Method and system for providing inputs to create a seed
Patent Information
- Application Number
- PCT/EP2025/054466
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2026-08-27
Smart Images

Figure EP2025054466_27082026_PF_FP_ABST
Abstract
Description
[0001] Title: Method and system for providing inputs to create a seed
[0002] Field of application
[0003] The present invention relates to a method for providing inputs to create a seed for cryptographic purpose.
[0004] The present invention also relates to a system for providing inputs to create a seed for cryptographic purpose.
[0005] Prior art
[0006] As known, a seed for cryptographic purpose is an initial value or a piece of random data used as input to generate cryptographic keys, pseudorandom numbers, or other cryptographic outputs. The seed is crucial because it provides the starting point for deterministic algorithms, such as a key derivation functions (KDFs), ensuring that their outputs can be reproducible if the same seed is used.
[0007] A key derivation function is a cryptographic algorithm for deriving one or more cryptographic keys from an input (the seed), such as a password, a passphrase or a master key. The purpose of the key derivation function is to take a less-secure or shorter piece of information (the input) and transform it into a cryptographic key which is suitable for secure operations, such as for encryption, authentication or digital signatures. The key derivation function may take in input also a salt, i.e. a random value added to the other inputs to ensure that the derived cryptographic key is unique, even if the input is reused. The salt is useful to weaken attacks, such as those precomputed (for instance based on rainbow tables) or brute-force attacks.
[0008] The input (seed) of the key derivation function (password, passphrase, master key, salt, etc) are also referred to by the term entropy. Entropy is also used in the context of key derivation function to indicate a measure of unpredictability or randomness of the inputs, and in this case is also expressed in bits, to quantify how unpredictable or non-redundant theinput to the key cryptographic function is; a high-entropy input makes it difficult for an attacker to deduct or brute-force the input.
[0009] Entropy plays a critical role in ensuring the security and strength of the derived cryptographic key. The security of the key derivation function is directly tied to the entropy of the input. Indeed, the key derivation function cannot add entropy to its input but only preserve and transform the existing entropy into the derived cryptographic key(s) .
[0010] Passwords and passphrases as a source of entropy, if human-generated, are not particularly strong because they tend to be predictable (e.g., common words, patterns or reuse).
[0011] Random Inputs, such as cryptographically secure random inputs, for instance generated by hardware or software RNGs (Random Number Generators), have much higher entropy.
[0012] However, RNGs require a software or hardware for producing the random inputs and such software and hardware are not so practical to use and not always at hand, whereas providing entropy as a password is more practical for the user, since it does not require software or any hardware. On the other hand, the user may forget the password or passphrase, with the result that the input to the key derivation function can no longer be provided.
[0013] The problem at the base of the present invention is that of devising a method and a system for providing a seed (input) for cryptographic purpose, for instance for a key derivation function, which in very practical in use but at the same time very safe and reproducible, overcoming the limitations that currently affects the prior art methods and systems. Summary of the invention
[0014] The idea at the base of the present invention is that of generating a seed for cryptographic purpose based on a plurality of answers to a plurality of requests.The terms “answers” and “requests” has to be read broadly. “requests” include precise requests or questions to a user, for instance in written form and natural language, such as the request
[0015] “what is the name of your first school ’.
[0016] The “answer”, in this simple example, is the name of the first school of a user, such as “Alessandro Volta”, wherein the user is the human user who actually attended “Alessandro Volta” school as his / her first school, and who actually provides “Alessandro Volta” as “answer”, based on his / her personal memory.
[0017] However, “requests” encompass requests to the user of other kind (type) of inputs such as a fingerprint of the user; the user is still the human user but the “answer” is provided by the user in the form of an action, consisting in placing his / her finger on a sensor; the action is preferably intrinsically associated to the human user, more preferably univocally retrieved by his / her body.
[0018] On the other hand, “requests” include requests of inputs from a nonhuman user, such as an agent, script, program or device; in this case the answer in provided by the non-human user. For example, GPS coordinates may be enquired as a request and an agent, reading the GPS coordinates from a device (such as the smartphone) of the user, may provide the coordinate as an answer.
[0019] The seed may be correctly created only if the plurality of answers to the plurality of requests are all correct.
[0020] More particularly, it is requested that a same seed is provided each time an operation with cryptographic purpose has to be executed, for instance to derive a corresponding cryptographic key. The same seed is returned by the method as disclosed, only if the same answers to certain questions stored in the profile are given.
[0021] In the example above, for instance, the same and correct seed is createdeach time the answers to the mentioned requests
[0022] -“Alessandro Volta”,
[0023] -the fingerprint of the human user, and
[0024] -the GPS coordinates of the house of the user
[0025] are returned.
[0026] In case only one of the answers differs, for instance if the user is not at home, the seed cannot be correctly created. More particularly, another seed will be created in this case, and another cryptographic key, not suitable for the cryptographic purpose of the user associated to the profile.
[0027] According to the disclosure above, the requests may be all addressed to the human user, or al least in part to the agent, and the answers are provided, respectively, all by the human user, or at least in part by the agent, with the scope of generating a seed for the human user. In this case, the seed is used for cryptographic purpose for the human user and to univocally identify the human user.
[0028] However, according to another aspect of the invention, also the term “user” has not to be read in a limitative way, i.e. as the human user. The term “user” encompasses, for instance, the agent, such as a script, a program or an artificial intelligence agent, i.e. a computer agent including an artificial intelligence algorithm.
