Ledger Secured Key Escrow Access for Encrypted Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing encryption systems face challenges in allowing authorized third-party access without compromising security, as backdoors can be exploited by malicious parties, and existing key escrow systems rely on trust that is difficult to verify.

Innovation Solution

A system utilizing a plurality of trustee systems to securely store and manage secret shares of a secret, ensuring only a designated third party can access the secret, with validation mechanisms to verify requests and provide an overt record of access, using cryptographic protocols and asymmetric key pairs to maintain security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If backdoors are introduced into encryption algorithms to enable authorized third-party access, then access control is improved, but security is compromised because backdoors can be exploited by unauthorized malicious third parties

Engineering Contradiction:
Improveauthorized accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The encryption key is divided into multiple secret shares distributed to different trustee systems. No single trustee or backdoor can reconstruct the key alone; a threshold number of trustees must collaborate, preventing unilateral exploitation while enabling authorized access through controlled key recovery procedures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Trusted trustee systems act as intermediaries between the data owner and authorized third parties. These trustees hold secret shares and participate in a verifiable key recovery process that requires mutual authentication and produces an overt record of access, preventing direct backdoor exploitation while enabling legitimate access requests.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If trusted authorities are used to control access to encrypted data, then access management is simplified, but trust verification becomes impossible as there is no effective way of verifying whether the trusted authority has acted in the interests of the data owner

Engineering Contradiction:
Improveaccess managementVSAvoidtrust verification
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements overt feedback mechanisms where the data owner receives persistent records of all key recovery requests and trustee actions. This transparency allows the owner to verify that trustees have acted according to authorization, enabling detection and measurement of trustworthiness through observable audit trails.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The data owner pre-designates trusted trustees and establishes authorization rules before any key recovery is needed. This preliminary configuration creates a framework where future access requests can be automatically verified against pre-established criteria, enabling ongoing trust verification without requiring continuous manual intervention.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If key escrow systems are implemented with social linkage verification, then authorized access is enabled, but the system still requires trust in social or institutional bodies which has limitations and drawbacks

Engineering Contradiction:
Improveauthorized accessVSAvoidtrust dependency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system replaces social and institutional trust mechanisms with cryptographic and computational verification. Instead of relying on courts or trusted individuals to validate access requests, the system uses digital signatures, public-key cryptography, and smart contracts to automatically verify authorization and record access events, eliminating dependency on fallible social structures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3576000B1System and method for providing an authorised third party with overt ledger secured key escrow access to a secret
Publication Date: 2020.08.12 TEGEDER ROLAND
  • EP3576000B1 patent drawingFigure 1
  • EP3576000B1 patent drawingFigure 2
  • EP3576000B1 patent drawingFigure 3

AI summary

The present invention relates to a cryptographic protocol, and a system for implementing said protocol, for providing overt ledger secured key escrow access to encrypted data. The invention uses a plurality of trustee systems, each holding a secret share of a secret, to validate requests for the secret from authorised third parties. When a valid request is made, each trustee system publishes its secret share to a ledger. The secret shares can be combined to reveal the encryption key only by the authorised third party. Requests for the encryption key, and the responses by the trustee systems, can be accessed by the owner of the encryption key to identify the requesting third party and to have proof that the key has been revealed to the third party.