Cryptographic Secret Splitting and Encryption for Secure Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securely storing and authenticating cryptographic keys and passwords are inconvenient, as they often require human operators to simultaneously provide components or shares, and are vulnerable to unauthorized access if physical media like paper or USB sticks are stolen.

Innovation Solution

A system and method that splits a cryptographic secret into multiple shares, encrypts each share, and distributes them to different share-holders, allowing only the combining computing system to decrypt and authenticate them, ensuring secure regeneration of the key without the need for simultaneous operator input and protecting against unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the password or second cryptographic key is stored on physical media such as paper, smart cards, or USB sticks for human operators to provide, then the system allows manual authentication, but the unauthorized party can steal these media and regenerate the second cryptographic key

Engineering Contradiction:
Improvemanual authenticationVSAvoidsecurity against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the second cryptographic key into multiple components or shares, which are distributed to different human operators. Each operator holds only a portion of the key, making it impossible for any single operator to regenerate the complete key alone. This segmentation eliminates the security vulnerability of storing the entire key on physical media while maintaining manual authentication capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cryptographic system as an intermediary that manages the key components and their combination. Instead of directly storing and transmitting the complete key on physical media, the system uses cryptographic protocols to distribute shares and reconstruct the key only when authorized combinations of operators provide their shares simultaneously, adding a layer of security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the components or shares of the second cryptographic key are distributed to multiple human operators for simultaneous provision, then the security against single-point compromise is improved, but the inconvenience of requiring simultaneous operator input increases

Engineering Contradiction:
Improvesecurity against single-point compromiseVSAvoidconvenience of key regeneration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic threshold mechanisms where the required number of operator shares for key regeneration can be adjusted based on security policies and operational needs. The system can adapt between requiring all operators to be present or allowing a subset, providing flexibility that balances security requirements with operational convenience in different scenarios.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The cryptographic system automatically manages the collection, verification, and combination of operator shares without requiring manual coordination. The system handles the complex cryptographic operations of validating shares and reconstructing the key, reducing the operational burden on human operators while maintaining the security benefits of multi-operator involvement.

Inventive Principle:
Principle #25Self-service

3Device complexity

If the second cryptographic key is encrypted using a single encryption key for distribution to share-holders, then the encryption process is simplified, but the risk of key compromise increases if the encryption key is stolen

Engineering Contradiction:
Improveencryption processVSAvoidrisk of key compromise
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the encryption key into multiple components and uses different encryption keys for different shares of the second cryptographic key. Each share is encrypted with a unique key, so compromise of one encryption key does not expose other shares. This segmentation maintains manageable encryption processes while significantly reducing the risk of complete key compromise.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11777740B1Systems and methods for maintaining confidentiality, integrity, and authenticity of the last secret
Publication Date: 2023.10.03 WELLS FARGO BANK NA
  • US11777740B1 patent drawing
  • US11777740B1 patent drawing
  • US11777740B1 patent drawing

AI summary

A method for securely sharing and authenticating a last secret can include splitting a secret into a first split and a second split, the secret comprising a cryptographic element and controlling access to a first key, the secret comprising at least one of a password, a second key, and a tokenized value, and the first key controlling access to a secure computing system, encrypting the first split by an encryption key established between the dealer computing system and the combining computing system, encrypting the second split by the encryption key established between the dealer computing system and the combining computing system, transmitting the encrypted first split to a first share-holder, transmitting the encrypted second split to a second share-holder, designcrypting the encrypted first split, and designcrypting the encrypted second split.