selected IdP provides the user with an authentication token upon a respective request from the user, using a computer device, when the user wishes to use a decryption key.

[0021] The authentication token received from the IdPs are unique tokens. Each of the authentication token serves as proof of authentication and confirms that a user is successfully authenticated. Each authentication token is unique and related to the user and may be unique to the authentication event requested by the user. The authentication token may comprise information about the user’s identity and authentication status. The authentication token may comprise one or more information, such as identifier for the IdP, intended audience of the token, associated data and / or subject information, user information, nonce information, expiration time etc.

[0022] The computer device may be in data communication with at least one group of computing servers, which may be a data communication with the computer device and each other directly or indirectly. The key management system may comprise at least one group of computing servers. The computing server may be configured to act as a node. The IdP server, also if more than one, may be configured to send an authentication token to the computer device upon a request from the user using the computer device. The IdP server, also if more than one, may be configured to send an authentication token to the key management system upon a request from the user using the computer device. The key management system may be configured to generate an access identifier, access ID, based on the IdP or IdPs the user has selected. The key management system may generate an access identifier, access ID, based on the information received from the IdP or IdPs, e.g. at least the respective authentication tokens. The key management system may concatenate all the access ID related to each of the IdP servers in a single set of access ID. For example; the information related to the IdPs may be listed as IdP1. . . IdPN, and the authentication tokens T1. . ,TN, and the specific user information, such as username or other user related information may be listed as U1... UN, such that the key management system may generate the access ID identifier as one of following:

[0023] - access ID = (T1, ...,TN);

[0024] - access ID = (T1, U1, . . . ,TN, UN);

[0025] - access ID = (IdP1, U1, . . . , IdPN, UN);

[0026] Other information may be added, or constellation may be used, to ensure a reliable access ID.

[0027] The key management system may generate, upon a request from the user, an encryption key using the information in the access ID and if preferred other information to ensure a high security level. The key management system may perform the task of generating the encryption key on the computer device. The key management system may perform the task of generating the encryption key even if the computer device is off-line, e.g., not connected to the internet, or to a specific server, or not connected to part of the key management system.

[0028] The key management system may send a decryption request, upon a request from the user, for a decryption key to one or more servers. The decryption request may comprise an access ID. The decryption request may comprise other information, if provided. The key management system may send information related to the encrypted key, and if preferred information related to the access ID, and if provided other information to ensure a high security level and to ensure that the decryption key may be generated correctly. The key management system may comprise a selected group of computing servers. The key management system may send a decryption request to a selected group of computing servers. The group of computing servers may generate a decryption key according to the information received in the decryption request. The selected group of computing servers may send the decryption key or a plurality of shares of the decryption key to the key management system, e.g. the computer device. Alternatively, the selected group of computing servers may send the decryption key or a plurality of shares of the decryption key to a selected device. A further alternative, the selected group of computing servers may send the decryption key or a plurality of shares of the decryption key to the selected device different from the computer device.

[0029] The group of computing servers may be a group of distributed computing servers. The distributed computing servers may be a part of a distributed computing system. The distributed computing system may be a part of the key management system. The distributed computing system may be a computing system, wherein multiple computing servers and computer devices work together to perform complex tasks. One or more of the servers in the group of computing servers may be geographically separated.

[0030] In an advantageous embodiment of the invention, said key management system or the user device is configured to select an access policy, and said access policy or an encrypted access policy is comprised in said access ID.

[0031] An access policy may relate to the validity of the information in the access ID. The key management system may for example generate the access ID as one of following: access ID = (T1, . . . ,TN, access policy); access ID = (T1, U1, . . . ,TN, UN, access policy); access ID = (IdP1, U1, . . . , IdPN, UN, access policy);

[0032] The key management system may use the access policy to control and manage who can access and perform operations on decryption keys. The access policy may be related to or identified as an access policy ID, which may be used instead of the access policy in the access ID. When writing the term access policy, the term may also refer to the use of an access policy ID. The access policy ID or an encrypted access policy ID may be comprised in said access ID. The access policy may be a selected access policy. The selected access policy may be provided or chosen by a user or be provided as a default setting in the key managements system. Other solution for setting up and selecting an access policy may be provided. The access policy may ensure that only authorized users may receive the decryption key and thereby protect sensitive information. In a further advantageous embodiment of the invention, at least one of said group of computing servers is configured to verify the validity of each of said authentication token based on the respective access policy.

