Persona Management via Distributed Key Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online marketplaces and exchanges rely exclusively on cryptographic keys for user identification, leading to significant risks of personal information loss if the device storing the private key is lost or destroyed, as users must maintain the private key for access to encrypted data.
Innovation Solution
A persona management system utilizing blockchain technology and Shamir secret sharing to share portions of the private key with trusted parties, allowing for secure regeneration and recovery of the private key, eliminating the need for users to store the key themselves and enabling identity management by proxy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users store private cryptography keys on their devices, then they can access encrypted personal information, but they risk losing access to their identity information if the device is lost or destroyed
Solution Approach 1:
The patent divides the private key into multiple secret shares using Shamir's Secret Sharing scheme. Instead of storing the complete private key on a single device, the system segments it into N shares distributed across different storage locations or devices. Any M shares (where M ≤ N) can reconstruct the original private key, ensuring that loss of one or more devices does not result in permanent data loss.
Solution Approach 2:
The system performs preliminary key segmentation and distribution before any potential device loss occurs. By pre-distributing secret shares to multiple trusted locations or devices, the system ensures that recovery capability is already in place, eliminating the need for complex recovery procedures after device loss.
2Ease of operation
If users maintain their own private keys, then they have full control over their encrypted data, but they bear the responsibility and risk of key management
Solution Approach 1:
The patent introduces a trusted third-party intermediary system that manages the secret shares on behalf of users. Instead of users directly managing their private keys, the intermediary system stores and manages the segmented secret shares. This mediator handles key recovery operations by collecting sufficient shares and reconstructing the private key when needed, reducing user burden while maintaining security through cryptographic principles.
Solution Approach 2:
The system enables automated key recovery through self-service mechanisms. When a user loses their device, the system automatically initiates the key recovery process by collecting secret shares from distributed sources and reconstructing the private key without requiring manual intervention or complex administrative procedures.
3Object-affected harmful factors
If cryptography is used to secure identity information, then data security is improved, but the system becomes vulnerable to complete data loss if the decryption key is lost
Solution Approach 1:
The patent applies different security characteristics to different parts of the cryptographic system. Secret shares are distributed with varying access permissions and storage locations, creating local quality variations. Each share has the same cryptographic strength but different accessibility properties, allowing the system to balance security and recoverability at different locations.
Solution Approach 2:
The system implements beforehand cushioning by pre-distributing secret shares to multiple locations before any potential key loss scenario occurs. This creates a buffer or safety net that cushions against the harmful effect of device loss, ensuring that encrypted data remains accessible even when original storage devices are compromised or lost.
Data Source
AI summary
A system and method for persona management in online environments provides an identity by proxy with trusted parties having portions of the private cryptographic key of the consumer so that the private cryptographic key of the consumer may be generated. The system and method implements the persona management in online environments in one embodiment using an immutable ledger with decentralized transaction consensus and a process to share portions of the private cryptographic key with trusted third parties.


