Distributed Cryptographic Key Hierarchy for Secure Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection systems face challenges with privacy and management overheads, as they are either insecure due to third-party involvement or prone to customer lockouts and data losses due to poor management practices.
Innovation Solution
A data protection system utilizing a hierarchy of cryptographic keys distributed between a backend server, a key controller, and an administrator's computing device, with a first master key selected by the administrator and a second master key generated by the key controller, providing multi-factor protection and limiting access to plaintext data and keys, thus enhancing security and reducing management burdens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption keys are stored by a third party for customer data protection, then data security is improved, but privacy is reduced because government agencies or unscrupulous parties could compel the third party to release keys
Solution Approach 1:
The encryption key is divided into multiple segments or shares that are distributed to different parties (customer, vendor, third party). No single party possesses the complete key, making it impossible to decrypt data without collaboration. This resolves the contradiction by maintaining security through distributed control while preserving privacy through cryptographic commitment schemes that prevent key revelation.
Solution Approach 2:
A trusted third party acts as an intermediary that holds key segments but cannot reconstruct the full key alone. This intermediary enables secure key management while implementing privacy-preserving mechanisms such that even the third party cannot access plaintext data or force key disclosure to external entities.
2Object-affected harmful factors
If encryption keys are stored locally on customer premises in a key management server, then privacy is improved, but customer management overheads increase significantly
Solution Approach 1:
The patent introduces a third-party key management intermediary that assumes responsibility for key storage and management operations. This eliminates the need for customers to maintain their own key management servers, reducing management overhead while preserving privacy through cryptographic techniques that prevent the intermediary from accessing plaintext data.
Solution Approach 2:
The system implements automated key management processes where the third-party intermediary handles key generation, distribution, and recovery operations without requiring customer intervention. This self-service approach to key management significantly reduces the operational burden on customers while maintaining strong privacy protections.
3Object-affected harmful factors
If encryption keys are stored locally on customer premises, then privacy is improved, but the system becomes prone to customer lockouts due to failure to correctly manage or backup the key management server
Solution Approach 1:
The encryption key is segmented into multiple shares distributed to different parties including the customer and a third party. This segmentation eliminates single points of failure, as the customer can recover access by collaborating with the third party if their local key segment is lost or corrupted, thereby improving access reliability while maintaining privacy.
Solution Approach 2:
The system implements pre-configured key recovery mechanisms where third parties hold key segments in advance. This beforehand preparation ensures that if customer lockout occurs due to local key management failures, recovery is immediately possible through the pre-established third-party key segments, enhancing reliability without compromising privacy.
4Object-affected harmful factors
If users or customers retain and manage their own encryption keys, then privacy is improved, but the risk of customer lockout increases due to users forgetting passwords or careless management
Solution Approach 1:
The patent introduces a third-party intermediary that assists users in key management operations without compromising privacy. This intermediary provides services such as key generation assistance, secure storage, and recovery facilitation, making key management easier for users while maintaining strong privacy protections through cryptographic techniques.
Solution Approach 2:
The system enables users to perform key management operations independently through automated processes and user-friendly interfaces. Users can generate, store, and recover keys with minimal intervention, improving ease of operation while privacy is maintained through cryptographic designs that prevent unauthorized access even when users handle their own keys.
Data Source
AI summary
There is disclosed a data protection system which comprises a backend server for providing a secure data storage facility to a network, the network being managed by an administrator. The system includes at least one key controller hosted on the network, and a hierarchy of cryptographic keys for cryptographically protecting data of the network. The hierarchy of keys are distributed between the network, the key controller and the backend server. The hierarchy of keys comprises first and second master keys Ax, Cx that are associated with the administrator and the key controller respectively. One or more derived keys are derived from the first and second master keys. At least one of the first and second master keys are kept resident on the network and at least one of the derived keys are kept resident on the backend server.


