Cryptographic Key Regeneration via Biometric Forcing Functions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for storing cryptographic keys and blockchain addresses are vulnerable to loss, theft, and hacking, particularly due to the reliance on key wallets and biometric data that can be intercepted or compromised.
Innovation Solution
A method and system for regenerating cryptographic keys and network addresses based on captured user biometric data and additional input data, without the need for stored encrypted forms, thereby reducing the risk of data loss and hacking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys and blockchain addresses are stored in key wallets on devices, then users can access their digital assets, but the devices become vulnerable to loss, theft, and hacking attacks
Solution Approach 1:
The patent extracts the sensitive cryptographic data from the storage device entirely. Instead of storing keys and addresses in wallets on devices, the system uses regeneration techniques where data is derived from biometric inputs and forcing functions that do not require persistent storage, thereby removing the attack target
Solution Approach 2:
The patent introduces biometric data and forcing functions as intermediaries between the user and their digital assets. These intermediaries enable secure access without requiring the actual cryptographic keys to be stored on the device, creating a security layer that prevents direct attacks on stored data
2Reliability
If key wallets are backed-up to the cloud, then data loss is prevented, but the wallets become vulnerable to remote third-party attacks and brute-force password attacks
Solution Approach 1:
The patent removes the vulnerability to remote attacks by extracting the actual cryptographic keys from cloud storage. Instead of storing recoverable key data in the cloud, the system stores only regeneration parameters (forcing functions and input parameters) that cannot be used to directly access assets without the biometric component
Solution Approach 2:
The patent changes the parameters of cloud storage from storing actual cryptographic keys or passwords to storing only forcing function definitions and input parameters. These parameters are mathematically transformed and cannot be reverse-engineered to obtain the original keys, preventing brute-force and remote attacks
3Reliability
If biometric data is captured and stored on smart devices to lock and unlock key wallets, then password attack vulnerability is reduced, but biometric data may be intercepted during transfer and can be demanded by external entities
Solution Approach 1:
The patent extracts biometric data from the storage system entirely. Biometric data is used only transiently for regeneration and then discarded, never stored on the device. This eliminates the risk of interception during transfer and exposure to external entities while maintaining security benefits
4Ease of operation
If sensitive data is stored on user devices, then convenient access is provided, but the devices are targets for hacking and data theft
Solution Approach 1:
The patent removes sensitive data from device storage while maintaining access convenience through regeneration. Users can access their digital assets as conveniently as before, but the assets are secured because the cryptographic keys never exist in stored form on the device, eliminating the hacking target
Data Source
AI summary
A computing system comprising a receiver configured to receive a biometric-based cryptographic key, a user input configured to receive a first set of user input data under direction of the user, and a processor coupled to the receiver and to the user input, wherein the processor is configured to receive an indicator of a first forcing function and a first plurality of input parameters for the first forcing function, wherein the processor is configured to determine a first output cryptographic key in response to the biometric-based cryptographic key, the first set of user input data, the first forcing function, and the first plurality of input parameters, without reference to any encrypted forms of the first output cryptographic key, and wherein the processor is configured to use the first output cryptographic key to access a first digital asset stored on a remote server.


