Secure Community Server Key Recovery Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing key recovery systems face security vulnerabilities when recovery keys are stored on separate devices, as users lack control over the security exposure of these devices and may be compromised if they fail to meet security criteria.

Innovation Solution

A method involving a secure community management system where recovery keys are distributed and managed by a secure community server, ensuring that only compliant devices receive and hold key portions, with encryption and revocation mechanisms to maintain security, and users can discard sensitive information to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If recovery keys are stored on separate devices, then key recovery capability is provided, but security control is lost because users cannot monitor the security exposure of those devices

Engineering Contradiction:
Improvekey recovery capabilityVSAvoidsecurity exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A secure community server acts as an intermediary between the user and the holder's device. The server receives, verifies, and stores the recovery key securely, eliminating direct trust dependency on the holder's device security. The server mediates the recovery process by validating security criteria and controlling key distribution, thus resolving the contradiction between providing recovery capability and maintaining security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If recovery keys are stored on holder's device, then key recovery is enabled, but the device may be compromised if it fails to meet security criteria

Engineering Contradiction:
Improvekey recovery accessibilityVSAvoiddevice security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary security verification of the holder's device before allowing recovery key storage. The secure community server checks whether the device meets predetermined security criteria in advance. Only devices that pass the security check are permitted to receive and store recovery keys, thus preventing compromised devices from accessing recovery functionality while maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If users send recovery key to holder's device, then recovery capability is provided, but users lack control over security exposure of the holder's device

Engineering Contradiction:
Improverecovery key distributionVSAvoidsecurity exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The secure community server implements a feedback mechanism that continuously monitors the holder's device security status. The server receives updates about the device's security criteria compliance and adjusts recovery key access accordingly. If the device fails to meet security criteria, the server automatically revokes access or prevents key distribution, providing users with indirect control over security exposure while maintaining versatile recovery key distribution capability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3367609B1Recovering a key in a secure manner
Publication Date: 2020.11.04 BLACKBERRY LTD
  • EP3367609B1 patent drawingFigure 1~2
  • EP3367609B1 patent drawingFigure 3
  • EP3367609B1 patent drawingFigure 4~5

AI summary

The present disclosure describes methods and systems, including computer-implemented methods, computer program products, and computer systems, for distributing recovery keys. One method includes: transmitting, from a first user device to a secure community server, a key distribution request, wherein the key distribution request identifies a second user device, and the first user device and the second user device are members of a same secure community managed by the secure community server; transmitting a first portion of a recovery key to secure community server for forwarding to the second user device; transmitting a second portion of the recovery key to the secure community server; and discarding the first portion and the second portion of the recovery key at the first user device.