Non-Custodial Secret Backup With Distributed Recovery Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for backing up cryptographic keys and secrets face challenges as they often require custody of the secret to be passed to a third party, which can lead to loss, theft, or modification, and the increased complexity of keys makes them difficult to manage securely.

Innovation Solution

A method is provided where the backup comprises public data, allowing third parties to assist in recovery without custody of the secret, using a secret sharing scheme and key derivation to create a public backup that can be securely deleted, ensuring recovery is the only way to access the secret.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If custody of the secret is passed to a third party for backup, then recovery capability is improved, but security and reliability deteriorate due to risk of loss, theft, or modification

Engineering Contradiction:
Improverecovery capabilityVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The secret is divided into multiple shares using secret sharing schemes. Instead of storing the entire secret with a third party, the secret is segmented into pieces distributed among multiple parties, so that no single third party has full custody and control of the secret.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted third party is introduced as an intermediary that does not custody the secret but instead facilitates the backup and recovery process. The third party holds public keys and enables enrollment and recovery operations without ever obtaining custody of the actual secret data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If increased complexity of keys is used to enhance security, then resistance to brute force is improved, but ease of operation deteriorates due to difficulty in memorization and management

Engineering Contradiction:
ImprovesecurityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Complex keys are segmented into multiple smaller shares using secret sharing. Instead of requiring a user to memorize a single complex key, the key is divided into multiple simpler shares that can be distributed and managed more easily, while still providing equivalent security when combined.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of requiring the original complex key to be memorized or stored securely, copies of the key are created in the form of shares distributed to multiple parties. These copies can be easily stored and transmitted, eliminating the need for secure memorization while maintaining key functionality.

Inventive Principle:
Principle #26Copying

3Productivity

If keys are written down for backup, then recovery capability is improved, but security deteriorates due to increased risk of loss, theft, or modification

Engineering Contradiction:
Improverecovery capabilityVSAvoidrisk of loss
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The key is segmented into multiple shares that can be distributed across different locations and parties. This segmentation reduces the risk of total loss, as not all shares need to be compromised for the key to be vulnerable. Each share can be stored securely in different locations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted third party acts as an intermediary that facilitates the distribution and storage of key shares without directly custodying the secret. This intermediary enables secure backup mechanisms that reduce the risk of loss while maintaining recovery capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12438716B2Non-custodial enrollment and recovery of a secret
Publication Date: 2025.10.07 LOKBLOK INC
  • US12438716B2 patent drawing
  • US12438716B2 patent drawing
  • US12438716B2 patent drawing

AI summary

A method for non-custodial backup of a secret (1021) by the owner of said secret, assisted by a multiplicity n of recovery agents, each having individual public keys and private keys, and the owner having a first value (1013), comprising providing the owner with a first computer program, which at rest will reside on a computer readable medium, configured to enroll the secret by computing a public data set (1023) which does not need to be kept private, requires no security, no secure channels for distribution, and no custody requirements A method for recovery of the secret (1021) is also disclosed, without which there is no way to run the enrollment backwards and recover the secret.