Cloud Backup Security via Local Master Key Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online storage systems face security risks due to the storage of user master passwords or their derivatives on servers, making them vulnerable to unauthorized access and password guessing attacks, especially when employees or hackers compromise the system.
Innovation Solution
Implementing a three-level security system where user master passwords are not stored on servers, using unique user device keys (UDKs) for authentication and encryption, which are generated and managed locally on the client device, ensuring that the master password is never transmitted or stored externally, and using a separate key for encryption and decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user master passwords or their derivatives are stored on servers for authentication, then authentication functionality is enabled, but security is compromised due to vulnerability to unauthorized access and password guessing attacks
Solution Approach 1:
The patent extracts the master password from the server environment entirely. Instead of storing passwords on servers, the system uses password-less authentication where the master password remains exclusively on the user's device. The server stores only encrypted data and authentication tokens, eliminating the security vulnerability of centralized password storage while maintaining authentication functionality through device-bound cryptographic keys.
Solution Approach 2:
The authentication system is segmented into device-side and server-side components. The master password and cryptographic key generation occur on the user's device, while the server handles only encrypted data storage and token verification. This segmentation ensures that even if the server is compromised, the master password remains secure on the user's device, resolving the contradiction between authentication functionality and security.
2Ease of operation
If employee access to user passwords is provided for system maintenance, then system maintenance capability is improved, but security is worsened as employees can pose as users
Solution Approach 1:
The patent removes passwords entirely from the server environment, making them inaccessible to employees. System maintenance is performed through cryptographic token management and encrypted data operations rather than direct password access. This extraction of passwords from the server eliminates internal security threats while maintaining system maintenance capability through secure token-based authentication.
3Loss of information
If network traffic monitoring is possible, then network analysis capability is improved, but security is worsened as interlopers can grab usernames and passwords
Solution Approach 1:
The patent extracts the master password from network transmission entirely. Authentication is performed using device-generated cryptographic tokens that never expose the master password on the network. Even though network traffic is visible, the intercepted tokens are useless without the master password that remains securely on the user's device, resolving the contradiction between network transparency and password security.
Solution Approach 2:
The system introduces cryptographic tokens as intermediaries between the user's device and the server. These tokens can be transmitted over the network for authentication but are mathematically derived from the master password without exposing it. This intermediary mechanism allows network communication while protecting the master password from interception, resolving the security contradiction.
4Reliability
If master passwords are stored locally on user devices, then authentication capability is maintained, but security is worsened as devices may be compromised
Solution Approach 1:
The patent implements dynamic authentication where the master password remains on the user's device but is never transmitted. The system dynamically generates cryptographic tokens for each authentication session based on the master password and device-specific secrets. This dynamic approach maintains authentication capability while reducing vulnerability to device compromise, as stolen tokens cannot be reused without the master password.
5Ease of manufacture
If traditional password-based authentication is used, then ease of implementation is improved, but security is worsened due to brute-force attacks
Solution Approach 1:
The patent replaces the mechanical password-based authentication system with a cryptographic token-based system. Instead of relying on secret passwords that can be guessed, the system uses mathematically secure cryptographic operations where authentication tokens are derived from the master password through one-way functions. This substitution maintains implementation simplicity while providing resistance to brute-force attacks through cryptographic security.
Data Source
AI summary
Methods and systems are provided for secure online data access. In one embodiment, three levels of security are provided where user master passwords are not required at a server. A user device may register with a storage service and receive a user device key that is stored on the device and at the service. The user device key may be used to authenticate the user device with the storage service. As data in the storage service is encrypted with a master password, the data may be protected from disclosure. As a user master key or derivative thereof is not used in authentication, the data may be protected from a disclosure or breach of the authentication credentials. Encryption and decryption may thus be performed on the user device with a user master key that may not be disclosed externally from the user device.


