Three-Element-Core Mechanism for Secure Key Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for securely storing and sharing confidential information face challenges with clumsy and insecure key exchange processes, particularly with asymmetric encryption, due to weak or absent identity verification, limiting their adoption and effectiveness.

Innovation Solution

A tightly coupled, distributed three-element-core mechanism comprising key masters, registries, and cloud lockboxes, which integrates with various user-facing applications to establish unique identities, manage encryption keys, and provide secure data exchange, while minimizing exposure to system administrators and supporting multiple security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric encryption is used to protect information, then security is improved, but the key exchange process becomes clumsy and complex

Engineering Contradiction:
ImprovesecurityVSAvoidkey exchange process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted third party (TTP) that acts as an intermediary to manage key pairs and facilitate secure key exchange. The TTP generates asymmetric key pairs for users, verifies their identities, and enables them to exchange encrypted data without directly sharing private keys. This mediator approach resolves the complexity of direct asymmetric key exchange while maintaining strong security through centralized key management and identity verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If identity verification is weak or absent in key exchange, then the process is simpler, but security effectiveness degrades

Engineering Contradiction:
Improvekey exchange simplicityVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary identity verification through the trusted third party before key exchange occurs. The TTP verifies user identities, issues digital certificates, and establishes trust relationships in advance. This preliminary action ensures that only authenticated users can participate in key exchange, maintaining security effectiveness while keeping the actual exchange process simple for end users who don't need to perform complex verification themselves.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If private keys are not shared for asymmetric encryption, then security is maintained, but the solution becomes point-to-point and less adaptable

Engineering Contradiction:
ImprovesecurityVSAvoidencryption solution flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal key management system where the trusted third party serves multiple functions: generating key pairs for individual users, enabling peer-to-peer encryption, facilitating group communications, and supporting various authentication scenarios. The system allows private keys to remain secure while enabling flexible multi-party interactions through the TTP's coordination, thus achieving both security and adaptability across different use cases.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9973484B2System and method for securely storing and sharing information
Publication Date: 2018.05.15 CROWDSTRIKE
  • US9973484B2 patent drawing
  • US9973484B2 patent drawing
  • US9973484B2 patent drawing

AI summary

The present application generally relates to systems, devices, and methods to conduct the secure exchange of encrypted data using a three-element-core mechanism consisting of the key masters, the registries and the cloud lockboxes with application programming interfaces providing interaction with a wide variety of user-facing software applications. Together the mechanism provides full lifecycle encryption enabling cross-platform sharing of encrypted data within and between organizations, individuals, applications and devices. Control of the private key required for decryption is maintained by the information owner. More specifically, the mechanism establishes unique identities, verifies authenticity, generates and securely exchanges asymmetric encryption key pairs, encrypts, transmits, receives and decrypts data to/from cloud lockboxes; creates and appends metadata specific to the applications and retrieves and/or act upon metadata.