Distributed Secret Share Generation Using PRNG Trees

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face cognitive overload managing multiple passwords for encrypted storage resources, and centralized solutions require a single entity to interoperate with various services, applications, and devices, which is not user-friendly.

Innovation Solution

A system that distributes secret shares using a pseudo random number generator tree, where distribution devices generate share values based on a polynomial function, using random numbers and device identification, allowing multiple devices to independently recreate a secret value securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a centralized solution is used to manage encrypted storage resources, then interoperability across services and devices is achieved, but user convenience deteriorates due to the need to identify and manage a single central entity

Engineering Contradiction:
ImproveinteroperabilityVSAvoiduser convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the centralized secret management function into distributed secret shares that can be independently held by multiple devices. Instead of requiring users to identify and manage a single central entity, the system divides the secret into multiple parts that can be stored across different devices, allowing interoperability without centralization.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple passwords are used to secure different encrypted storage resources, then security is improved, but user convenience deteriorates due to cognitive overload

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments a single secret into multiple shares that can be distributed across different devices. Users only need to remember one secret while their devices collectively hold the distributed shares, maintaining security through distribution while eliminating the need to manage multiple passwords.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces polynomial functions and secret sharing schemes as intermediaries between the user's single secret and the multiple encrypted storage resources. The mathematical functions automatically generate distributed shares from the single secret, eliminating the need for users to manually create and manage multiple passwords.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If secret shares are distributed across multiple devices, then user convenience is improved by reducing cognitive overload, but system complexity increases due to the need for polynomial functions and pseudo random number generation

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where devices automatically generate polynomial functions and pseudo-random shares using their own identification values. The system performs the complex mathematical operations autonomously without requiring user intervention, hiding the complexity while providing simple user interaction.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the complex secret sharing problem into a simpler parameter-based system where each device uses its identification value as a parameter to generate its share. This parameterization approach simplifies the overall system complexity while maintaining the security benefits of distributed secret sharing.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3198781B1Techniques for distributing secret shares
Publication Date: 2019.06.12 INTEL CORP
  • EP3198781B1 patent drawingFigure 1
  • EP3198781B1 patent drawingFigure 2
  • EP3198781B1 patent drawingFigure 3A

AI summary

Various embodiments are generally directed to an apparatus, method and other techniques generating one or more polynomial elements for a polynomial function using a node value of a pseudo random number generator tree as a seed value, the polynomial function comprising a secret value and the polynomial elements, and the pseudo random number generator tree at least partially matching at least one other pseudo random number generator tree on another device, generating a plurality of share values based on the one or more polynomial elements and the polynomial function and distributing a share value of the plurality of share values to a device.