Decoupled Data Processing Authentication for Sensitive Operations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection methods for sensitive computer data, such as those in the medical field, face challenges in providing sufficient security without being overly constraining, especially for users with itinerant occupations who cannot carry necessary authentication equipment.
Innovation Solution
A data processing method that decouples the definition of operations from their execution, requiring strong authentication only for the confirmation phase, ensuring that only authorized users can execute sensitive operations by verifying relationships between users during different sessions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If strong authentication is used to protect sensitive data, then security level is improved, but user convenience deteriorates due to the need to carry authentication equipment
Solution Approach 1:
The patent segments the authentication process into two distinct phases: a first phase where a user defines processing operations with simple authentication, and a second phase where another user confirms these operations with strong authentication. This segmentation allows the system to maintain high security requirements for data processing while enabling users to perform initial operations without carrying authentication equipment, thus resolving the contradiction between security and convenience.
2Ease of operation
If simple authentication is used for data access, then user convenience is improved, but security level deteriorates
Solution Approach 1:
The patent applies preliminary action by allowing users to define and queue processing operations in advance using simple authentication, without immediately executing them. The actual execution of these operations is deferred to a later confirmation phase where strong authentication is required. This preliminary definition step enables user convenience while the subsequent strong authentication step ensures security, resolving the contradiction between ease of operation and security level.
3Reliability
If strong authentication is required for all operations, then security level is improved, but operational efficiency deteriorates
Solution Approach 1:
The patent segments the authentication burden by applying strong authentication only to the confirmation phase of data processing operations, while the initial definition phase uses simple authentication. This segmentation reduces the frequency and scope of strong authentication requirements, thereby maintaining security level while improving operational efficiency by allowing faster, less restrictive access for operation definition and review.
Solution Approach 2:
By allowing operations to be defined in advance with simple authentication and then confirmed later with strong authentication, the patent eliminates the need to require strong authentication for every single operation. This preliminary definition approach improves operational efficiency by reducing authentication overhead while maintaining security through the required confirmation step.
Data Source
AI summary
A method and apparatus are provided for processing data. The method includes a step of receiving, during a first communication session established with said server, a request formulated by a first user defining at least one processing operation to be executed on first data, and a step of executing said processing operation on said first data, during a second communication session established with said server after said first session for a second user. The step of executing is applied on condition that the second user has been authenticated via a strong authentication method during the second session and that a relationship between the first and second users has been verified.


