Proof-of-work key wrapping with thresholding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic systems for controlling access to data rely solely on key possession, which is insufficient for sophisticated access control mechanisms that require considerations of time, computing resources, and device attributes, and often necessitate a separate trusted third party for verification, making the system complex and vulnerable.
Innovation Solution
Integration of a proof-of-work key wrapping mechanism that encrypts cryptographic keys, allowing recipient devices to derive the key without an unwrapping key, by configuring the encryption strength and hints as a computational puzzle that consumes specific computing resources, thereby eliminating the need for a third-party verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional cryptographic key possession is used for access control, then access simplicity is maintained, but access control sophistication is insufficient
Solution Approach 1:
The patent transforms the static key possession model into a dynamic proof-of-work model where access control is determined by computational parameters (work requirements, time constraints, resource verification) rather than simple key presence. This enables sophisticated access control policies while maintaining cryptographic security.
Solution Approach 2:
The system eliminates the need for external verification authorities by making the proof-of-work verification self-contained within the cryptographic protocol. The recipient device independently verifies the sender's computational work through mathematical validation, removing the need for complex third-party verification infrastructure.
2Reliability
If a separate trusted third party is added for verification, then verification reliability is improved, but system complexity increases and vulnerability increases
Solution Approach 1:
The patent extracts the verification function from external third parties and embeds it directly into the cryptographic proof-of-work mechanism. The mathematical structure of the proof-of-work itself provides verification, eliminating the need for separate verification authorities and reducing system complexity.
Solution Approach 2:
The patent introduces cryptographic proof-of-work as an intermediary that mediates between sender and recipient without requiring trusted third parties. The computational work and its verification serve as the intermediary mechanism that establishes trust through mathematical proof rather than institutional trust.
3Adaptability or versatility
If proof-of-work key wrapping is implemented, then access control sophistication is improved, but computing resource consumption increases
Solution Approach 1:
The patent implements proof-of-work with configurable work requirements that can be adjusted to achieve sufficient access control verification without excessive computational overhead. The system performs just enough computational work to verify device capabilities and enforce access policies, avoiding unnecessary resource consumption.
Solution Approach 2:
The proof-of-work requirements are dynamically adjusted based on the specific access control needs, device capabilities, and security policies. This allows the system to optimize computational resource consumption by adapting the work requirements to the actual security needs rather than using fixed high thresholds.
Data Source
AI summary
The technology disclosed herein provides a proof-of-work key wrapping system that uses key thresholding to cryptographically control data access. An example method may include: accessing a plurality of cryptographic key shares, wherein two or more of the plurality of cryptographic key shares enable access to content; selecting, by a processing device, a set of cryptographic attributes in view of a characteristic of a computing device; encrypting the plurality of cryptographic key shares to produce a plurality of wrapped key shares, wherein at least one of the plurality of cryptographic key shares is encrypted in view of the set of cryptographic attributes; and providing a wrapped key share of the plurality of wrapped key shares and at least one of the cryptographic attributes to the computing device, wherein the at least one cryptographic attribute facilitates deriving an access key from the plurality of wrapped key shares.


