Decentralized Data Search with Encrypted Peer Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for searching, finding, reproducing, and exporting electronic data across decentralized systems are inefficient and insecure, particularly in global enterprises, leading to productivity losses and significant costs due to reliance on central data processing systems that are vulnerable to attacks and require extensive maintenance and adaptation.

Innovation Solution

A method involving encrypted queries between systems with authentication and secure data transmission using HTTPS and public key infrastructure, allowing secure searching, finding, reproducing, and exporting of electronic data across systems without a central organizational structure, ensuring secure and efficient data access and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a central data processing system is used to manage and search electronic data across multiple systems, then data access and management become simplified, but the system becomes vulnerable to attacks, requires extensive maintenance and adaptation, and loses reliability

Engineering Contradiction:
Improvedata access and managementVSAvoidsystem security and availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the centralized data management system into multiple independent peer systems that each maintain their own data locally. Instead of one central server, the functionality is segmented across several nodes that can independently operate and search their own data stores, eliminating the single point of failure while maintaining operational simplicity through standardized communication protocols

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces encrypted communication protocols and authentication mechanisms as intermediaries between peer systems. These security layers enable simplified data access across the network while maintaining reliability through secure, authenticated interactions that prevent unauthorized access and attacks on the distributed architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encrypted queries and authentication protocols are implemented between systems, then data security is enhanced, but communication overhead and processing time increase

Engineering Contradiction:
Improvedata securityVSAvoidquery processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication and encryption setup during system initialization and connection establishment. Security credentials and encryption keys are exchanged and configured in advance, so that during actual data queries, the systems can communicate efficiently with already-established secure channels, minimizing the time penalty of security protocols

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs asymmetric encryption (public-key cryptography) where systems exchange public keys rather than maintaining continuous symmetric encryption sessions. This parameter change in the encryption approach reduces computational overhead during query operations while maintaining strong security, as public key exchange requires minimal processing compared to continuous symmetric key management

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9450948B2Method for securely searching, finding, reproducing, recovering, and/or exporting of electronic data
Publication Date: 2016.09.20 ARTEC COMP
  • US9450948B2 patent drawing
  • US9450948B2 patent drawing

AI summary

A method for securely searching, finding, reproducing, recovering, and/or exporting electronic data from at least two systems which can be found in a network and which are organized in a functionally identical and decentralized manner. The individual systems include a system certificate and a corresponding serial number by the manufacturer and can carry out an authentication process using said system certificate and serial number. Information is provided on user authorizations between the systems using configuration tables which are stored on each of the systems. A maximum level of security is ensured by combining cryptographic methods and the mutual authentication of the involved systems. A user interface is provided for the user, wherein the user receives a pre-selection of the requested electronic data in the user interface and can then mark the pre-selection for further processing.