[0029] According to this aspect of the invention, all the requests are addressed to the agent, all the answers are provided by the agent and the seed, still used for cryptographic purpose, univocally identify the agent, not the human user.
[0030] Based on the solution idea given above, the technical problem is solved by a method for creating a seed for cryptographic purpose, including -a step of configuration of a profile, said profile including at least n requests of input (n >= 2), and said profile being stored in a memory;-a step of retrieving m inputs (m<=n), wherein said step of retrieving m inputs includes running a processor for:
[0031] • selecting m requests among the n requests in said profile,
[0032] • requesting m answers to the selected m requests,
[0033] taking m answers to said m requests as inputs to create the seed; wherein at least one of said m inputs is not stored.
[0034] The profile, when associated to a human user, serves the purpose of generating the seed for cryptographic operations to be attributed or assigned to the human user. In this case, requests and answers may be provided by the human user and / or by the agent. The cryptographic operation in this case may be “legally” associated to the human user associated to the profile.
[0035] The profile, on the other hand, when associated to the computer agent, serves the purpose of generating the seed for cryptographic operations to be attributed or assigned to the agent itself. The operation in this case may be “legally” associated to the agent associated to the profile.
[0036] In both cases (profile associated to the human user or agent), at least one answer to a corresponding at least one request among the m requests is not stored anywhere, i.e. it is not stored in any computer memory (hard disk, flash drive, RAM, ROM, register etc).
[0037] For instance, the profile of the user may include a request of information, set by the user, for which only the user knows the answer, since based on his own “biological” memory, such as:
[0038] “What feeling did you feel on the first day of school?”.
[0039] This question is set and stored in the profile of the human user by the human user him / herself.
[0040] However, the answer, which may be “disorientation”, is known only by the human user, since he remembers his sensation, and is not stored in any computer memory.The answer “disorientation” contributes to the generation of the seed along with, for instance, a second answer to a second question.
[0041] Just to cite a simple example, a second request among the m requests may be
[0042] “What is the IMEI of your device?” and the answer to this request is provided by the agent. In this case, the answer, i.e. the IMEI “BSGGLKJBD9834hf98er” is stored in the memory of the device.
[0043] The seed is generated by the two answers
[0044] “disorientation” and “BSGGLKJBD9834hf98er”.
[0045] The same answers “disorientation” and “BSGGLKJBD9834hf98er” allow to create the same seed (and therefore the same cryptographic key) each time they are returned to questions (requests). The term “questions” is also used as a synonym of “requests”.
[0046] In case these questions are posed to another human user, having another device, the corresponding answers differ.
[0047] First of all, the other human user may reply “happiness” to the question “What feeling did you feel on the first day of school?”, based on his personal memory, and the device of such another user has another IMEI, therefore returns a different answer.
[0048] The same idea above also applies for the profile associated to the computer agent.
[0049] For instance, the profile of the agent may include a request of information, set by the agent itself, for which only the agent knows the answer, since based on his own computing capability, and therefore does not require storage of the answer.
[0050] To cite an example, the question may be:
[0051] “What is the hash code of your favorite book?”.
[0052] This question is set and stored in the profile of the agent by the agentitself.
[0053] The answer can be provided only by the agent since only the agent knows what is its favorite book and therefore can calculate the hash code thereof.
[0054] The agent in particular includes an artificial intelligence algorithm which is properly trained based on training data sets. Once trained, the agent deterministically answers the same answer (for instance “Divina commedia”) to the same question (“What is the hash code of your favorite book?”) . Creation of the profile is made by the agent itself by formulating n requests and storing them as the agent profile.
[0055] The answer constituted by the hash of the book “Divina commedia” contributes to the generation of the seed along with, for instance, a second answer.
[0056] Just to cite a simple example, also in this case, a second request among the m requests may be
[0057] “What is the IMEI of the device where you (the agent) are running?” and the answer to this request is provided by the agent (“BSGGLKJBD9834hf98er”), as taken from the memory of the device. The seed is generated by the two answers “hash code” and “BSGGLKJBD9834hf98er”. The same answers “hash code” and “BSGGLKJBD9834hf98er” allows to create the same seed, each time they are provided, and therefore the same cryptographic key.
[0058] In case these questions are posed to another agent, the corresponding answers differ.
[0059] In particular, the other agent may reply, to the question
[0060] “What is the hash code of your favorite book?”.
[0061] the hash code of the book “At Swim-Two-Birds (1939) of Flann O’Brien” since, based on its training data set, this is the favorite book.In other words, different training (or different fine tunings) of different artificial intelligence algorithm allows to distinguish behaviors of the computer agents, and in some way to provide a “personal” identity to the agents, in the form of a capability to provide same answers to predefined questions, where said same answers are only known to the agent, since computed by the agent at run time, once the request is queried, and not stored in any memory (RAM, ROM, flash drive etc).
[0062] In abstract terms, the computing capability of the artificial intelligence algorithm simulate the biological memory of a human user in providing a same and personal answer each time a certain request is queried, wherein said same and personal answer differs from an artificial intelligence algorithm to another artificial intelligence algorithm in the same way in which a same and personal answer differs from a human user to another human user, even if the same request is queried.
