Ledger Secured Key Escrow Access for Encrypted Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing encryption systems face challenges in allowing authorized third-party access without compromising security, as backdoors can be exploited by malicious parties, and existing key escrow systems rely on trust that is difficult to verify.
Innovation Solution
A system utilizing a plurality of trustee systems to securely store and manage secret shares of a secret, ensuring only a designated third party can access the secret, with validation mechanisms to verify requests and provide an overt record of access, using cryptographic protocols and asymmetric key pairs to maintain security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If backdoors are introduced into encryption algorithms to enable authorized third-party access, then access control is improved, but security is compromised because backdoors can be exploited by unauthorized malicious third parties
Solution Approach 1:
The encryption key is divided into multiple secret shares distributed to different trustee systems. No single trustee or backdoor can reconstruct the key alone; a threshold number of trustees must collaborate, preventing unilateral exploitation while enabling authorized access through controlled key recovery procedures.
Solution Approach 2:
Trusted trustee systems act as intermediaries between the data owner and authorized third parties. These trustees hold secret shares and participate in a verifiable key recovery process that requires mutual authentication and produces an overt record of access, preventing direct backdoor exploitation while enabling legitimate access requests.
2Ease of operation
If trusted authorities are used to control access to encrypted data, then access management is simplified, but trust verification becomes impossible as there is no effective way of verifying whether the trusted authority has acted in the interests of the data owner
Solution Approach 1:
The system implements overt feedback mechanisms where the data owner receives persistent records of all key recovery requests and trustee actions. This transparency allows the owner to verify that trustees have acted according to authorization, enabling detection and measurement of trustworthiness through observable audit trails.
Solution Approach 2:
The data owner pre-designates trusted trustees and establishes authorization rules before any key recovery is needed. This preliminary configuration creates a framework where future access requests can be automatically verified against pre-established criteria, enabling ongoing trust verification without requiring continuous manual intervention.
3Ease of operation
If key escrow systems are implemented with social linkage verification, then authorized access is enabled, but the system still requires trust in social or institutional bodies which has limitations and drawbacks
Solution Approach 1:
The system replaces social and institutional trust mechanisms with cryptographic and computational verification. Instead of relying on courts or trusted individuals to validate access requests, the system uses digital signatures, public-key cryptography, and smart contracts to automatically verify authorization and record access events, eliminating dependency on fallible social structures.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present invention relates to a cryptographic protocol, and a system for implementing said protocol, for providing overt ledger secured key escrow access to encrypted data. The invention uses a plurality of trustee systems, each holding a secret share of a secret, to validate requests for the secret from authorised third parties. When a valid request is made, each trustee system publishes its secret share to a ledger. The secret shares can be combined to reveal the encryption key only by the authorised third party. Requests for the encryption key, and the responses by the trustee systems, can be accessed by the owner of the encryption key to identify the requesting third party and to have proof that the key has been revealed to the third party.