Meta-Secret Key Generation for Secure Content Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital content distribution systems face inefficiencies in secure key management, as they require multiple sets of secret-shares for different keys, making large-scale applications impractical and vulnerable to hacking and unauthorized key sharing.

Innovation Solution

A cryptographic method using a meta-secret to generate multiple cryptographic keys and sets of secret-shares, where each set can be used to decrypt data items identified by unique key identifiers, distributed across different subscriber premises or servers, ensuring secure decryption and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple sets of secret-shares are used for different keys in existing digital content distribution systems, then security against hacking and unauthorized key sharing is improved, but device complexity and impracticality for large-scale applications increase

Engineering Contradiction:
Improvesecurity against hacking and unauthorized key sharingVSAvoidcomplexity of key management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a single set of secret-shares that can generate multiple cryptographic keys through different key identifiers. This multi-functional approach allows the same secret-share set to serve multiple purposes (decrypting different content items) without requiring separate secret-share sets for each key, thereby reducing system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the key generation process by introducing key identifiers that distinguish between different cryptographic keys derived from the same secret-shares. This segmentation allows the system to manage multiple keys through a unified secret-share structure, reducing the overhead of maintaining multiple separate key management systems.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple sets of secret-shares are maintained for different keys, then security is improved, but the system becomes vulnerable to hacking and unauthorized key sharing

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to hacking and unauthorized key sharing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges multiple key management functions into a single unified system. By combining multiple cryptographic keys under one set of secret-shares with key identifiers, the system reduces the attack surface. Hackers can no longer target individual key management systems independently, as all keys are derived from the same secret-share pool, making the system more resilient to hacking and unauthorized key sharing.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If traditional key management methods are used, then ease of operation is maintained, but productivity and efficiency for large-scale content distribution decrease

Engineering Contradiction:
Improveease of key management operationVSAvoidefficiency of content distribution
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent enhances productivity by enabling a single set of secret-shares to generate multiple cryptographic keys for different content items. This multi-functional approach eliminates the need to manage and distribute separate key sets for each content item, significantly improving efficiency and scalability for large-scale content distribution while maintaining ease of operation through a unified key management interface.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9106407B2Key generation using multiple sets of secret shares
Publication Date: 2015.08.11 CISCO TECHNOLOGY INC
  • US9106407B2 patent drawing
  • US9106407B2 patent drawing
  • US9106407B2 patent drawing

AI summary

A cryptographic method, including generating, using a meta-secret, a first plurality of cryptographic keys, each cryptographic key associated with a respective key identifier, creating, using the meta-secret, a second plurality of sets of secret-shares, which are capable, by combining all the secrets-shares in any one of the sets together with the respective key identifier, of generating the associated cryptographic key, and performing cryptographic operations using the cryptographic keys. Related methods and apparatus are also included.