[0063] Due to this principle, security of the seed generated for the human user or for the computer agent is improved by hiding the answers in the internal configuration of the artificial intelligence algorithm, in same way the personal memory or unique features of a human user may hide their answers. This analogy may be further appreciated below, at the end of the summary of the invention (see section “Comparison between Human and Al Agents Generated Factors”, where further details and examples for human users or non-human users are given).
[0064] In one embodiment non limiting the present invention, the presence or knowledge of the user or an action taken by the user is required for providing at least one of the m inputs to increase security.
[0065] The number n and m are configurable from the user.
[0066] The number n of requests in the profile is at least five.
[0067] In the step of selecting the m requests among the n requests, the selection of the m requests to be prompted is preferably random.
[0068] In an embodiment, also the order in which the requests are requested israndom.
[0069] In the step of requesting the selected m requests, one request at a time is preferably requested.
[0070] In one embodiment of the invention, the n requests include at least two among requests of:
[0071] -a password known to the user;
[0072] -a PIN known to the user;
[0073] -biometric data of the user,
[0074] - information known to the user;
[0075] -data dynamically generated in connection with the user.
[0076] In one embodiment of the invention, the n requests include at least two among requests of information that:
[0077] -the user knows,
[0078] -brings,
[0079] -the user has,
[0080] -produces.
[0081] The method further includes the step of deriving a cryptographic key, wherein the cryptographic key is not stored anywhere.
[0082] The cryptographic key may be a private key or a public key, depending on the application for which it has to be used.
[0083] The step of deriving the cryptographic key is repeated each time the cryptographic key is required by the user. Each time, the step of requiring the cryptographic key by the user includes running the processor to retrieve the m inputs.
[0084] In one embodiment of the invention, the cryptographic key is a private cryptographic key and the step of storing the profile in memory includes: -generating a master public key from the private cryptographic key of theuser; encrypting the master public key with the profile of the user, and storing them in memory; wherein
[0085] the step of encrypting the master public key with the profile is made using one of the m inputs as a factor for encrypting.
[0086] In an embodiment, each time the step of deriving the private cryptographic key is repeated, the master public key is verified by means of the following steps:
[0087] -deriving a new master public key from the private cryptographic key derived by repeating its derivation; -decrypting the master public key by decrypting it with the profile through said one of the m inputs; -comparing the master public key decrypted and the new master public key derived; -continuing using the private cryptographic key derived by repeating if the master public key decrypted corresponds to the new master public key derived.
[0088] The cryptographic key is used for instance for transaction in an electronic wallet. This is only an example of use, not limiting for the invention, since the cryptographic key may be used for several other purposes, to cite one, digital signature.
[0089] Based on the solution idea given above, the technical problem is also solved by a system for providing inputs for creating a seed for cryptographic purpose, the system including a memory and a processor, wherein
[0090] -the memory stores a profile, said profile including at least n requests of input (n >= 2);
[0091] the processor is configured to retrieve m inputs (m<=n) by:
[0092] • selecting m requests among the n requests in said profile,
[0093] • requesting m answers to said selected m requests,
[0094] • taking m answers to said m requests as inputs for creating the seed, whereinat least one of the m inputs are not stored in a computer memory.
[0095] Advantageously, the method and system as disclosed are very practical because they do not require RNGs software or hardware for producing the random inputs but, at the same time, prevent problems associated to the fact that the user may forget the (input) to be provided as a source for the key derivation function or associated to the fact that the input is too low, such when it is formed by a single and weak password. Advantageously, at least one of the answers according to the method of the present invention is inherently associated to the users, such as biological information associated to the user (fingerprint, face recognition, etc) or answers to precise questions set by the user himself, and a plurality (at least m) of inputs are returned to increase complexity of the seed.
[0096] A comparison between Human and Al Agents Generated Factors How humans and Al agents may generate ephemeral authentication factors is herein further explained.
[0097] “Factors” are the inputs.
[0098] Factors are used for authentication.
[0099] “Ephemeral” means “not stored permanently”
[0100] By focusing on dynamic, transient data (whether in human behavior or Al sensor outputs and internal states) the security benefits of non-stored factors in systems, where a key is reconstructed on demand without ever persisting in storage.
[0101] The term “signature” hereafter is used to refer to a unique mathematical representation of a “trait” or “combination of traits”. The traits, with reference to the description already provided, are the “questions” or “requests” (e.g. Typing Dynamics, Human Memories, Internal Neural Activation Patterns), or combinations thereof, and the signature can be seen as the “answer(s)” to said “questions” or “requests” (since theanswers are used to generate the seed).
[0102] An Overview of Non-Stored Factors is herein explained. Non-stored factors are elements used for authentication or identity verification that exist only transiently. Non-stored factors are taken, computed or measured at the time of need and discarded immediately after use. This characteristic reduces the risk of replay attacks and long-term data compromise. Both humans and Al agents can generate ephemeral factors. Humans rely on behavioral biometrics (e.g., typing dynamics, voice patterns, and decision-making processes) and cognitive inputs (e.g. passwords or PINs that are not written anywhere) that are captured in real time. Al Agents Utilize sensor-derived noise (e.g., clock jitter, thermal fluctuations) and dynamic internal states (e.g., neural network activations) computed on the fly.
[0103] A Description and Identity Extraction of Human Behavioral Factors is given below. Examples of Behavioral Biometrics and Cognitive and Behavioral Context are as follows.
