Authentication Service Token Dispersal for Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems lack secure and efficient methods for ensuring the authenticity of both users and service providers in electronic commerce transactions, particularly in ensuring data privacy and preventing unauthorized access or repudiation of transactions.
Innovation Solution
A centralized authentication system that uses tokens to authenticate users and service providers through a mutual authentication process, generating a unique data container identifier based on user and service provider IDs, and dispersing data across multiple storage locations to ensure secure and anonymous access, while preventing unauthorized access and repudiation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication systems are used, then authentication can be performed, but data privacy cannot be ensured and unauthorized access may occur
Solution Approach 1:
The system segments data storage by dispersing data across multiple storage locations rather than storing it in a single centralized location. Each location holds only a portion of the data, and the complete data can only be reconstructed when all locations are accessed together. This segmentation prevents unauthorized access to complete data even if some storage locations are compromised.
Solution Approach 2:
The patent introduces an intermediary authentication service that acts as a mediator between users and service providers. This service verifies credentials without exposing sensitive data, using cryptographic protocols to validate authentication tokens and generate access codes without revealing underlying personal information or data contents.
2Productivity
If centralized data storage is used, then data access is efficient, but unauthorized access and repudiation risks increase
Solution Approach 1:
Data is divided into multiple segments and stored at different locations. The system maintains efficient access by using cryptographic keys and access codes that can quickly locate and retrieve the necessary data segments without requiring physical inspection of all storage locations, thus balancing efficiency with security.
Solution Approach 2:
The system changes the parameter of data storage from centralized to distributed across multiple locations. This transformation fundamentally alters the security model by ensuring that no single location contains complete data, thereby preventing unauthorized access and repudiation while maintaining access efficiency through cryptographic mechanisms.
3Ease of operation
If simple authentication methods are used, then ease of operation is improved, but authentication security deteriorates
Solution Approach 1:
The authentication service operates autonomously, automatically verifying credentials and generating access codes without requiring manual intervention. Users simply present their authentication tokens, and the system self-service completes the verification process using cryptographic protocols, maintaining both simplicity and security.
Solution Approach 2:
The authentication service acts as an intermediary that handles the complex cryptographic verification processes, shielding users from complexity. Users only need to interact with the simple interface of presenting their token, while the intermediary service manages the sophisticated security protocols in the background.
4Device complexity
If data is stored in single location, then storage simplicity is improved, but data privacy and security are compromised
Solution Approach 1:
The storage system is segmented into multiple independent locations, each holding only a fragment of the complete data. This segmentation increases physical distribution complexity but reduces logical complexity through standardized cryptographic access mechanisms that automatically locate and assemble data fragments.
Solution Approach 2:
The system transitions from single-location storage to multi-location distributed storage, adding a spatial dimension to data storage. This dimensional change is managed through cryptographic indexing and access codes that map logical data requests to physical storage locations across the distributed network.
Data Source
AI summary
A method includes authenticating a party based on presentation of a token by the party.


