Trust Engine for Cloud Data Security via Key Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic systems are vulnerable to user-dependent security breaches, as private keys and biometric data are often stored insecurely, leading to risks of loss, theft, and compromise, especially in mobile environments.
Innovation Solution
A cryptographic system that employs a trust engine with server-centric keys, where cryptographic keys and authentication data are stored securely on a server, allowing users to access cryptographic functions without releasing the private keys, and utilizes data splitting and encryption to ensure security across multiple geographically remote locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If private keys are stored on user devices for cryptographic operations, then cryptographic functions can be performed locally, but security is compromised due to user-dependent storage vulnerabilities
Solution Approach 1:
The patent extracts the private key storage function from the user device and relocates it to a secure server environment. The trust engine on the server performs cryptographic operations using stored private keys without exposing the keys to users, eliminating the security vulnerability of local key storage while maintaining cryptographic functionality.
Solution Approach 2:
The patent introduces a trust engine as an intermediary between users and cryptographic operations. This mediator handles all private key operations on the server side, allowing users to perform cryptographic functions locally through encrypted communications without directly accessing or storing private keys, thus resolving the contradiction between local operation capability and security.
2Adaptability or versatility
If users store private keys locally for mobile access, then cryptographic functions are accessible on multiple devices, but key loss or theft risk increases
Solution Approach 1:
The patent removes private key storage from mobile devices and centralizes it on secure servers. Users can access cryptographic functions from multiple devices through the trust engine without having private keys stored locally, enabling mobile versatility while eliminating the risk of key loss or theft associated with local storage.
Solution Approach 2:
The patent allows users to access cryptographic functionality from multiple devices by establishing encrypted communication channels to the server, rather than copying private keys to each device. This enables mobile access versatility while maintaining security, as the private key exists in only one secure location.
3Reliability
If cryptographic keys are frequently reissued to maintain security, then security is improved, but key management complexity and cost increase
Solution Approach 1:
The patent merges key management operations into a centralized trust engine on the server. This consolidation allows for automated key lifecycle management including generation, storage, rotation, and revocation, reducing the complexity and cost of frequent key reissuance while maintaining or improving security through centralized control.
Data Source
AI summary
A secure data parser is provided that may be integrated into any suitable system for securely storing data in and communicating data with cloud computing resources. The secure data parser parses data and then splits the data into multiple portions that are stored or communicated distinctly. Encryption of the original data, the portions of data, or both may be employed for additional security.


