Trust Engine for Cloud Data Security via Key Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cryptographic systems are vulnerable to user-dependent security breaches, as private keys and biometric data are often stored insecurely, leading to risks of loss, theft, and compromise, especially in mobile environments.

Innovation Solution

A cryptographic system that employs a trust engine with server-centric keys, where cryptographic keys and authentication data are stored securely on a server, allowing users to access cryptographic functions without releasing the private keys, and utilizes data splitting and encryption to ensure security across multiple geographically remote locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If private keys are stored on user devices for cryptographic operations, then cryptographic functions can be performed locally, but security is compromised due to user-dependent storage vulnerabilities

Engineering Contradiction:
Improvelocal cryptographic operation capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the private key storage function from the user device and relocates it to a secure server environment. The trust engine on the server performs cryptographic operations using stored private keys without exposing the keys to users, eliminating the security vulnerability of local key storage while maintaining cryptographic functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a trust engine as an intermediary between users and cryptographic operations. This mediator handles all private key operations on the server side, allowing users to perform cryptographic functions locally through encrypted communications without directly accessing or storing private keys, thus resolving the contradiction between local operation capability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If users store private keys locally for mobile access, then cryptographic functions are accessible on multiple devices, but key loss or theft risk increases

Engineering Contradiction:
Improvemobile access capabilityVSAvoidkey loss or theft risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent removes private key storage from mobile devices and centralizes it on secure servers. Users can access cryptographic functions from multiple devices through the trust engine without having private keys stored locally, enabling mobile versatility while eliminating the risk of key loss or theft associated with local storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent allows users to access cryptographic functionality from multiple devices by establishing encrypted communication channels to the server, rather than copying private keys to each device. This enables mobile access versatility while maintaining security, as the private key exists in only one secure location.

Inventive Principle:
Principle #26Copying

3Reliability

If cryptographic keys are frequently reissued to maintain security, then security is improved, but key management complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges key management operations into a centralized trust engine on the server. This consolidation allows for automated key lifecycle management including generation, storage, rotation, and revocation, reducing the complexity and cost of frequent key reissuance while maintaining or improving security through centralized control.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9064127B2Systems and methods for securing data in the cloud
Publication Date: 2015.06.23 SECURITY FIRST INNOVATIONS LLC
  • US9064127B2 patent drawing
  • US9064127B2 patent drawing
  • US9064127B2 patent drawing

AI summary

A secure data parser is provided that may be integrated into any suitable system for securely storing data in and communicating data with cloud computing resources. The secure data parser parses data and then splits the data into multiple portions that are stored or communicated distinctly. Encryption of the original data, the portions of data, or both may be employed for additional security.