[0033] The key management system may comprise at least one group of computing servers, which verifies the validity of each of said authentication token based on the respective access policy. When running the access policy, the access policy may provide an output, which is either “accept” or “reject”, referring to the validity of the authentication token. The result verifies whether or not the user may be accepted or rejected. The verification may allow, when accepted, the group of computing servers to generate the decryption key. The access policy may for example define how many of the authentication must be accepted or rejected before all of the total result is accepted. If two authentication tokens are provided, one of the authentication tokens may authenticate the user, wherein the other may fail due to an authentication token error. If the access policy defines that one authentication of the user is acceptable the decryption request will be accepted. The group of computing servers may send the decryption key or shares of the decryption key to the computer device or to the selected device different from the computer device, if such is chosen.

[0034] In a still further advantageous embodiment of the invention, at least one of said group of computing servers is a group of MPC computing servers configured to run a multi-party computation, MPC.

[0035] The key management system may comprise at least one group of MPC computing servers, which is configured to run a multi-party computation, MPC. Each of the MPC servers may be configured to act as a MPC node. MPC may be a useful and secure cryptographic protocol that may distribute a computation across a plurality of computing servers, where no individual computing server can see the other computing server’s data. Each server in the group of MPC computing servers may be configured to run an MPC protocol. The group of MPC computing servers may be configured to compute a decryption key, wherein each server may compute a share of the decryption key. The MPC may handle the computation process of providing the decryption key in a secure and private environment with high accuracy and precision. MPC may decrease the dependency on third-party service providers by keeping the data and computations safe inside the group of MPC computing servers. The group of MPC computing servers may securely communicate with the key management system, and the decryption key may be secretly shared through a secure communication channel.

[0036] In a further advantageous embodiment of the invention, said group of MPC computing servers is configured to execute a secret-sharing scheme in conjunction with said MPC.

[0037] The group of MPC computing servers may secretly share the MPC data between the servers according to a secret-sharing scheme. The MPC data may be shared secretly through a blockchain data communication, preferably using a secure channel. Alternatively, the MPC data may be shared secretly directly between the servers in the group of MPC computing servers. The decryption key may be shared secretly from the group of MPC computing servers directly to the computer device or to another selected device, preferably using a secure channel. The decryption key may be shared secretly from the group of MPC computing servers through a blockchain data communication, preferably using a secure channel.

[0038] In a still further advantageous embodiment of the invention, said group of computing servers is configured to execute an identity based encryption, IBE, scheme, such that said group of computing servers is capable of generating the encryption key or the decryption key according to the IBE scheme.

[0039] The group of computing servers may be configured to run an MPC according to an identity based encryption, IBE, scheme. The IBE scheme is a public-key cryptographic scheme that allows key management system to derive a public encryption key from an access ID. For example, to derive an encryption key knowing only the email address of the user. The IBE schemes may easily run efficiently in a group of MPC computing servers. The group of computing servers may be configured to execute the IBE scheme, such that the group of computing servers may be capable of generating the encryption key or the decryption key according to the IBE scheme. It should be understood that MPC may be related to the use of an MPC protocol.

[0040] In a further advantageous embodiment of the invention, said key management system is configured to deploy a smart contract in a group of BC computing servers configured to run a blockchain. The key management system may comprise a BC server or at least one group of BC computing servers, which is configured to run a blockchain protocol. The BC server or each of the group of servers may be configured to act as a blockchain node. The blockchain or blockchains may be handled by a BC server or a group of BC computing servers. The BC server or the group of BC computing servers is / are configured to run the blockchain or blockchains in time-ordered sequential order. The BC server or the group of BC computing servers may be configured to run a smart contract protocol in a blockchain. The key management system may deploy a decryption request as a smart contract in the BC server or the group of BC computing servers. The smart contract may be executed on a blockchain according to a selected protocol, when predetermined conditions have been met and verified. The smart contract may comprise information related to the access ID, and where to send the decrypted key when the decryption key may be generated by the group of MPC computing servers. The blockchain may orchestrate the group of MPC computing servers according to a protocol related to MPC. The blockchain may orchestrate the group of MPC computing servers according to the information in the smart contract.

[0041] A further aspect of the invention is presented by a computer device in a key management system is configured to at least handle cryptographic keys. The computer device in may be configurated to use the key management system to handle cryptographic keys, wherein the computer device comprises a processing unit and a communication unit, wherein the computer device is configured to run said key management system or part of said key management system, wherein the key management system is configured to be in data communication with at least one identity provider, IdP, server and said at least one group of computing servers, wherein said IdP server is configured to send an authentication token to said key management system upon a respective authentication request from said key management system, wherein said key management system is configured to generate a access identifier, access ID, related to said authentication token, and wherein said key management system is configured to perform one or both of following: a) generate an encryption key from said access ID, b) send a decryption request to a group of computing servers, wherein said group of computing servers is configured to generate a decryption key and send said decryption key or shares of said decryption key to said computer device or a selected device different from said computer device.

