Anonymous Cloud Key Broker for Secure Identity Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud-based technologies face challenges in providing secure, anonymous access to cloud services, especially for users who need to collaborate across different devices and networks while maintaining data security and privacy.
Innovation Solution
The implementation of anonymous cloud encryption methods and systems that utilize anonymizing tokens and encryption keys to facilitate secure, anonymous transactions and collaboration, ensuring that user identities and data are protected from the cloud service and key broker, even if required to be disclosed by law enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud services track and log user actions for security purposes, then security monitoring is improved, but user anonymity and privacy are worsened
Solution Approach 1:
The patent introduces an intermediary layer between the user and cloud service that enables anonymous authentication. The system uses cryptographic keys and tokens as intermediaries to prove user identity and authorization without revealing personal information. The cloud service verifies authentication credentials without ever learning the user's real identity, thus maintaining both security monitoring and user anonymity.
Solution Approach 2:
The patent segments the authentication process into separate components: identity generation, key management, and verification. By dividing the authentication system into distinct functional modules, the patent enables the verification of authentication credentials without exposing user identity information. This segmentation allows security monitoring to occur at the credential level rather than the personal information level.
2Reliability
If encryption keys are stored on the key broker for authentication, then authentication reliability is improved, but security risk from broker compromise is worsened
Solution Approach 1:
The patent extracts the most sensitive cryptographic material (private keys) from the key broker and stores it exclusively in the user's possession. The key broker only stores non-sensitive authentication credentials and metadata. This extraction eliminates the security risk of private key compromise while maintaining authentication reliability through the broker's verification capabilities.
Solution Approach 2:
The patent applies different security requirements to different components of the authentication system. High-security local storage is used for private keys on the user device, while the key broker uses standard security measures for storing authentication credentials. This local quality approach optimizes security for each component's specific needs rather than applying uniform security measures.
3Loss of information
If anonymous authentication is implemented, then user privacy is improved, but collaboration and account recovery become more difficult
Solution Approach 1:
The patent implements feedback mechanisms where the key broker provides verification responses and authentication status information back to users and collaborating parties. This feedback enables anonymous users to confirm successful authentication, share access credentials with collaborators, and receive guidance for account recovery without revealing their identity. The system responds to authentication attempts with actionable information that facilitates collaboration and recovery.
Solution Approach 2:
The patent creates a universal authentication system that handles multiple functions through a single anonymous credential mechanism. The same cryptographic infrastructure supports authentication, collaboration sharing, and account recovery operations. This multi-functionality eliminates the need for separate systems for each operation, maintaining ease of operation while preserving anonymity.
Data Source
AI summary
Embodiments of systems and methods for providing anonymous cloud encryption are provided. One embodiment of a method for providing anonymous cloud encryption includes communicating an anonymizing token to a key broker. Additionally, the method may include communicating at least one encryption key associated with the anonymizing token to the key broker. The method may also include conducting a secure anonymous transaction with a cloud service using at least one of the encryption keys associated with the anonymizing token.


