Database Security via Biometric Scrambler Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing database security management technologies lack multilevel authorization provisioning, are vulnerable to cyberattacks due to compromised single-sign-on (SSO) credentials and decryption keys, and fail to effectively secure sensitive data.

Innovation Solution

A system that uses data scrambling in conjunction with encryption and SSO credentials, employing biometric features like fingerprints and location coordinates to generate a descrambler key, which is self-destructed upon unauthorized access attempts, ensuring secure data access and relocation of sensitive data to more secure databases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single-sign-on (SSO) credentials and decryption keys are used to secure database access, then ease of operation is improved, but reliability deteriorates due to vulnerability to cyberattacks and credential compromise

Engineering Contradiction:
Improveease of database accessVSAvoidsecurity against cyberattacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into multiple independent components: SSO credential verification, biometric authentication (fingerprint, facial recognition), location-based verification, and device identification. Each component operates independently and contributes to the overall security decision, preventing single-point failure and reducing vulnerability to credential compromise while maintaining ease of operation through automated multi-factor verification.

Inventive Principle:
Principle #1Segmentation

2Reliability

If data encryption is used to protect sensitive information, then reliability is improved, but device complexity increases due to key management requirements

Engineering Contradiction:
Improvedata protection securityVSAvoidkey management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary encryption key management system that acts as a mediator between users and encrypted data. This system automatically handles key generation, distribution, rotation, and revocation based on user credentials and biometric verification. The intermediary layer abstracts complex key management operations from end users, maintaining high security while reducing perceived complexity for operational users.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multilevel authorization provisioning is implemented, then reliability is improved through enhanced security, but device complexity increases due to multiple authentication factors

Engineering Contradiction:
Improveauthorization securityVSAvoidauthentication system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authorization provisioning where the required authentication factors and authorization levels are not fixed but adapt based on contextual risk assessment. The system dynamically adjusts authentication requirements based on user behavior patterns, location, device status, and sensitivity of accessed data. This dynamic approach achieves high security reliability while maintaining operational simplicity by automatically adjusting complexity only when necessary based on real-time conditions.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11316658B2System and method for securing a database by scrambling data
Publication Date: 2022.04.26 BANK OF AMERICA CORP
  • US11316658B2 patent drawing
  • US11316658B2 patent drawing
  • US11316658B2 patent drawing

AI summary

A system is configured for managing security of a database associated with an organization. A fingerprint of an authorized user is captured. The data is scrambled using a scrambling technique. A list of users authorized to access the data is received from the user. A descrambler key corresponding to the scrambling technique is generated. The descrambler key is associated with fingerprints and predetermined location coordinates of authorized users. The descrambler key is configured to descramble the data when authorized users attempt to access the data using their fingerprints at their corresponding location coordinates. The scrambled data is encrypted. The system determines whether a particular user attempting to access the data is authorized to access the data by validating a fingerprint and location coordinates of the particular user. If the particular user is authenticated, the descrambler key descrambles the data. The particular user is allowed to access the data.