[0042] The computer device may be in data communication with a plurality of IdP servers. The computer device may be in data communication with a group of computing servers configured to run a MPC protocol. The computer device may be in data communication with a group of computing servers configured to run a blockchain protocol. The computer device may run other applications using the IdP, which is running on the IdP servers for authentication. The computer device may be in data communication with an external server system. The external server system may comprise a cloud solution or similar. The computer device may be in data communication with an external key management system server. The key management system may be in data communication with a selected device different from the computer device.

[0043] In an advantageous embodiment of the invention, said computer device is configured to run the key management system or part of the key management system locally on the computer device, such that an encryption key is generated locally on the computer device.

[0044] The computer device is configured to run the key management system or part of the key management system locally on the computer device. The key management system may perform the task of generating the encryption key even if the computer device is off-line, not connected to the internet or similar, or to a specific server, or not connected to part of the key management system. The secret information may be encrypted and stored locally on the computer device.

[0045] A further aspect of the invention is presented by a MPC computing server in data communication with a key management system. The MPC computing server may be comprised in a key management system. The MPC computing server may be in data communication within a key management system. MPC computing server comprising one or more processing units and at least one data communication unit, wherein said MPC computing server is comprised in a group of MPC computing servers configured to run a multi-party computation, MPC, when a key management system sends a decryption request to said group of computing servers, wherein the MPC computing server is configured to generate a share of a decryption key and sending said shares of said decryption key to a computer device or a selected device different from said computer device. It should be understood that the MPC may be related to an MPC, which is executed according to an MPC protocol.

[0046] An MPC computing server may comprise one or more processing units and at least one data communication unit. The MPC computing server may be comprised in a group of MPC computing servers, which may be configured to run a multi-party computation, MPC. The key management system may send a decryption request to the group of MPC computing servers. The MPC computing server may be configured to generate a share of a decryption key. The MPC computing server may be configured to send the share of the decryption key to a computer device or to a selected device different from the computer device. It should be understood that the MPC may be performed according to an MPC protocol.

[0047] A further aspect of the invention comprise a BC computing server in data communication with a key management system. The BC computing server may be comprised in a key management system. The BC computing server may be in data communication within a key management system. BC computing server comprising one or more processing units and at least one data communication unit, wherein said blockchain, BC, server is comprised in a group of BC computing servers configured to run a blockchain, wherein the blockchain is configured to one or more of the following:

[0048] - select a plurality of MPC computing servers for a group of MPC computing servers,

[0049] - orchestrate an MPC in said group of MPC computing servers, when a key management system deploys a decryption request in said group of BC computing servers, wherein the blockchain related to the BC computing server is configured to orchestrate said MPC using the group of MPC computing servers.

[0050] A group of computing servers may comprise a plurality of BC computing servers, which may be configured to store a copy of the blockchain on the server. The BC computing server may be comprised in a group of BC computing servers configured to run a blockchain protocol. The blockchain may be decentralised in a plurality of BC computing servers. It should be understood that the blockchain may be run according to a blockchain protocol. The blockchain may select and, if preferred, setting up, a plurality of MPC computing servers for the group of MPC computing servers. At least one of the BC computing servers may be configured to select reliable MPC computing servers or group of MPC computing servers. Each of the MPC computing server in the group of MPC computing servers may be required to fulfil one or more of the following requirements: each of the MPC computing servers may be placed in different geographical jurisdiction, each of the MPC computing servers comprise at least one predetermined property, each of the MPC computing servers has different ownership, each of the MPC computing servers has been registered on a blockchain’s list for at least a predetermined period of time, each of the MPC computing servers are separately registered with a completion point value.

[0051] The blockchain may orchestrate an MPC in a selected group of MPC computing servers. The blockchain may orchestrate an MPC based on a decryption request. The blockchain may be configured to orchestrate an MPC according to an identity based encryption, IBE, scheme. The key management system may deploy a decryption request in the blockchain. The group of BC computing servers may be configured run a smart contract in a blockchain. It should be understood that the smart contract may related to a smart contract which is run according to a smart contract protocol. The smart contract protocol may be predefined, such that the smart contract may be used by the key management system in the blockchain. Deploying a smart contract comprising decryption request in a blockchain, may increase the execution of the request in a safe and secure manner, without the use of a third party. The blockchain may be configured to orchestrate an MPC according to an identity based encryption, IBE, scheme. The decryption key or shares of the encryption key may be sent to the computer device or to a selected device, different from the computer device via a blockchain or shared secretly between the group of MPC computing servers and the devices through a secure communication channel.

