Application Key Hashing for Secure Targeted Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information processing technologies require key information for mutual authentication, which can lead to secure communication but necessitate key information sharing among targets, posing challenges in ensuring secure processes without unauthorized access.

Innovation Solution

An information processing apparatus and method that generates second key information based on first key information acquired from an application, retains specific information to identify target applications, and determines whether an accessing application is the target application before performing processes, thereby ensuring secure and targeted information processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mutual authentication is performed using shared key information, then secure communication can be realized, but key information must be shared among authentication targets which compromises security

Engineering Contradiction:
Improvesecure communicationVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication verification function from the key information itself. Instead of directly using shared key information for authentication, the system generates authentication verification information (hash values) from the key information and uses only this extracted verification data for mutual authentication. This allows secure communication without requiring other parties to possess the actual key information, thereby eliminating the security compromise of key sharing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces authentication verification information as an intermediary between the key information and the authentication process. This intermediary element (hash value) enables mutual authentication without exposing the actual key information to other parties. The verification information acts as a mediator that proves possession of the key information without revealing the key information itself, thus maintaining security while enabling secure communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If key information is shared for authentication, then authentication can be performed, but the security of the key information is compromised

Engineering Contradiction:
Improveauthentication capabilityVSAvoidkey information security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts only the necessary authentication verification capability from the key information by generating hash values. This extracted verification information enables authentication operations without requiring other parties to hold the actual key information, thus maintaining key information security while preserving authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent transforms the key information into a different parameter form (hash value) that maintains the essential authentication function but changes the security characteristics. The transformed parameter (authentication verification information) can be safely shared for authentication purposes without compromising the original key information security, as the transformation is one-way and irreversible.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10594691B2Information processing apparatus, information processing method, and program
Publication Date: 2020.03.17 SONY GROUP CORP
  • US10594691B2 patent drawing
  • US10594691B2 patent drawing
  • US10594691B2 patent drawing

AI summary

Provided is an information processing apparatus including: a processing unit configured to selectively perform a process using information acquired from an application. The processing unit generates second key information based on first key information when the first key information is acquired from an application, retains specific information for specifying a target application on which a process is to be performed, when the first key information is acquired, determines whether an accessing application is the target application based on the specific information when being accessed by the application after the specific information is retained, performs a process based on information acquired from the accessing application and the second key information when the application is determined to be the target application, and refrains from performing a process using information acquired from the accessing application when the application is determined not to be the target application.