[0104] Behavioral Biometrics
[0105] Humans exhibit unique behavioral traits that serve as dynamic markers of identity. These traits are measured live during an authentication session and are not stored as static data. Examples include:
[0106] - Typing Dynamics:
[0107] • Process: Measurement of typing speed, rhythm, keystroke durations, and inter-key intervals.
[0108] • Identity Generation: These patterns form a unique signature that differentiates one user from another. For further clarity, a patter is, for instance, a plurality x of intervals between x+1 keystrokes; the “question” here is to provide a pattern (of keystrokes); the answer is the pattern; the answer is given by the user by simply writing through the keyboard; the seed, and the corresponding signature, is created from the answer, i.e. from thekeystrokes.
[0109] • Ephemerality: The signature is computed during a(n authentication) session and then discarded, ensuring that even if the measurement process is observed, it cannot be replayed later.
[0110] - Voice Patterns:
[0111] • Process: Analysis of pitch, cadence, accent, and timbre through audio processing.
[0112] • Identity Generation: Subtle nuances in voice characteristics provide a robust, dynamic signature. For instance, here the “question” is to provide a timbre; the answer is the user voice input from which the timbre is extracted; the answer is given by the user by simply speaking; the seed, and the corresponding signature, is created from the answer, i.e. from the user timbre.
[0113] • Ephemerality: Like typing dynamics, the vocal signature is generated in real time without long-term storage.
[0114] - Gait and Movement:
[0115] • Process: Recording walking patterns and motion dynamics via sensors or video.
[0116] • Identity Generation: The unique manner in which a person moves contributes to their identity profile.
[0117] • Ephemerality: Measurements are live, ensuring that the data remains transient.
[0118] Cognitive and Behavioral Context
[0119] In addition to physical biometrics, humans exhibit cognitive behaviors — such as decision-making patterns and emotional responses — that are inherently ephemeral.
[0120] - Decision-Making Patterns:
[0121] Process: Capturing consistent choices or reactions in similar contexts.• Identity Generation: Over time, these patterns build a dynamic profile unique to the individual.
[0122] • Ephemerality: Such patterns are observed and used during the session without persisting beyond the moment of authentication.
[0123] - Human Memories
[0124] • Process: Capturing consistent sequence of key-presses (e.g. passwords, PINs, answers to predetermined security questions) • Identity Generation: Use the inserted sequence as identification
[0125] • Ephemerality: Key-presses are provided on demand and the output of those presses is never stored
[0126] Sensor-Derived and Internal States of Al Agent Factors is given below. As to Sensor-Derived Ephemeral Noise, Al agents can generate ephemeral factors analogous to human behavioral data by leveraging real-time sensor outputs. These include:
[0127] - Hardware-Generated Noise:
[0128] • Source: Clock jitter, memory access timing variations, and thermal noise inherent to hardware.
[0129] • Process: Algorithms capture these fluctuations in real time and process them (e.g., via cryptographic hash functions) to produce a transient numeric signature. For further clarity, a fluctuation is, for instance, a timing variation in reading a memory portion of a device; the “question” here is to provide a value for the timing variation; the answer is the timing variation; the answer is given by the Ai agent by measuring it when the memory portion is actually read; the seed, and the corresponding signature, is created from the answer measured.
[0130] • Ephemerality: The computed value exists only momentarilyand is discarded after contributing its share to key reconstruction.
[0131] - Environmental Sensor Data:
[0132] • Source: Ambient environmental readings from light sensors, temperature sensors, or electromagnetic interference.
[0133] • Process: Aggregated sensor data is normalized and processed to yield a high-entropy output.
[0134] • Ephemerality: As with hardware noise, this data is computed on demand and not stored permanently.
[0135] As to the Internal State Dynamics, beyond external sensors, Al agents also generate ephemeral factors from their own internal states:
[0136] - Internal Neural Activation Patterns:
[0137] • Source: Activation states within hidden layers of neural networks when processing a challenge (such as a timestamp or nonce) .
[0138] • Process: The internal computation yields a unique, sessionspecific signature based on the Al’s current operational state.
[0139] • Ephemerality: These dynamic activations are transient, existing only during the session and discarded immediately after key reconstruction.
[0140] Hereafter Comparison and Parallels are summarized.
[0141]
[0142] Key Analogies
[0143] - Transient Nature:
[0144] Both systems rely on momentary data that exists only during the authentication process. This transient nature is a cornerstone of their security, ensuring that sensitive data is not available for future exploitation.
[0145] - High Entropy Sources:
[0146] The dynamic characteristics of human behavior and Al sensor outputs provide high entropy, making them robust against forgery and replay attacks.
[0147] Key Differences
[0148] - Data Generation Source:Humans generate data through physiological and cognitive processes, whereas Al agents rely on hardware characteristics and computed internal states.
[0149] - Measurement Mechanism:
[0150] Human data is captured via behavioral biometric systems (e.g., voice recognition, keystroke analysis), while Al data is captured directly from sensors and internal computational states.
[0151] In view of the above, the process of generating non-stored, ephemeral factors for authentication reveals a fundamental similarity between human and Al agents: both rely on dynamic, transient data that exists only during the moment of use. Humans utilize behavioral biometrics along with cognitive cues to produce unique signatures that are never stored long-term. Similarly, Al agents harness real-time sensor noise and internal state activations to generate ephemeral signatures for secure operations.