[0052] A further aspect of the invention is presented by a method for handle cryptographic keys in a key management system, wherein said key management system comprises a computer device, wherein the key management system is configured to be in data communication with at least one identity provider, IdP, server and at least one group of computing servers, wherein said IdP server is configured to send an authentication token to said key management system upon an authentication request from said key management system, wherein said key management system is configured to generate an access identifier, access ID, related to each of said authentication tokens, wherein the method comprises following acts: selecting at least one identity provider, IdP, server, receiving an authentication token from each of the IdP server, generating an access ID based on said authentication tokens, performing one or both of following acts: a) generating said encryption key from said access ID, b) generating a decryption key by sending a decryption request to a group of computing servers, wherein said group of computing servers is generating said decryption key from said access ID and sending said decryption key to said computer device or a selected device different from said computer device.

[0053] The key management system may comprise at least one computer device. The computer device may be handled by at least one user. A user may access the computer device and require a secret information to be encrypted and stored. The key management system may be configured to be in data communication with at least one group of computing servers. The key management system may be configured to be in data communication with a plurality of IdP, servers, which may be chosen by a user. Each of the IdP servers are configured to send an authentication token related to the user to the key management system upon an authentication request from the key management system.

[0054] The user may for example select a first and a second IdP, the user wishes to use. The key management system may request authentication and may receive an authentication token from each of the first and second IdP from a server or servers. The key management system may generate an access ID, related to the authentication tokens on the computer device. Alternatively, the key management system may generate an access ID related to each of said authentication tokens on an external server. The user may wish to encrypt a secret information. The key management system may generate the encryption key and encrypt the secret information. The user creates a backup of the encrypted secret information by storing the encrypted secret information in an accessible memory storage unit, which may be accessed by the user, when the user requires access.

[0055] When the user wishes to decrypt the encrypted secret information, the user requests a decryption key from the key management system. The key management system may send a decryption request to a group of computing servers directly. Alternatively, the key management system may deploy the decryption request as a smart contract in a blockchain or as an input to a smart contract on a blockchain. A group of computing servers may generate the decryption key according to the decryption request. The group of computing servers may send the decryption key to the computer device or a selected device different from said computer device, such that the user may use the decryption key to decrypt the encrypted secret information. It is not necessary to store the decryption key. If the user wishes to require the use of the decryption key again, the user may request the key management system again, and the key management system may generate the decryption key again, based on the decryption request the key management system sends.

[0056] The key management system may comprise a computer device, at least one identity provider, IdP, server and at least one group of computing servers. The computer device may be configured to be in data communication with the at least one identity provider, IdP, server and the at least one group of computing servers. The IdP server is configured to send an authentication token to the computer device upon an authentication request from the computer device. The computer device is configured to generate an access identifier, access ID, related to the authentication token. The computer device is configured to perform one or both of following: a) generate an encryption key from said access ID, b) send a decryption request to said group of computing servers, wherein the group of computing servers is configured to generate a decryption key and sending said decryption key or shares of said decryption key to said computer device or a selected device different from the computer device.

[0057] The computer device may control, alternatively execute, the method for handle cryptographic keys in data communication with a key management system, wherein the computer device may be the key manage system or part of a key management system.

[0058] In an advantageous method acts of the invention, said access ID comprises a IdP information, wherein said IdP information comprises information related to each of the identity provider server.

[0059] The access ID may also comprise IdP information, wherein the IdP information may be related to each of the identity provider server the user has chosen. For example, the user selects the IdP on an IdP server to authenticate the user. The authenticate token or information related to the authenticate token may be comprised in the access ID. An access policy may also be included in the access ID. The IdP information may be validated by the information comprised in the access policy.

[0060] In a further advantageous method acts of the invention, the method comprises further acts: encrypting said secret information using an encryption key, generating an additional identifier based on a computation information related to said group of computing servers, generating an additional encryption key, encrypting an additional information or part of the additional information using said additional encryption key, storing the encrypted secret information and said encrypted additional information in an accessible memory storage unit.

[0061] The user may encrypt the secret information using the encryption key, the user has requested from the key management system. The user may wish to store the encrypted secret information in a memory storage unit. An additional identifier may be generated. The additional identifier may be based on computation information. The computation information may be related to a selected group of computing servers. The selected group of computing servers may for example be a group of MPC computing servers. An additional encryption key may be generated from the additional identifier. An additional encryption key may be generated from other information if preferred. The additional key may be used for encryption an additional information or part of the additional information. The encrypted secret information and the encrypted additional information may be stored in an accessible memory storage unit. The user may choose where to store the encrypted secret information and the encrypted additional information together or separately, e.g., one the same location or in separate locations.

