Apparatus and Method for Processing Fragmented Cryptographic Keys
A system includes a set of private key fragments distributed across a set of networked resources. Each private key fragment independently produces a fractional cryptographic result. A combination module on a designated networked resource combines a sufficient number of fractional cryptographic results to produce an operable cryptographic result. A method includes generating a set of private key fragments. The set of private key fragments is located across a set of networked resources. Fractional cryptographic results are produced at the set of networked resources. The fractional cryptographic results are combined to produce an operable cryptographic result.
1 . A system, comprising:
a plurality of private key fragments distributed across a plurality of networked resources, each private key fragment independently producing a fractional cryptographic result; and
a combination module on a designated networked resource to combine a sufficient number of fractional cryptographic results to produce an operable cryptographic result.
2 . The system of claim 1 wherein each networked resource accesses a common public key corresponding to the plurality of private key fragments.
3 . The system of claim 1 wherein each private key fragment is distributed to a different networked resource.
4 . The system of claim 1 wherein each private key fragment is generated at a different networked resource.
5 . The system of claim 1 wherein the complete private key corresponding to the plurality of private key fragments is never reconstituted.
6 . The system of claim 1 wherein the operable cryptographic result is utilized to access data.
7 . The system of claim 1 further comprising unique access controls for each private key fragment.
8 . A computer readable storage medium, comprising executable instructions to;
receive fractional cryptographic results from a plurality of private key fragments distributed across a plurality of networked resources; and
combine the fractional cryptographic results to produce an operable cryptographic result.
9 . The computer readable storage medium of claim 8 further comprising executable instructions to access a common public key corresponding to the plurality of private key fragments.
10 . The computer readable storage medium of claim 8 further comprising executable instructions to access data utilizing the operable cryptographic result.
11 . A method, comprising:
generating a plurality of private key fragments;
locating the plurality of private key fragments across a plurality of networked resources;
producing fractional cryptographic results at the plurality of networked resources;
combining the fractional cryptographic results to produce an operable cryptographic result.
12 . The method of claim 11 further comprising combining the operable cryptographic result with a public key to access data.
13 . The method of claim 11 wherein generating includes generating the plurality of private key fragments at the plurality of networked resources.
14 . The method of claim 11 wherein generating includes generating the plurality of private key fragments at a central networked resource and then distributing the plurality of private key fragments to the plurality of networked resources.
15 . The method of claim 11 further comprising protecting the plurality of private key fragments with access controls.