Split Key Authentication on Blockchain
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud storage systems are vulnerable to single point failures and lack flexible user control over proxy re-encryption, especially in blockchain environments, where decentralized access and secure authentication are crucial but challenging due to the absence of a central authority, and existing authentication methods rely on passwords, which are cumbersome and insecure for multi-user scenarios.
Innovation Solution
A blockchain platform system that enables proxy re-encryption, secure multi-user smart contracts, and passwordless authentication using Shamir's secret sharing and split-key mechanisms, allowing for dynamic encryption, secure file sharing, and independent audit capabilities, while ensuring security against chosen ciphertext attacks and distributed denial-of-service attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If centralized authorities are used to control cloud storage access, then access management is simplified, but the system becomes vulnerable to single point failures and permanent data loss
Solution Approach 1:
The patent segments the centralized authority's control function by distributing access management across multiple decentralized nodes in a blockchain network. Each node maintains a copy of the access control ledger, eliminating the single point of failure while preserving coordinated access management through consensus mechanisms.
Solution Approach 2:
The patent introduces smart contracts as intermediary automated agreements that mediate access control decisions between users and data storage. These self-executing contracts encode access policies and automatically enforce them without requiring centralized authority intervention, thereby distributing control while maintaining systematic access management.
2Ease of manufacture
If password-based authentication is used for multi-user smart wallets, then implementation is simple, but security is compromised and user burden increases
Solution Approach 1:
The patent segments the authentication credential into multiple cryptographic key shares distributed among different users or devices. Instead of relying on a single password, the system requires a threshold number of key shares to reconstruct the private key and authenticate, thereby enhancing security while maintaining simple enrollment through automated key generation and distribution.
Solution Approach 2:
The patent replaces the mechanical password-based authentication system with cryptographic key-based authentication using public-key infrastructure and threshold cryptography. This substitution eliminates the vulnerabilities of password sharing while providing secure multi-user access through mathematical proofs of authorization.
3Device complexity
If proxy re-encryption is implemented without flexible user control, then implementation is straightforward, but user autonomy over data sharing is limited
Solution Approach 1:
The patent implements dynamic proxy re-encryption where users can programmatically define and modify re-encryption policies through smart contracts. Access rights can be granted conditionally based on time, usage patterns, or other criteria, and these policies can be updated or revoked without system reconfiguration, providing flexible user control while maintaining manageable system complexity through automated enforcement.
4Adaptability or versatility
If traditional authentication methods are used in blockchain environments, then compatibility with existing systems is maintained, but security and auditability are insufficient for decentralized access
Solution Approach 1:
The patent introduces blockchain-based smart contracts as intermediaries that mediate authentication and access control between traditional systems and the decentralized blockchain environment. These contracts provide tamper-proof logging of all access events and authentication decisions, enabling reliable audit trails while maintaining compatibility with existing authentication infrastructures through standardized interfaces.
Data Source
AI summary
An approach is disclosed on a blockchain platform for authenticating clients. A public and private key is created at a client device. The private key into is split two or more parts. The split private key part is split into to two or more client devices including a first client device and a remaining client devices. Signing to authenticate a challenge to login using a partial key part occurs at the first client device. The challenge is sent to the remaining client devices wherein the remaining client devices that sequentially sign using short range wireless network connection and respond back to the challenge to login without a password.


