Proof-of-work key wrapping with thresholding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems for controlling access to data rely solely on key possession, which is insufficient for sophisticated access control mechanisms that require considerations of time, computing resources, and device attributes, and often necessitate a separate trusted third party for verification, making the system complex and vulnerable.

Innovation Solution

Integration of a proof-of-work key wrapping mechanism that encrypts cryptographic keys, allowing recipient devices to derive the key without an unwrapping key, by configuring the encryption strength and hints as a computational puzzle that consumes specific computing resources, thereby eliminating the need for a third-party verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional cryptographic key possession is used for access control, then access simplicity is maintained, but access control sophistication is insufficient

Engineering Contradiction:
Improveaccess control sophisticationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transforms the static key possession model into a dynamic proof-of-work model where access control is determined by computational parameters (work requirements, time constraints, resource verification) rather than simple key presence. This enables sophisticated access control policies while maintaining cryptographic security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system eliminates the need for external verification authorities by making the proof-of-work verification self-contained within the cryptographic protocol. The recipient device independently verifies the sender's computational work through mathematical validation, removing the need for complex third-party verification infrastructure.

Inventive Principle:
Principle #25Self-service

2Reliability

If a separate trusted third party is added for verification, then verification reliability is improved, but system complexity increases and vulnerability increases

Engineering Contradiction:
Improveverification reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the verification function from external third parties and embeds it directly into the cryptographic proof-of-work mechanism. The mathematical structure of the proof-of-work itself provides verification, eliminating the need for separate verification authorities and reducing system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic proof-of-work as an intermediary that mediates between sender and recipient without requiring trusted third parties. The computational work and its verification serve as the intermediary mechanism that establishes trust through mathematical proof rather than institutional trust.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If proof-of-work key wrapping is implemented, then access control sophistication is improved, but computing resource consumption increases

Engineering Contradiction:
Improveaccess control sophisticationVSAvoidcomputing resource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent implements proof-of-work with configurable work requirements that can be adjusted to achieve sufficient access control verification without excessive computational overhead. The system performs just enough computational work to verify device capabilities and enforce access policies, avoiding unnecessary resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The proof-of-work requirements are dynamically adjusted based on the specific access control needs, device capabilities, and security policies. This allows the system to optimize computational resource consumption by adapting the work requirements to the actual security needs rather than using fixed high thresholds.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11303437B2Proof-of-work key wrapping with key thresholding
Publication Date: 2022.04.12 RED HAT INC
  • US11303437B2 patent drawing
  • US11303437B2 patent drawing
  • US11303437B2 patent drawing

AI summary

The technology disclosed herein provides a proof-of-work key wrapping system that uses key thresholding to cryptographically control data access. An example method may include: accessing a plurality of cryptographic key shares, wherein two or more of the plurality of cryptographic key shares enable access to content; selecting, by a processing device, a set of cryptographic attributes in view of a characteristic of a computing device; encrypting the plurality of cryptographic key shares to produce a plurality of wrapped key shares, wherein at least one of the plurality of cryptographic key shares is encrypted in view of the set of cryptographic attributes; and providing a wrapped key share of the plurality of wrapped key shares and at least one of the cryptographic attributes to the computing device, wherein the at least one cryptographic attribute facilitates deriving an access key from the plurality of wrapped key shares.