Anonymous Cloud Key Broker for Secure Identity Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud-based technologies face challenges in providing secure, anonymous access to cloud services, especially for users who need to collaborate across different devices and networks while maintaining data security and privacy.

Innovation Solution

The implementation of anonymous cloud encryption methods and systems that utilize anonymizing tokens and encryption keys to facilitate secure, anonymous transactions and collaboration, ensuring that user identities and data are protected from the cloud service and key broker, even if required to be disclosed by law enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud services track and log user actions for security purposes, then security monitoring is improved, but user anonymity and privacy are worsened

Engineering Contradiction:
Improvesecurity monitoringVSAvoiduser anonymity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary layer between the user and cloud service that enables anonymous authentication. The system uses cryptographic keys and tokens as intermediaries to prove user identity and authorization without revealing personal information. The cloud service verifies authentication credentials without ever learning the user's real identity, thus maintaining both security monitoring and user anonymity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process into separate components: identity generation, key management, and verification. By dividing the authentication system into distinct functional modules, the patent enables the verification of authentication credentials without exposing user identity information. This segmentation allows security monitoring to occur at the credential level rather than the personal information level.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption keys are stored on the key broker for authentication, then authentication reliability is improved, but security risk from broker compromise is worsened

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsecurity risk from broker compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the most sensitive cryptographic material (private keys) from the key broker and stores it exclusively in the user's possession. The key broker only stores non-sensitive authentication credentials and metadata. This extraction eliminates the security risk of private key compromise while maintaining authentication reliability through the broker's verification capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different security requirements to different components of the authentication system. High-security local storage is used for private keys on the user device, while the key broker uses standard security measures for storing authentication credentials. This local quality approach optimizes security for each component's specific needs rather than applying uniform security measures.

Inventive Principle:
Principle #3Local quality

3Loss of information

If anonymous authentication is implemented, then user privacy is improved, but collaboration and account recovery become more difficult

Engineering Contradiction:
Improveuser privacy protectionVSAvoidcollaboration and recovery
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent implements feedback mechanisms where the key broker provides verification responses and authentication status information back to users and collaborating parties. This feedback enables anonymous users to confirm successful authentication, share access credentials with collaborators, and receive guidance for account recovery without revealing their identity. The system responds to authentication attempts with actionable information that facilitates collaboration and recovery.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent creates a universal authentication system that handles multiple functions through a single anonymous credential mechanism. The same cryptographic infrastructure supports authentication, collaboration sharing, and account recovery operations. This multi-functionality eliminates the need for separate systems for each operation, maintaining ease of operation while preserving anonymity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9160535B2Truly anonymous cloud key broker
Publication Date: 2015.10.13 DELL PROD LP
  • US9160535B2 patent drawing
  • US9160535B2 patent drawing
  • US9160535B2 patent drawing

AI summary

Embodiments of systems and methods for providing anonymous cloud encryption are provided. One embodiment of a method for providing anonymous cloud encryption includes communicating an anonymizing token to a key broker. Additionally, the method may include communicating at least one encryption key associated with the anonymizing token to the key broker. The method may also include conducting a secure anonymous transaction with a cloud service using at least one of the encryption keys associated with the anonymizing token.