Per-User Secret Shares for Anonymous Data Transmission
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data transmission systems face challenges in ensuring secure and reliable transmission of user data, particularly in maintaining user anonymity and preventing unauthorized exposure of sensitive information.
Innovation Solution
The use of per-user-functionality secret shares, including data retrieval, evaluation, and auditing secret shares, along with data encryption using a user data private key maintained on the client side, and indexed user data storage through one-way transformation, to enhance data security and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If user data is stored in a centralized database for easy retrieval and management, then data access efficiency is improved, but the risk of unauthorized access and identity exposure increases
Solution Approach 1:
The patent segments user data into multiple secret shares and distributes them across different storage locations. No single location contains the complete user data, so even if one storage location is compromised, the full user identity cannot be reconstructed. This resolves the contradiction by maintaining data accessibility through distributed storage while reducing unauthorized access risk through cryptographic segmentation.
Solution Approach 2:
The patent introduces secret sharing schemes and cryptographic protocols as intermediaries between the user data and storage systems. These intermediaries transform user data into secure secret shares that can be stored and retrieved efficiently while providing mathematical guarantees against unauthorized reconstruction of user identity. This resolves the contradiction by enabling efficient data access through the intermediary layer while the intermediary itself provides security protection.
2Ease of operation
If user identifying information is stored for authentication and data retrieval purposes, then user account functionality is improved, but the vulnerability to identity theft and data breaches increases
Solution Approach 1:
The patent segments user identifying information into multiple secret shares that are distributed across different storage locations. The system can still authenticate users and retrieve data by reconstructing the secret shares through cryptographic protocols, but no single location contains the complete user identity. This resolves the contradiction by maintaining user account functionality through distributed secret reconstruction while reducing identity exposure risk through segmentation.
Solution Approach 2:
The patent applies different security properties to different parts of the system. Each storage location has the property of storing only partial secret shares that are mathematically useless on their own, while the central authentication system has the property of being able to reconstruct full user identity only when authorized. This resolves the contradiction by enabling user account functionality at the authentication layer while maintaining security at the storage layer through local quality differentiation.
3Extent of automation
If a centralized system maintains user data for efficient management and retrieval, then system control and coordination are improved, but the impact of security breaches and data leaks increases
Solution Approach 1:
The patent segments the centralized data storage into multiple distributed storage locations, each holding only partial secret shares. The automated system control is maintained through cryptographic protocols that can coordinate between distributed locations, but the impact of security breaches is reduced because no single location contains complete user data. This resolves the contradiction by maintaining system control through automated cryptographic coordination while reducing data breach impact through segmentation.
Solution Approach 2:
The patent changes the fundamental parameter of data storage from storing complete user records to storing distributed secret shares. This parameter change allows the system to maintain automated control and coordination through cryptographic reconstruction protocols while dramatically reducing the impact of security breaches, as compromised data represents only a fraction of the original information. This resolves the contradiction by transforming the storage parameter to enable both automation and security.
Data Source
AI summary
There is a need for more effective and efficient secure data transmission. This need can be addressed by, for example, solutions for secure data transmission that utilize secret shares. In one example, a method includes generating a hashed user identifier based on a received user identifier; transmitting the hashed user identifier to an external computing entity; receiving a data retrieval secret share from the external computing entity, in response, transmitting an account identifier and an auditing public key to the external computing entity; and receiving an encrypted data audit secret share from the external computing entity, wherein: (i) the encrypted data audit secret share is based at least in part on a data audit secret share encrypted using the auditing public key, and (ii) the data audit secret share is based at least in part on a secret value.


