Blockchain Private Key Management via Entropic Security Questions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for securing private keys in blockchain technology, such as paper wallets and hardware devices, are vulnerable to theft, loss, and require users to remember and store long passphrases, which can be challenging and may compromise the decentralized nature of blockchain.
Innovation Solution
A computer-based system that uses a series of personally crafted security questions to generate a passphrase, encrypting the private key, and storing it on an analytic server, allowing users to access their keys without needing to remember or physically store the passphrase or private key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If private keys are stored on paper wallets or hardware devices, then security against digital theft is improved, but vulnerability to physical loss, theft, and damage increases
Solution Approach 1:
The patent extracts the private key from physical storage media (paper wallets, hardware devices) and stores it in encrypted form on secure servers. The encryption key is derived from user answers to security questions, separating the private key storage from physical media that are vulnerable to loss and damage.
Solution Approach 2:
The patent introduces encrypted private keys stored on secure servers as an intermediary solution. Instead of directly storing private keys on vulnerable physical media or requiring users to remember passphrases, the system uses encrypted keys accessible through security question verification, mediating between security requirements and user accessibility.
2Strength
If users encrypt private keys with long passphrases, then security strength is improved, but ease of operation deteriorates due to memory requirements
Solution Approach 1:
The patent replaces the mechanical system of human memory (remembering long passphrases) with a different system based on security questions. Users answer questions they remember, and the system derives encryption keys from these answers, substituting the need for memorizing complex strings with answering familiar questions.
Solution Approach 2:
The patent changes the parameter for key derivation from fixed-length passphrases to variable-length answers to security questions. This allows users to provide answers in their own words while the system ensures sufficient entropy through multiple questions, maintaining security while improving usability.
3Ease of repair
If users back up encrypted private keys with passphrases, then recovery capability is improved, but security risk increases due to centralized storage requirements
Solution Approach 1:
The patent enables users to service their own key recovery needs through security questions without requiring centralized administrative intervention. Users can recover their encrypted private keys by answering their own security questions, making the system self-service oriented and eliminating the need for trusted third-party custodians.
Solution Approach 2:
The patent inverts the conventional approach where centralized administrators hold backup keys. Instead, the system distributes control by requiring users to provide security question answers themselves for recovery, turning the recovery mechanism from centralized to decentralized while maintaining security.
4Reliability
If conventional security methods are used, then private key protection is improved, but user responsibility and operational complexity increase
Solution Approach 1:
The patent creates a universal system that handles multiple functions: secure storage, encryption, backup, and recovery all through a single interface using security questions. This consolidates what would otherwise require multiple separate mechanisms (paper wallets, hardware devices, passphrase management, backup procedures) into one unified approach.
Data Source
AI summary
Disclosed herein are embodiments of systems, methods, and products for authentication using entropic threshold. A server may require a user to create a series of security questions to which only the user has the answers. The answers to the security questions may satisfy an entropic threshold. Based on the answers to the security questions, the client device may generate a passphrase and encrypt the user's private key based on the passphrase. The server may also store the encrypted private key and the series of security questions into a database. When the user tries to access the private key, the server may send the user's security questions and encrypted private key. The client device may require the user to provide the answer to each security question. When the client device receives answers to all security questions, the client device may use the resulting passphrase to decrypt the user's encrypted private key.


