Oblivious Pseudorandom Function for Cloud Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Key Management Systems (KMS) face challenges in ensuring secure and reliable key management, particularly in cloud-based technologies, where trust in the cloud provider is required, leading to security concerns and vulnerabilities, especially when dealing with encrypted data and encryption keys.
Innovation Solution
The implementation of Oblivious Pseudorandom Functions (OPRFs) enables secure key management by allowing two parties to cooperatively evaluate a function, where only one party receives the output, and the other party cannot learn the input or output, ensuring that encryption keys remain secure and do not need to be trusted to any cloud provider, eliminating the need for infrastructure on tenant premises.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cloud-based Key Management System is implemented, then accessibility and scalability are improved, but security and trust requirements worsen due to reliance on cloud provider
Solution Approach 1:
The patent introduces an intermediary cryptographic protocol (OPRF) that mediates between the client and cloud provider. The protocol uses blinding keys and pseudorandom functions to ensure that the cloud provider cannot learn the encryption keys or input values, while still allowing secure key management operations to be performed in the cloud.
Solution Approach 2:
The patent replaces the mechanical/trust-based system of cloud key management with a cryptographic mathematical system. Instead of relying on trust in the cloud provider's behavior, the system uses cryptographic proofs and oblivious evaluation to guarantee security properties mathematically.
2Ease of operation
If traditional KMS is used where provider sees keys, then key management operations are simplified, but security vulnerabilities increase due to provider access to encryption keys
Solution Approach 1:
The OPRF protocol acts as an intermediary layer between the key management operations and the cloud provider. It allows the provider to perform operations on encrypted data without ever seeing the actual encryption keys, using cryptographic blinding and unblinding operations.
Solution Approach 2:
The patent extracts the sensitive cryptographic secret (the OPRF key held by the provider) from the key management operations. The provider holds only the OPRF key, while the actual encryption keys are derived locally by clients using the OPRF protocol, preventing the provider from accessing them.
3Productivity
If cloud provider has full access to keys for management, then key lifecycle operations are efficient, but trust requirements and security risks worsen
Solution Approach 1:
The OPRF protocol serves as a cryptographic intermediary that enables efficient key management operations in the cloud while maintaining security. It allows the cloud provider to participate in key operations without needing to see or trust the actual encryption keys.
Solution Approach 2:
The system enables self-service key management where clients can perform key operations locally using the OPRF protocol. Clients can derive keys, update keys, and manage their own cryptographic material without the provider needing direct access, while still leveraging cloud resources for computation.
Data Source
AI summary
A computing device includes an interface configured to interface and communicate with a communication system, a memory that stores operational instructions, and processing circuitry operably coupled to the interface and to the memory that is configured to execute the operational instructions to perform various operations. The computing device processes an input value associated with a key based on a blinding key in accordance with an Oblivious Pseudorandom Function (OPRF) blinding operation to generate a blinded value and transmits it to another computing device (e.g., that is associated with a Key Management System (KMS) service). The computing device then receives a blinded key that is based on processing of the blinded value based on an OPRF using an OPRF secret. The computing device processes the blinded key based on the blinding key in accordance with the OPRF unblinding operation to generate the key (e.g., to be used for secure information access).


