Cryptography Chip Identity Verification Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cryptographic keys are vulnerable to loss or compromise, leading to security risks and economic losses, as existing methods lack effective identity verification mechanisms to control access to encryption keys.

Innovation Solution

A cryptography chip with integrated storage for key and identity information verifies the identity of users requesting cryptographic operations, ensuring that only authorized users can perform operations using stored cryptographic keys, and preventing unauthorized access by rejecting unverified requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cryptographic keys are stored for use in cryptographic operations, then cryptographic functionality is enabled, but the keys become vulnerable to loss or compromise

Engineering Contradiction:
Improvecryptographic functionalityVSAvoidkey compromise risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the cryptographic system into separate components: a cryptography chip that stores and protects cryptographic keys, and a separate identity verification mechanism. This segmentation isolates the keys in a secure environment while enabling controlled access through identity verification, thus maintaining cryptographic functionality while reducing key compromise risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an identity verification mechanism as an intermediary between the user and the cryptographic keys. This intermediary layer verifies user identity before allowing access to cryptographic operations, preventing unauthorized key usage even if the key storage is compromised. The intermediary controls and limits access to the cryptographic functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If access control mechanisms are added to protect cryptographic keys, then security is improved, but system complexity increases

Engineering Contradiction:
Improveunauthorized accessVSAvoidsystem structure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges the identity verification functionality directly into the cryptography chip, combining what could be separate systems into a single integrated device. This merging reduces overall system complexity while maintaining security, as the identity verification and key protection work together within the same secure hardware environment.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The cryptography chip performs self-verification of user identity and automatically controls access to cryptographic operations without requiring external complex verification systems. The chip manages its own security protocols, key protection, and access control internally, reducing the need for additional external security infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3622665B1Cryptography chip with identity verification
Publication Date: 2021.07.28 ADVANCED NEW TECHNOLOGIES CO LTD
  • EP3622665B1 patent drawingFigure 1
  • EP3622665B1 patent drawingFigure 2
  • EP3622665B1 patent drawingFigure 3

AI summary

Disclosed herein are methods, systems, and apparatus, including computer programs encoded on computer storage media, for performing cryptographic operations subject to identity verification. One of the methods includes receiving, by a cryptography chip, a request to perform a requested cryptographic operation from a client including client identity information, wherein the cryptography chip includes a processing resource that performs cryptographic operations and a storage resource that stores key information used in the cryptographic operations, and identity information associated with clients that are permitted to request cryptographic operations; determining, by the cryptography chip, that the client identity information is associated with one of the clients that are permitted to request cryptographic operations; and performing, by the cryptography chip, the requested cryptographic operation based on the key information stored in the storage resource.