Private Key Recovery via Requester-Provided Password Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional identity management systems require human interaction for key recovery, limiting security and efficiency in recovering private keys, especially when keys are lost or damaged.

Innovation Solution

The system allows for private key recovery by encrypting the recovered key using a requester-provided password, enabling secure delivery to the user without relying on an agent-provided password, thus enhancing security and accessibility for both token and non-token clients.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an agent-provided password is used to encrypt and deliver the recovered private key, then the key recovery process can be completed, but security is compromised because the password must be communicated verbally to the user

Engineering Contradiction:
Improvekey recovery completenessVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The user provides their own password to encrypt the recovered private key, eliminating the need for an agent to communicate the password verbally. This self-service approach maintains security while enabling complete key recovery, as the user already possesses the password needed to protect their own key material.

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If human interaction is required for password communication during key recovery, then security can be maintained through verbal communication, but efficiency and accessibility are reduced

Engineering Contradiction:
Improvesecurity controlVSAvoidkey recovery efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system allows users to independently complete key recovery by providing their own password without requiring an agent's verbal communication. This eliminates the need for human interaction in the password communication step, significantly improving efficiency and accessibility while maintaining security through the user's existing password knowledge.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If a requester-provided password is used to encrypt the recovered private key, then security is enhanced and accessibility is improved, but the system must verify and process the user-provided credentials

Engineering Contradiction:
Improvesecurity levelVSAvoidpassword verification process
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The user's password is collected and used during the key recovery process itself, rather than requiring separate verification steps. The system processes the user-provided password to encrypt the recovered key, combining verification and encryption in a single integrated operation that minimizes additional complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9137017B2Key recovery mechanism
Publication Date: 2015.09.15 RED HAT INC
  • US9137017B2 patent drawing
  • US9137017B2 patent drawing
  • US9137017B2 patent drawing

AI summary

A method and system for key recovery for a private key of a digital certificate for a client.