[0062] In a still further advantageous method acts of the invention, the method comprises further acts: sending said authentication tokens, and said encrypted additional information to said group of computing servers, decrypting said encrypted additional information using said group of computing servers, generating a decryption key based on said additional information, sending said decryption key to said computer device or a selected device different from said computer device.

[0063] The key management system may send the authentication tokens, and the encrypted additional information to a group of computing servers, when requesting a decryption key. The group of computing servers may decrypt the encrypted additional information. The group of computing servers may then generate a decryption key based on the additional information. When the group of computing servers may have generated a decryption key or a plurality of shares of the decryption key. The group of computing servers may then send the decryption key or a plurality of shares of the decryption key to the computer device or a selected device different from the computer device.

[0064] This invention has now been explained with reference to a few embodiments and methods, which have only been discussed to illustrate the many varying possibilities achievable with the key management system and method according to the present invention.

[0065] Brief description of the drawings

[0066] The embodiments of the invention are described in the following with reference to:

[0067] Fig. 1 : Illustrating a first embodiment of a key manage system.

[0068] Fig. 2: Illustrating a second embodiment of a key manage system.

[0069] Fig. 3 : Showing a first flow diagram of a method related to a key management system. Fig. 4: Showing a second flow diagram of a method related to a key management system.

[0070] Fig. 5: Showing a flow diagram of a key management system requesting a decryption key, using a smart contract in a blockchain, capable of orchestrating a group of MPC servers.

[0071] In the explanations of the figures, identical or corresponding elements will be provided with the same designations in different figures. Therefore, no explanation of all details will be given in connection which each single figure / embodiment.

[0072] Detailed description

[0073] Embodiments of the invention are explained in the following detailed description. It is to be understood that the invention is not limited in its scope to the following description or illustrated in the drawings. The invention is capable of other embodiments and of being practiced or carried out in various ways.

[0074] Fig. 1 illustrates a first embodiment of a key management system 1. The key management system 1 may comprise a computer device 2, and if preferred, a group of computing servers 6. The computer device 2 is in data communication with a plurality of IdP servers, 4,5, which can authenticate a user 3 if requested.

[0075] The user 3 uses the computer device 2 to access the key management system 1. A key management system 1 may run locally on the computer device 2 or in a cloud solution, or on both locations partially. The user 3 may create a backup of a secret information using an encryption key. The user may choose to generate the encryption key locally on the computer device 2. The computer device 2 is in data communication with two IdP servers, 4,5 chosen by the user 3. A unique access identifier, access ID, is generated such that the access ID is related to IdP information for and preferably from the respective IdPs located on each IdP server 4,5. The access ID may furthermore comprise one or more following user related information, such as username, email address and other selected identifiers. The user 3 may choose more than two IdPs, if preferred. An access policy may be selected, wherein the access policy may be included information related to the approval of the IdP information and user information in the access ID. The computer device 2 may generate the access ID, when requested. The access ID may have a sequential data structure, which comprise each of the authentication tokens or information related to or comprised in the authentication tokens. The access ID may for example be a string of concatenated information. Alternatively, other type of data structure may also be selected. The user may also choose an access policy, AP. The access policy AP may be related to the selected IdP’s on the IdP servers 4,5. The access policy AP may also be comprised as information in the access ID.

[0076] The computer device 2 may generate an encryption key using the access ID. The computer device 2 may encrypt a secret information using the encryption key. The computer device 2 may generate an encrypted access policy AP, which may be used for generating a decryption key at a later stage. Alternatively, other information or additional information may be encrypted. The user 3 may choose to store the secret information in a memory storage unit. The secret information may be stored, with further encrypted information other that than the secret information. The memory storage unit may be located on the computer device 2, or on an external server, e.g., cloud solution or similar.

[0077] When the user 3 wishes to recover the secret information, the user selects one or more IdP servers 4,5, which each can authenticate the user 3. Each of the IdP servers 4,5 sends an authentication token T',T2related to the IdPs requested by the user to the computer device 2. The computer device 2 is in direct data communication with a group of computing servers 6. The group of computing servers 6 any be a group of MPC computing servers configured to run an MPC protocol. The group of MPC computing servers may be comprised in the key management system 1. The key management system 1 may perform a setup procedure of the group of MPC computing servers before the user is capable of creating backups and perform recoveries. The key management system 1 may perform a setup procedure to ensure a secure communication channel is available, and to provide a reliable MPC performance. The MPC computing servers in the group of MPC computing servers comprises one or more processing units and at least one data communication unit. The group of MPC computing servers may be configured to run a multi-party computation, MPC, when the key management system 1 sends a decryption request to the group of MPC computing servers 6. Each of the MPC computing server may be configured to generate a share of a decryption key and sending the shares of the decryption key to the computer device 2.

