Decryption Key Segmentation for Face-to-Face Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing access to secret data, such as personal and business data, fail to ensure that data is disclosed only to authorized partners in a face-to-face manner, leading to potential unauthorized disclosure.

Innovation Solution

A system where a decryption key is pre-sent to an authorized partner's terminal and confirmed through proximity communication, ensuring that data can only be decrypted and accessed by the intended recipient in a face-to-face confirmation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is transmitted to multiple potential partners through communication networks, then data accessibility and convenience are improved, but security and control over authorized disclosure deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The decryption key is segmented into two separate parts: the first part is stored in the data holder's terminal, and the second part is stored in the disclosure partner's terminal. Both parts are necessary to decrypt the data, ensuring that even if one part is compromised, the data remains secure. This segmentation resolves the contradiction by maintaining security while enabling controlled accessibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary verification mechanism where the disclosure partner's terminal must verify its identity and authority before receiving the second key part. This intermediary step acts as a mediator that ensures only authorized partners can access the data, resolving the security concern while maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional access control methods are used without face-to-face confirmation, then operational convenience is improved, but the risk of unauthorized disclosure increases

Engineering Contradiction:
Improveoperational convenienceVSAvoidunauthorized disclosure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by pre-distributing the first part of the decryption key to authorized disclosure partners before actual data access is needed. This preliminary distribution is done securely through verified communication channels, establishing a foundation for future secure access while maintaining operational convenience when actual disclosure is required.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms where the disclosure partner's terminal must provide verification information (such as authentication responses or proximity confirmation) to prove its identity and authority. This feedback loop ensures that only authorized partners can complete the decryption process, reducing unauthorized disclosure risk while maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #23Feedback

3Reliability

If decryption keys are stored centrally on servers, then data management control is improved, but system vulnerability and single points of failure increase

Engineering Contradiction:
Improvedata management controlVSAvoidsystem vulnerability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The decryption key is divided into multiple parts and distributed to different terminals rather than being stored centrally on a server. This segmentation eliminates the single point of failure that would exist in a centralized system, as the data remains secure as long as even one key part is protected. Each terminal holds only a portion of the key, reducing the vulnerability of any single device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system enables self-service decryption where authorized partners can decrypt data locally on their own terminals using their stored key part, without needing to query a central server. This self-service capability reduces dependency on centralized infrastructure, lowering system complexity and vulnerability while maintaining effective data management control through distributed security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8347407B2Authority management method, system therefor, and server and information equipment terminal used in the system
Publication Date: 2013.01.01 LENOVO INNOVATIONS LTD (HONG KONG)
  • US8347407B2 patent drawing
  • US8347407B2 patent drawing
  • US8347407B2 patent drawing

AI summary

There is provided an authority management system in which, when a data user discloses secret information only to a specific partner having the authority to receive the disclosure of the secret information, the information can be disclosed only if the correctness of the partner is confirmed in a face-to-face manner. A holder of disclosure data encrypts data, generates and divides a decryption key of the data, and sends a partial decryption key to a disclosure partner beforehand. At the time of data disclosure, the data holder physically meets a disclosure partner terminal. The partial decryption key is sent in a proximate state, and the decryption key is reproduced. With this, the data is decrypted and disclosed. Thus, the data holder meets the disclosure partner having the authority to receive the disclosure, and visually confirms the correctness of the partner.