[0152] Brief description of the enclosed drawings
[0153] Figure 1 is a diagram representing the main steps for setting a profile for a user.
[0154] Figure 2 is a diagram representing the main steps for retrieving input from a user.
[0155] Figure 3 is a diagram representing the main steps for using a cryptographic key derived from the key derivation function in the diagram of figure 2.
[0156] Detailed description of the invention
[0157] In the description an example of the method according to the present invention is given with reference to the enclosed drawing.
[0158] According to the idea of the present invention, inputs to create a seed for a cryptographic purpose are given in the form of answers to requests. Requests are set by the user and stored in a profile associated to the user.Hear after, the term “user” is used to mean a human user but, according to what already disclosed in the summary of the invention, a non-human user, such as a computer agent, may be involved in the method steps. In one embodiment, the profile of a user, and therefore the requests, are public and not protected.
[0159] Answers, instead, are not stored in the profile.
[0160] At least one answer is only known to the users or is part of the user, for instance his / her biometric features. In other words, at least one answer, preferably a plurality of answer, but not necessarily all the answers, are intrinsically associated to the user, meaning that a personal memory of the human user or his / her physical-biometrical characteristics or his / her behaviors or actions are required to provide an answer(s).
[0161] In one embodiment, all the answers are only known to the users or are part of the user.
[0162] On the other hand, according to another embodiment, at least one answer is not provided by users but, for instance, by an agent or script or program of device of the user (in short “agent”). Hereafter, some not limiting examples of requests / answers associated to an agent are given. The request may be the IMEI of the user’s device and the agent returns the IMEI number as an answer. The seed may be generated by means of a determinist algorithm based taking the IMEI and other inputs (provided by the user or agents).
[0163] The request may be the geographic location of the user’s device and the agent returns the geographic location, such as a 3D coordinates. The answer is considered correct and suitable to generate the seed, only if the geographic location is within a predetermined region. If the geographic location is outside the predetermined region, the seed cannot be (correctly) created. In an alternative embodiment, in case the geographic location is outside the predetermined region another request is prompted to the user; this approach aims to implement a form of adaptive security(the number of requests is adapted during execution of the method based on an incorrect).
[0164] The agent may be an artificially intelligence algorithm. With the expression “artificially intelligence algorithm” it is herein meant an agent associated to a knowledgebase or training data set.
[0165] In case the profile is the one of the user, the knowledgebase of the “artificially intelligence algorithm” is associated to the user. In other words, the answers to which the user might respond are answered by an Al agent trained on a dataset previously provided by the user. Just to cite an example, the dataset may be the mailbox of the user, preferably a mailbox existing since several years. The request may be in the form of an information in one or more email exchanged with an addressee of the email. For instance, the question may be in the form
[0166] “Does Paolo Rossi prefer fish or meat?”.
[0167] The answer is determined by the Al (artificial intelligence) agent, based on correspondence included in the email. In this case, the user prepares the request for the profile (“Does Paolo Rossi prefer fish or meat?) but he / she is not involved in the process of answering.
[0168] The request may be of course much more complex, just to cite another simple example in the form
[0169] “what is the favorite team of Paolo Rossi among the following: . ?” (where the list of teams in the request may be very long) .
[0170] Moreover, the request may be much more abstract such as in the form “which was the destination of summer holidays agreed with my wife for 1998”), and the answer is “Rome”.
[0171] The profile, i.e. the requests, are set by the user.
[0172] Fig. 1 is a diagram block indicative of a procedure for setting the profile of the user. Until a predetermined number n of requests is set, the user has to store a request to the profile.Any user may have a profile different from another user.
[0173] A request as set by a user may be unique to the user.
[0174] Preferably, an application, for smartphone or browser, includes an onboarding phase for the user. The onboarding phase allows to set a plurality of requests as the profile of the user.
[0175] The number of requests n stored in the profile is at least five but the number n is not limited by upper bounds.
[0176] The number of requests is set by the user.
[0177] For instance, a user A may set 8 requests in the profile: QA1, ..., QA8. A user B may set only 5 requests: QB1, ..., QB5.
[0178] Once the number of requests is set by the user, for instance 5 requests QB1, ..., QB5 by user B, the method as disclosed may request to provide answers. As said, at least one answer has to be provided by the user, since known only by the user (his / her memories) or available in presence thereof (biological data).
[0179] The answers provided are inputs for creating the seed.
[0180] A cryptographic key of the user may be created based on the seed.
[0181] The cryptographic key is never stored.
[0182] The cryptographic key is (re)generated each time the user needs it.
[0183] Also seed is never stored.
[0184] The seed is (re)generated each time the user needs it. The same seed is (re)generated only if same answers to same requests are provided. Each time the user needs the cryptographic key, he has to provide answers to the requests.
[0185] From one time to the other, the requests queried may differ.
[0186] An example is given, where the seed is used to derive a cryptographic key. The first time the user B requests the cryptographic key derivation,requests (QBi) of answers (ABi) are in the order
[0187] QB5, QB4, QBI, QB3, QB2.
[0188] The answers (ABi) will be AB5, AB4, ABI, AB3, AB2.
[0189] The second time the user B requests the cryptographic key derivation, requests (QBi) of answers (ABi) are in the order
[0190] QBI, QB5, QB2, QB3, QB4.