[0078] The data communication between computer device 2 and the group of computing servers 6 may be a secure data communication. The computer device 2 sends a decryption request to the group of computing servers 6. The decryption request may be encrypted. The decryption request may comprise an access ID comprising relevant authentication tokens T',T2, user related information and, if selected, access policy. The group of computing servers 6 may decrypt the decryption request. The group of computing servers 6 may verify the validity of each of the authentication tokens T T2related to the user based on the access policy. If at least one of those authentication tokens T',T2is valid, the group of computing servers 6 may generate a decryption key and send the decryption key to the computer device 2. The secret information may then be decrypted using the decryption key.

[0079] Fig. 2 illustrates a second embodiment of a key management system. The key management system 1 may comprise a computer device 2 and a group of computing servers 6. The group of computing servers 6 may be a group of MPC computing servers 6J,62,63capable of running multi-party computation, MPC, protocol. The group of MPC computing servers 6J,62,63may execute MPC according to a secret-sharing scheme. The group of MPC computing servers 6J,62,63may execute an identity based encryption, IBE, scheme, such that the group of MPC computing servers 6J,62,63generates an encryption key or a decryption key according to the IBE scheme provided.

[0080] A blockchain, BC, group of servers 7 may run a blockchain protocol. A smart contract may be deployed and executed on a blockchain. The group of BC computing servers 7 may orchestrate the MPC according to the smart contract order. The computer device 2 may deploy a decryption request as a smart contract in the blockchain operated by the group of BC computing servers 7. The group of BC computing servers 7 is capable of orchestrating the MPC. The group of BC computing servers 7 may orchestrating the MPC via a smart contract or by other means, which may be deployed by the key management system upon request from the computer device 2.

[0081] The user 3 may have stored an encrypted secret information in a memory storage unit. The memory storage unit may be located in the computer device 2, or on an external server, not showed in fig. 2. When the user 3 wishes to recover the secret information, the user 3 uses the computer device 2. The computer device 2 is in data communication with a plurality of IdP servers 4,5, which can authenticate the user 3. The user may select two IdP servers 4,5. Each of the IdP servers sends an authentication token T T2to the computer device 2. The computer device 2 may indirectly be in data communication with the group of MPC computing servers 6J,62,63via a group of BC computing servers 7. The data communication between computer device 2 and the group of BC computing servers 7 may be a secure communication. The computer device 2 may send a decryption request by deploying a smart contract in the blockchain. The decryption request may comprise an access ID. The decryption request may be comprised in the smart contract. The group of BC computing servers 7 orchestrating the MPC based on the information in the smart contract deployed by a computer device 2.

[0082] The group of MPC computing servers 6J,62,63may decrypt the decryption request. The group of MPC computing servers 61,62,63may verify the validity of each of the authentication tokens T T2based on the access policy, which was comprised in the ID identifier. If at least one of those authentication tokens T1,T2is valid, the group of MPC computing servers 6J,62,63generates a decryption key or shares of the decryption key, and sends the decryption key or shares of the decryption key to the computer device 2 through a secure connection D1. Alternatively, the group of MPC computing servers 6J,62,63sends the decryption key or shares of the decryption key to a selected device 8 through a secure connection D2. The selected device 8 may be different from the computer device 2. The user selects which device may be selected. The secret information may then be retrieved from the memory storage unit and decrypted using the decryption key, such that the secret information is available for the user.

[0083] Fig. 3 shows a first flow diagram of a method related to a key management system. The key management system is configured to provide an encryption key and a decryption key. The user chooses which key the key management system shall provide and when. A plurality of IdPs, which may run on one or more of the IdP servers 4,5, are available for the user, wherein the user may request authentication. The computer device 2 selects two or more IdPs for authentication purpose. One example of providing an encryption key a) or a decryption key b) is described below:

[0084] A key management system 1 may be running on a computer device 2 locally. Each of the selected IdP servers 4,5 may send an authentication token T',T2to the requesting computer device 2 upon respective requests R1, R2from the requesting computer device 2. The key management system 1 receives the authentication tokens T T2from each of the selected IdP servers 4,5. a) If the user wishes to encrypt and store a secret information:

[0085] The computer device 2 generates an encryption key from the access ID. The computer device 2 uses the encryption key to encrypt the secret information. The encrypted secret information may then be stored in an accessible memory storage unit. The access policy, if selected, may be encrypted using the additional encryption key. The encrypted access policy may be stored with the encrypted secret information, linked together, on accessible memory storage unit. b) If the user wishes to decrypt a secret information:

[0086] The computer device 2 generates a decryption request and sends the decryption request to a group of computing servers 6. The decryption request may comprise the authentication tokens. The group of computing servers 6 generates the decryption key according to the decryption request receive from the computer device 2. The group of computing servers 6 sends the decryption key or shares of the decryption key to the computer device 2, or to a selected device 8 different from the computer device 2. The user 3, using the computer device 2, may then decrypt the encrypted secret information using the decryption key.

