Remote Private Key Security via Segmentation and Biometric Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security systems face challenges in securely accessing and managing private keys for encrypted data, particularly when compliance with varying jurisdictional regulations is required, and there is a risk of unauthorized access even for authorized individuals.

Innovation Solution

A method and system for remote private key security that generates a private key, encrypts data, and transmits the key and encrypted data to separate secure locations, allowing access only after confirming the identity of the individual using biometric information, ensuring the key is deleted from the original location and stored securely in a remote private key deposit and data center.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the private key is stored locally for easy access, then access convenience is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the private key into multiple parts and distributes them across different geographic locations. No single location holds the complete key, so even if one location is compromised, the full key cannot be reconstructed. This resolves the contradiction by maintaining accessibility (through distributed nodes) while enhancing security (through key fragmentation).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary mechanism where the private key is split and stored across multiple locations with specific access policies. An authorized user can retrieve the key by accessing multiple locations, but unauthorized access to any single location is insufficient. This intermediary structure balances convenience and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the private key is transmitted to a remote location for security, then security is improved, but access complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By segmenting the private key across multiple remote locations, the system achieves enhanced security without requiring a single complex centralized system. Each location stores a portion of the key, simplifying individual location design while the collective system provides robust security and manageable access procedures.

Inventive Principle:
Principle #1Segmentation

3Reliability

If biometric verification is implemented for key access, then unauthorized access prevention is improved, but authentication time increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs biometric verification in advance before allowing access to the private key. By requiring authentication beforehand, the system ensures that only authorized individuals can retrieve the key, preventing unauthorized access. The time investment is made upfront, enabling secure access when needed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11184335B1Remote private key security
Publication Date: 2021.11.23 ACRONIS INT
  • US11184335B1 patent drawing
  • US11184335B1 patent drawing
  • US11184335B1 patent drawing

AI summary

A method for remote private key security is described. The method may include generating a private key and may further include generating encrypted data by encrypting data using an encryption algorithm, wherein the data is stored at a first location and the private key is for the encrypted data. The method may also include transmitting the private key to a remote private key deposit at a second location. The method may additionally include transmitting the encrypted data to a remote data center at a third location. Moreover, the method may include permitting access to the private key at the remote private key deposit to an individual at the second location in response to confirming an identity of the individual present at the second location.