[0191] The answers will be ABI, AB5, AB2, AB3, AB4.1
[0192] The order of the requests may be randomly handled.
[0193] The method is configured to return the same seed independently from the order of the requests QBi and therefore from the order of answers ABi. In other words, if the seed is created by means of answers in the order ABI, AB5, AB2, AB3, AB4, the cryptographic key KI is derived.
[0194] The same cryptographic key KI is derived, if the seed is created by means of answers in the order AB5, AB4, ABI, AB3, AB2.
[0195] The answers provided the first time and the second time must however be corresponding. For example, the answer AB5 to question QB5, which is the first answer when the user is queried for the first time, must correspond to the answer AB5 to question QB5, which is the second answer when the user is queried for the second time.
[0196] In absence of correspondence, two different seeds are created and therefore also two different cryptographic keys: KI the first time and K2 the second time.
[0197] The cryptographic key is the correct one of the users only in case all the answers ABI, AB2, AB3, AB4, AB5 to all the requests QBI, QB2, QB3, QB4, QB5 are correct, independently from the order.
[0198] The number n of requests set in the profile is set by the user and is preferably not less than 5.
[0199] In the example provided above with reference to user B and n=5 requestsQB1, QB2, QB3, QB4, QB5, the number m of requests with which the user is prompted to provide an answer is also set to 5.
[0200] However, as schematically represented in figure 2, the number m may be less than number n.
[0201] For instance, user B may be prompted with m=3 requests although, in his profile n=5, requests QB1, QB2, QB3, QB4, QB5 are set.
[0202] Also, the number m of requests with which the user is prompted to provide an answer is set by the user and is preferably at least two.
[0203] This number m is also stored in the profile.
[0204] The higher is the number m of requests with which the user is prompted, the stronger is the seed (and the entropy) and the stronger is the security of the key derivation function and the corresponding cryptographic key. However, it is not complicate for the user to properly reply to the answers since they are inherently associated to his life or body or behavior, and since set by himself.
[0205] In case m<n, from one time to the other, the user may be prompted with different requests.
[0206] For instance, user B with profile including requests QB1, QB2, QB3, QB4, QB5 and m=2, may be prompted the first time with requests QB1, QB2 and the second time with requests QB3, QB5.
[0207] In case of correct answers AB1, AB2 for the first time and AB3, AB5 for the second time, the same seed and the same cryptographic key is generated, which is the key of the user.
[0208] Any one of said requests Qai, QBi may be a request of a password, PIN, biometric data of the user, information known to the user, data dynamically generated in connection with the user, information that the user knows, brings, the user has, produces. Data dynamically generated by the user may be derived, for instance, by gesture data, such as change of movement directions of a hand or finger.Advantageously, the answers may be taken through a device local to the user, for instance through a smartphone and an application running on it. The key derivation function may be processed by an algorithm remotely stored with respect to the application and smartphone, for instance on a remote server.
[0209] In an embodiment, also the profile is stored on a memory remotely located with respect to the application and smartphone, on the remote server or another remote server. In that case, the application communicates the entropy to the server(s) to and waits for the cryptographic key from the server(s).
[0210] In one embodiment, the method as disclosed also includes a step of deriving the cryptographic key. The cryptographic key is not stored anywhere.
[0211] The step of deriving the cryptographic key is repeated each time the cryptographic key is required by the user, and the step of requiring the cryptographic key by the user includes running the processor to retrieve the m inputs from the user.
[0212] In one embodiment of the invention, a private cryptographic key is generated and the step of storing the profile in memory includes:
[0213] -generating a master public key from the private cryptographic key of the user;
[0214] -encrypting the master public key with the profile of the user, and storing them in memory; wherein
[0215] the step of encrypting the master public key with the profile is made using one of the m inputs as a factor for encrypting.
[0216] Each time the step of deriving the private cryptographic key is repeated, the master public key is verified by:
[0217] -deriving a new master public key from the private cryptographic key derived by repeating its derivation;-decrypting the master public key by decrypting it with the profile through said one of the m inputs;
[0218] -comparing the master public key decrypted and the new master public key derived;
[0219] -continuing using the private cryptographic key derived by repeating if the master public key decrypted corresponds to the new master public key derived.
[0220] The private cryptographic key is used for transaction in an electronic wallet. Hereafter are given some advantages and details of the methods and system according to the disclosure.
[0221] The generation and management of secure cryptographic keys are paramount for ensuring data confidentiality, integrity, and authenticity (CIA). Prior art key generation methods rely on entropy sources within devices, such as noise from hardware sensors and user interactions (e.g., keyboard inputs) . These device-based entropy sources may produce non-reproducible keys, necessitating secure key management systems to handle key storage, distribution, and lifecycle management. Existing systems primarily focus on key management rather than innovative key derivation mechanisms. Moreover, they often lack the flexibility for users to generate consistent keys based on personal or object- specific entropy sources, limiting the adaptability and personalization of cryptographic solutions.
[0222] According to the present disclosure cryptographic keys are derived from user-supplied real-life entropy sources. Unlike prior art device-based entropy collection methods, the method as disclosed allows users to generate reproducible cryptographic keys by leveraging personal or object-associated data such as passwords, photos, videos, audio recordings, and unique identifiers of owned devices (e.g., UUIDs) or services (e.g. OAuth codes).