[0087] Fig. 4 shows a second flow diagram of a method related to a key management system. Another example is following a key management system 1 may be running on a computer device 2 locally. The key management has set up the group of MPC computing servers 6. Each of the selected IdPs on the IdP servers 4,5 may send an authentication token T',T2to the requesting computer device 2 upon respective authentication requests R1, R2from the requesting computer device 2. The key management system 1 receives the authentication tokens T',T2from each of the selected IdPs on the IdP servers 4,5. The key management system 1 or the computer device 2 selects an access policy. The key management system 1 generates an access ID based on the authentication tokens T T2received and, if preferred, other information as well, such as access policy, IdP information, user related information etc. a) If the user wishes to encrypt a secret information:

[0088] An encryption key may be generated using an access ID. The secret information may be encrypted using the encryption key. An additional identifier, additional ID, has been created, e.g., based on the information related to the group of MPC computing servers 6. An additional encryption key may be created. The additional encryption key may be based on the additional ID. The access policy may be encrypted using the additional encryption key. The encrypted secret information and the encrypted access policy may be linked to each other when stored. The encrypted secret information and the encrypted access policy may be retrieved as a pair when the user wishes to decrypt the secret information. b) If the user wishes to decrypt a secret information:

[0089] The computer device 2 generates a decryption request and sends the decryption request to a group of computing servers 6. Alternatively, the computer device 2 may deploy a smart contract in a blockchain, wherein the smart contract comprise the decryption request. The decryption request may comprise an access ID provided with the authentication tokens and an access policy. The decryption request may alternatively comprise an access ID provided with authentication tokens and an encrypted access policy. The encrypted access policy may be decrypted by the group of computing servers. The access ID may be validated by the group of computing servers, such that a verification of the information or at least some of the information in the access ID is validated and the user 3 is accepted. The group of computing servers 6 may generate the decryption key according to the decryption request. The group of computing servers 6 sends the decryption key or shares of the decryption key to the computer device 2, or to a selected device 8 different from the computer device 2. The user 3, using the computer device 2, may then decrypt the encrypted secret information using the decryption key.

[0090] Fig. 5 shows a flow diagram of a key management system requesting a decryption key using a smart contract in a blockchain capable of orchestrating a group of MPC servers. The key management system may prepare a decryption request for a decryption key. The key management system may generate an access ID. The key management system generates a smart contract, wherein the smart contact may comprise information related the access ID, if provided an access policy and selected authentication tokens, and if further provided other information, the smart contract may be deployed in a blockchain. The blockchain is configured to orchestrate an MPC in a, preferable selected, group of MPC computing servers. When the access ID is validated, the group of MPC computing servers may start generating the decryption key. If the access ID is not validated, the group of MPC computing servers will not start generating a decryption key. The blockchain for orchestrating an MPC protocol based on the information in a smart contract deployed in the blockchain. The group of MPC computing servers may be configured to run an IBE scheme. The group of MPC computing servers may generate the decryption key or a plurality of shares of the decryption key. The decryption key may be generated according to the IBE scheme available. The decryption key or a plurality of shares of the decryption key may be sent directly to the computer device. Alternatively, decryption key or a plurality of shares of the decryption key may be sent via the block chain to the computer device.

Claims

25PATENT CLAIMS1. A key management system for handling cryptographic keys, wherein said key management system (1) comprises a computer device (2), wherein the key management system (1) is configured to be in data communication with at least one identity provider, IdP, server (4,5, IdPh.IdP1) and at least one group of computing servers (6), wherein said IdP server (4,5, IdPh.IdP1) is configured to send at least an authentication token (T' ..T ) to said key management system (1) upon an authentication request (R1, R2) from said key management system (1), wherein said key management system (1) is configured to generate an access identifier, access ID, based on said authentication token(T1TN), wherein said key management system (1) is configured to perform one or both of following: a) generate an encryption key from said access ID, b) send a decryption request to said group of computing servers (6), wherein said group of computing servers (6) is configured to generate a decryption key from said access ID and sending said decryption key or shares of said decryption key to said computer device (2) or a selected device (8) different from said computer device (2).

2. The key management system according to claim 1, wherein on or both of said key management system (1) or the user device (2) are configured to select an access policy, and wherein said access policy or an encrypted access policy is comprised in said access ID.

