Distributed Cryptographic Key Service for Cloud Data Confidentiality

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cloud services pose a single point of trust for data confidentiality, making them vulnerable to malicious attacks, as encryption/decryption keys are either stored centrally or permanently available, potentially compromising data security.

Innovation Solution

A system comprising a cloud service and a cryptographic key service with multiple cryptographic key servers, where file encryption keys are computed and distributed among servers, ensuring no single server possesses all key information, thus distributing trust and preventing a single point of attack.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If encryption/decryption keys are stored centrally or permanently available in traditional cloud services, then data access is simplified and operations are easier, but data confidentiality is compromised due to single point of trust vulnerability

Engineering Contradiction:
Improvedata access simplicityVSAvoiddata confidentiality
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The encryption key is divided into multiple key shares that are distributed across different cloud service providers. No single provider possesses the complete key, thereby eliminating the single point of trust vulnerability while maintaining secure data access through collaborative decryption processes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A key management service acts as an intermediary that coordinates key share distribution and manages the decryption process across multiple cloud service providers. This intermediary ensures that data access remains operationally simple while maintaining confidentiality through distributed key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a single central key management service is used, then key management is simplified, but the system becomes vulnerable to malicious attacks on the single point of trust

Engineering Contradiction:
Improvekey management structureVSAvoidmalicious attack vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The key management function is segmented across multiple independent cloud service providers, each holding only a portion of the key information. This segmentation prevents any single provider from being a target for malicious attacks while maintaining organized key management through distributed architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each cloud service provider operates with localized key share information specific to their role in the distributed system. This local quality ensures that no single provider has access to complete key information, thereby reducing vulnerability to attacks while maintaining efficient local key management operations.

Inventive Principle:
Principle #3Local quality

3Speed

If encryption keys are permanently available at client devices or central services, then decryption operations are faster, but the risk of key compromise increases

Engineering Contradiction:
Improvedecryption speedVSAvoidkey security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The key management system transitions from static permanent key storage to dynamic temporary key share distribution. Key shares are provisioned temporarily for specific decryption operations and then revoked, maintaining fast decryption speeds while improving key security through ephemeral key usage patterns.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10803194B2System and a method for management of confidential data
Publication Date: 2020.10.13 BLOCKDAEMON APS
  • US10803194B2 patent drawing
  • US10803194B2 patent drawing
  • US10803194B2 patent drawing

AI summary

A system and a method for managing confidential data in a cloud service is provided. The system comprises a cryptographic key service comprising two or more cryptographic key servers, Si, each being arranged to compute file encryption keys, kj, on the basis of information regarding data and using one or more cryptographic keys, Kj. The cryptographic keys, Kj, are secretly shared among the cryptographic key servers, Si, and none of the cryptographic key servers, Si, possesses knowledge of all of the cryptographic keys, Kj. A single point of trust at the cryptographic key service is avoided.