[0223] According to the method as disclosed:-Key Generation is reproducible. Users can consistently regenerate the same cryptographic key using the same set of entropy sources (answers to requests as set in the profile), eliminating the need for complex key management systems.
[0224] -Entropy Sources is versatile. The method accepts a wide range of entropy inputs (the answers may be alphanumeric, biometric data, or other data typed), including but not limited to personal memories, physical objects, and digital media.
[0225] -The method is customizable. Users are enabled to use a combination of entropy factors for key regeneration (i.e. only answers to some requests as set in the profile) . This flexibility ensures key derivation is achievable even if some factors are forgotten or lost, while allowing the addition or removal of factors (requests / answers) without altering the cryptographic key or the user’s identity.
[0226] -Dynamic Access Structure Capability. The method supports dynamic adjustment of the access structure required for key derivation without altering the user’s identity (the same cryptographic key may be derived from answers to different requests as set in the user’s profile). This flexibility has broad practical applications, such as enabling users to enhance security in authentication systems without requiring changes to underlying credentials or identities.
[0227] -Identity Representation. The derived keys can uniquely represent both user identities and object identities, enabling applications such as secure authentication, transaction signing, and personalized encryption without reliance on centralized authorities.
[0228] -Projection from Real Life to Bits. The method associates real-life data (the answers to requests, wherein the requests are personal queries touching the personal sphere or history or body of a person) into binary representations suitable for cryptographic purposes.
[0229] -Keyless Architecture. In stark contrast to traditional methods whereexternal servers are required to store or manage cryptographic keys, the method as disclosed does not need for key management. Keys are regenerated on-demand by users, ensuring enhanced security and complete user autonomy without the existence of centrally managed keys.
[0230] -Extensibility to Object Identities. The method extends beyond personal identities to include objects (e.g., smart appliances) by utilizing their unique identifiers and contextual data to generate corresponding keys. -Extensibility to Agents: The method extends beyond personal identities to include information technology-based agents (e.g. Al agents, devices or sensors) by leveraging their unique architecture models and intrinsic data (e.g., model weights, training material, or fine-tuning data, external detections such as GPS coordinates) to generate corresponding cryptographic keys.
[0231] In one embodiment of the invention, the following modules may be adopted to implement the system for cryptographic key derivation. The modules form the architecture of the system as claimed. The architecture may be distributed on a plurality of server so as part of the processing is made on a server and part on another server.
[0232] *Entropy Collector. This module gathers entropy (the answers) from user-supplied real-life sources, which may accept inputs from personal memories, owned devices, biometric sensors, and real-life objects, including contextual information such as the spatial or temporal relationships between these objects, their last interaction times, or other relevant real-world associations.
[0233] *Entropy Transformer. This module processes the collected entropy (the answers) using a proprietary algorithm to ensure uniformity and suitability for cryptographic key derivation. To cite an example, entropy collected one time as answers to requests in the order QB1, QB2, QB3, QB4, QB5 and in the order QB5, QB3, QB4, QB2, QB1 another time maybe normalized to the same order QB1, QB2, QB3, QB4, QB5.
[0234] This module processes the collected entropy (the answers) using a proprietary algorithm to ensure uniformity and suitability for cryptographic key derivation. The entropy collection process supports both recursive structures and multiple question pools, enabling dynamic flexibility. For instance:
[0235] 1. Recursive Possibilities: Each question block (QB) can lead to a set of sub-questions. For example, answering QB1 may lead to sub-questions QB1.1, QB1.2, and so on. The collected entropy is normalized regardless of the depth or branching of the question sequence, ensuring consistent derivation.
[0236] 2. Multiple Question Pools: The entropy collection can alternate between different stacks of questions. For instance, the process can dynamically switch from:
[0237] • QB Path: A question block pool defined by parameters n_B (number of questions) and a threshold m_B (minimum answers required for key derivation) .
[0238] • QC Path: An alternate pool of questions defined by its own parameters n_C and m_C.
[0239] This design ensures that entropy collected one time as answers to requests in the order QB1, QB2, QB3, QB4, QB5 (or sub-questions like QB1, QB 1.1, QB 1.2) and another time in a different order or path (e.g., QB5, QB3, QC1, QC2) can be normalized to a consistent format.
[0240] *Key Derivation Function (KDF). KDF transforms the processed entropy into the cryptographic key, i.e. it derives cryptographic key. The KDF ensures that the same set of entropy inputs consistently produces the identical key.
[0241] *Pseudorandom Function (PRF): A PRF is a cryptographic function that takes an input (e.g., a key and a message) and produces an output thatis computationally indistinguishable from random, given the input. The PRF ensures that the same input consistently produces the same pseudorandom output, making it deterministic and predictable for identical inputs while maintaining randomness to outside observers without knowledge of the key.
[0242] threshold Manager: Manages the threshold-based and dynamic threshold mechanisms, allowing flexibility in the number of entropy factors (answers) required for key derivation.
[0243] The Key Generation Process may be summarized as follows.
[0244] *Entropy Collection:
[0245] - Users select or provide real-life entropy sources (the answers) based on their personal or object- specific data.
[0246] - The system as disclosed accept multiple types of inputs, allowing for flexibility and personalization.
[0247] *Entropy Processing:
[0248] - The collected entropy is normalized and aggregated to form a coherent input for the KDF.
[0249] - The algorithm ensures that minor changes in entropy sources result in significant key alterations, maintaining cryptographic strength.