3. The key management system according to claim 2, wherein at least one of said group of computing servers (6) is configured to verify the validity of each of said authentication token based on the respective access policy.

4. The key management system according to claim 1, 2 or 3, wherein at least one of said group of computing servers (6) is a group of MPC computing servers (6) configured to run a multi-party computation, MPC.

5. The key management system according to claim 4, wherein said group of MPC computing servers (6) is configured to execute a secret-sharing scheme in conjunction with said MPC.

6. The key management system according to any one of the preceding claims, wherein said group of computing servers (6) is configured to execute an identity based encryption, IBE, scheme, such that said group of computation servers (6) is capable of generating the encryption key or the decryption key according to the IBE scheme.

7. The key management system according to any one of the preceding claims, wherein said key management system (1) is configured to deploy a smart contract in a group of BC computing servers (7) configured to run a blockchain.

8. A computer device in a key management system is configured to at least handle cryptographic keys, wherein the computer device (2) comprises a processing unit and a communication unit, wherein the computer device (2) is configured to run said key management system (1) or part of said key management system (1), wherein the key management system (1) is configured to be in data communication with at least one identity provider, IdP, server (4,5) and said at least one group of computing servers (6), wherein said IdP server (4,5) is configured to send an authentication token (T T2) to said key management system (1) upon a respective authentication request (R1, R2) from said key management system (1), wherein said key management system (1) is configured to generate a access identifier, access ID, related to said authentication token (T T2), andwherein said key management system (1) is configured to perform one or both of following: a) generate an encryption key from said access ID, b) send a decryption request to a group of computing servers (6), wherein said group of computing servers (6) is configured to generate a decryption key and send said decryption key or shares of said decryption key to said computer device (2) or a selected device (8) different from said computer device (2).

9. A computer device according to claim 8, wherein said computer device (2) configured to run the key management system (1) or part of the key management (1) system locally on the computer device (2), such that an encryption key is generated locally on the computer device (2).

10. An MPC computing server in data communication with a key management system comprises one or more processing units and at least one data communication unit, wherein said MPC computing server (6J,62,63) is comprised in a group of MPC computing servers (6) configured to run a multiparty computation, MPC, when a key management system (1) sends a decryption request to said group of computing servers (6), wherein the MPC computing server (6 62,63) is configured to generate a share of a decryption key and sending said share of said decryption key to a computer device (2) or a selected device (8) different from said computer device (2).

11. A BC computing server in data communication with a key management system comprises one or more processing units and at least one data communication unit, wherein said blockchain, BC, server is comprised in a group of BC computing servers (7) configured to run a blockchain, wherein said blockchain is configured to handle one or more of the following:- select a plurality of MPC computing servers for a group of MPC computing servers (6),- orchestrate a MPC in said group of MPC computing servers (6),28 when a key management system (1) deploys a decryption request in said blockchain, wherein the blockchain related to the BC computing server is configured to orchestrate said MPC using the group of MPC computing servers (6).

12. A method for handle cryptographic keys in a key management system (1), wherein said key management system (1) comprises a computer device (2), wherein the key management system (1) is configured to be in data communication with at least one identity provider, IdP, server (4,5) and at least one group of computing servers (6), wherein said IdP server (4,5) is configured to send an authentication token (T1,T2) to said key management system (1) upon an authentication request (Rl, R2) from said key management system (1), wherein said key management system (1) is configured to generate a access identifier, access ID, related to said authentication token (T1,T2), wherein the method comprises following acts: selecting the at least one IdP server (4,5), receiving an authentication token (T1,T2) from each of the at least one IdP server (4,5), generating an access ID based on said authentication token (T1,T2), performing one or both of following acts: a) generating an encryption key from at least said access ID, b) generating a decryption key by sending a decryption request to said group of computing servers (6), wherein said group of computing servers(6) is generating said decryption key from said access ID and sending said decryption key to said computer device (2) or a selected device (8) different from said computer device (2).

13. The method according to claim 12, wherein said access ID comprises an IdP information, wherein said IdP information comprises information related to the IdP server (4,5).2914. The method according to claim 12 or 13, wherein the method comprises further acts: encrypting said secret information using said encryption key, generating an additional identifier based on a computation information related to said group of computing servers, generating an additional encryption key, encrypting an additional information or part of the additional information using said additional encryption key, storing the encrypted secret information and said encrypted additional information in an accessible memory storage unit.

15. The method according to claim 14, wherein the method comprises further acts: sending said authentication token (T’,T2), and said encrypted additional information to said group of computing servers (6), decrypting said encrypted additional information using said group of computing servers (6), generating said decryption key based on said additional information, sending said decryption key to said computer device (2) or a selected device (8) different from said computer device (2).