DASA Database Securitization for Digital Communications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securing digital communications and access, particularly in password managers, rely heavily on static master passwords, which are vulnerable to social engineering, brute force attacks, and malware, and require trust in third-party cloud services, leading to inadequate authentication and authorization.
Innovation Solution
A system utilizing a real or virtual master distributed auto-synchronous array (DASA) database with multiple partial DASA databases for secure data storage and retrieval, enabling bi-directional data transmission, authentication, validation, and access control through a set of computing operations that include encryption and decryption, ensuring secure communication and access across devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static master passwords are used for authentication, then ease of operation is improved, but reliability of security is worsened due to vulnerability to social engineering, brute force attacks, and malware
Solution Approach 1:
The patent transitions from static passwords to dynamic authentication credentials that change over time. The system generates temporary authentication tokens and credentials that are valid only for specific time windows and transactions, making them useless for replay attacks and significantly harder to compromise through traditional means while maintaining user convenience through automated token management.
Solution Approach 2:
The system performs preliminary authentication and validation actions before granting access to sensitive operations. Multiple layers of authentication are executed in advance, including device validation, credential verification, and authorization checks, ensuring that security measures are already in place before critical operations occur.
2Ease of operation
If third-party cloud services are trusted for data storage, then ease of operation is improved, but reliability of security is worsened due to data breaches and compromised private data
Solution Approach 1:
The patent segments authentication and security credentials into isolated, device-specific containers that cannot be accessed by third parties. Each device maintains its own secure enclave with dedicated cryptographic keys and credentials, preventing centralized data breaches from compromising multiple devices simultaneously and eliminating the need to trust third-party cloud providers with sensitive authentication data.
Solution Approach 2:
The system introduces cryptographic intermediaries and trusted execution environments that mediate between users and cloud services. These intermediaries handle authentication and encryption operations locally on user devices, acting as a security buffer that prevents direct exposure of sensitive data to potentially compromised cloud infrastructure while still enabling cloud-based functionality.
3Productivity
If password managers are used to store multiple passwords, then productivity is improved, but reliability of security is worsened due to single point of failure with master password
Solution Approach 1:
The patent divides the password management system into distributed, device-specific security zones. Instead of relying on a single centralized password manager protected by one master password, each device maintains its own isolated credential store with independent authentication mechanisms. This segmentation ensures that compromise of one device does not affect others and eliminates the single point of failure.
Solution Approach 2:
The system changes the fundamental parameters of password management by transitioning from static master passwords to dynamic, context-aware authentication credentials. Credentials are generated with specific time validity periods, scope limitations, and revocation capabilities, transforming password management from a centralized vulnerability into a distributed, adaptive security system that maintains productivity while improving resilience.
Data Source
AI summary
One more devices and/or access control systems are described that securitize data and data transmissions using three sets of computing operations including authentication, validation, and securitization that allows or denies access to the data and/or the data transmissions. The system includes securitization of signals between one or more secure master and/or partial DASA databases for various user devices. Specific methods and devices for securing (primarily digital and normally two-way) communications using applications that offer the combination of securing communications from user devices with reader devices, are also is provided.