[0250] *Threshold-Based Aggregation:
[0251] - Users can define a threshold indicating the minimum number of entropy factors (answers) required to regenerate the key.
[0252] - This allows key derivation even if some entropy factors are unavailable, providing resilience against loss or forgetfulness.
[0253] *Dynamic Threshold Adjustment:
[0254] -The system supports the modification of the threshold as user needs evolve. For example, a user can increase the number of required factors to enhance security without altering the existing key or identity.* Seed Derivation:
[0255] -The KDF or the PRF applies cryptographic transformations to the aggregated entropy to produce the cryptographic seed.
[0256] -Since the entropy sources are user-controlled and reproducible, the derived key can be regenerated on-demand without storing the key.
[0257] Advantageously, the system as disclosed allows to set thresholds for security in cryptographic key derivation.
[0258] *Flexibility in Entropy Usage:
[0259] - Users are not required to use all initially provided entropy factors every time the cryptographic key is regenerated.
[0260] - The system can reconstruct the key using any subset of entropy factors (answers) that meet or exceed the predefined threshold.
[0261] *Adding or Removing Entropy Factors:
[0262] - Users can modify their set of entropy sources by adding new factors (requests and corresponding answers) or removing existing ones.
[0263] - Such modifications do not affect the derived key or the user's identity, provided the remaining factors satisfy the threshold requirement.
[0264] *Resilience and Redundancy:
[0265] -The threshold mechanism ensures that the loss or compromise of certain entropy factors does not render the key unrecoverable.
[0266] - This redundancy enhances the system's robustness against partial data loss.
[0267] The term threshold in the application is used to indicate number m. indeed, the profile of the user includes at least n requests of input, with n >= 2, and according to the method, m inputs (m<=n) from the user are collected as answers from the user. The threshold is m (for instance 3), meaning that no cryptographic key is derived in absence of at least m (3) answers to corresponding requests (3 request). Based on the user’s need,the threshold m may be increased (to 4 for instance) or decreased (to 2 for instance), meaning that, respectively, more or less answers (4 or 2) to corresponding more or less requests (4 or 2) as set in the profile has to be given by the user to derive the cryptographic key. Also the number of requests in the profile may be changed by the user.
[0268] The Dynamic Threshold Capability has the following advantages.
[0269] *Adaptive Security Levels:
[0270] - Users can adjust the threshold based on their current security needs. For instance, increasing the threshold can provide stronger security for high-value operations without necessitating key regeneration.
[0271] *Seamless Threshold Evolution:
[0272] -The system allows threshold changes without requiring the user to transfer accounts, identity and / or account / identity related properties or undergo complex reconfiguration processes.
[0273] - This dynamic adaptability ensures that security measures can evolve in tandem with user requirements.
Claims
CLAIMS1. Method for providing inputs to create a seed for cryptographic purpose, the method including:-a step of configuration of a profile, said profile including at least n requests of input (n >= 2), and said profile being stored in a memory; -a step of retrieving m inputs (m<=n), wherein said step of retrieving m inputs includes running a processor for:• selecting m requests among the n requests in said profile,• requesting m answers to the selected m requests,• taking the m answers to said m requests as inputs for creating the seed; whereinat least one of said m answers is not stored in a computer memory.
2. Method according to claim 1, wherein the profile is a human user profile and said at least one of said m answers is known only to the human user, based on his biological memory.
3. Method according to claim 2, wherein the n requests of input in the human user profile are set by the human user.
4. Method according to claim 1 , wherein the profile is a profile associated to a non-human user and said at least one of said m answers is known only to the non-human user.
5. Method according to claim 4, wherein the n requests of input in the non-human user profile are set by the non-human user, wherein the non-human user is a computer agent.
6. Method according to claim 5, wherein the computer agent includes an artificial intelligence algorithm, trained on a data set, and wherein the artificial intelligence algorithm, once trained, is enabled to generate said n requests and said answers to requests, wherein a same answer is returned by the artificial intelligence algorithm on a same request.
7. Method according to claim 6, wherein the dataset on which an artificial intelligence algorithm is trained differs from the dataset on which any other artificial intelligence algorithm is trained, so as requests configured in the non-human user profile of the artificial intelligence algorithm and corresponding answers provided by artificial intelligence algorithm are different from requests configured in the non-human user profile of another artificial intelligence algorithm and corresponding answers provided by said another artificial intelligence algorithm.
8. Method according to claim 1, wherein said number n and m are configurable.
9. Method according to claim 1, wherein said number n is at least five.
10. Method according to claim 1, wherein, in said step of selecting the m requests among the n requests, the selection of the m requests to be requested is random.
11. Method according to claim 1, wherein in said step of requesting the selected m requests, one request at a time is requested.
12. Method according to claim 2, said n requests include at least two among requests of:-a password known to the human user;-a PIN known to the human user;-a biometric data of the human user,-an information known to the human user;-data dynamically generated in connection with the human user.
13. Method according to claim 1, said n requests include at least two among requests of information that the human user-knows, brings, has, or produces.
14. Method according to claim 1, further including the step of deriving a cryptographic key from the seed, wherein said cryptographic key is notstored anywhere.
15. Method according to claim 14, wherein said step of deriving the cryptographic key is repeated each time the cryptographic key is required, wherein said step of requiring the cryptographic key includes running the processor to retrieve the m inputs.