Cryptographic Key Management via Trust Engine Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic systems are vulnerable to unauthorized access and key compromise due to user dependence, poor password management, and insecure storage of private keys, leading to security breaches and the need for frequent key management and reissuance.
Innovation Solution
A cryptographic system with a trust engine that stores cryptographic keys and user authentication data on a secure server, allowing users to access cryptographic functions without releasing the actual keys, using a data splitting and assembly process to secure data across multiple geographically remote locations, ensuring security and availability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If cryptographic keys are issued to users through their browser and stored on hard drives, then users can access cryptographic functions, but the keys become susceptible to compromise through unauthorized access and poor security practices
Solution Approach 1:
The patent extracts the private key from the user's control environment and stores it on a remote server. The key is issued to the user's browser but immediately transferred to and stored on a secure server, removing it from the vulnerable user environment where it could be compromised through poor security practices, brute-force attacks, or unauthorized access.
Solution Approach 2:
The patent introduces a server as an intermediary between the key generation authority and the user. The server acts as a trusted mediator that holds and manages the private key on behalf of the user, providing cryptographic functions without exposing the key to the user's potentially insecure environment.
2Adaptability or versatility
If users store private keys on mobile computing devices for mobile access, then cryptographic functions are available mobile, but the keys become vulnerable to loss, theft, and compromise
Solution Approach 1:
The patent extracts the private key from mobile devices and stores it on a remote server. Instead of storing keys locally on mobile devices where they are vulnerable to physical loss, theft, or device compromise, the key is issued to the mobile device's browser but immediately transferred to and stored on a secure server, eliminating the vulnerability while maintaining mobile access capability.
3Reliability
If cryptographic keys are stored on archived or backup computer systems, then data redundancy is provided, but key migration occurs creating security breaches
Solution Approach 1:
The patent introduces a centralized server as an intermediary that manages key storage and distribution. Instead of allowing keys to migrate through multiple backup systems and archiving locations where security breaches can occur, the server acts as a single secure repository that provides controlled access to keys, eliminating unauthorized migration while maintaining data availability.
4Ease of operation
If simple login and password access is provided for key access, then ease of access is improved, but adequate security is not provided
Solution Approach 1:
The patent introduces a server as an intermediary that implements robust authentication and access control mechanisms. Instead of relying on simple client-side login and password systems that are vulnerable to compromise, the server mediates all key access requests with secure authentication protocols, providing both ease of access and adequate security.
Data Source
AI summary
A common interface for managing cryptographic keys is provided. A request to manage a cryptographic key may be received in a first interface format, translated to a common interface format, and then executed remotely from the first interface. Return arguments may then be translated from the common interface format to a format compatible with the first interface and communicated securely to the first interface. The cryptographic keys may be used in connection with a secure data parser that secures data by randomly distributing data within a data set into two or more shares.


