Decryption Key Segmentation for Face-to-Face Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for managing access to secret data, such as personal and business data, fail to ensure that data is disclosed only to authorized partners in a face-to-face manner, leading to potential unauthorized disclosure.
Innovation Solution
A system where a decryption key is pre-sent to an authorized partner's terminal and confirmed through proximity communication, ensuring that data can only be decrypted and accessed by the intended recipient in a face-to-face confirmation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is transmitted to multiple potential partners through communication networks, then data accessibility and convenience are improved, but security and control over authorized disclosure deteriorate
Solution Approach 1:
The decryption key is segmented into two separate parts: the first part is stored in the data holder's terminal, and the second part is stored in the disclosure partner's terminal. Both parts are necessary to decrypt the data, ensuring that even if one part is compromised, the data remains secure. This segmentation resolves the contradiction by maintaining security while enabling controlled accessibility.
Solution Approach 2:
The patent introduces an intermediary verification mechanism where the disclosure partner's terminal must verify its identity and authority before receiving the second key part. This intermediary step acts as a mediator that ensures only authorized partners can access the data, resolving the security concern while maintaining ease of operation for legitimate users.
2Ease of operation
If traditional access control methods are used without face-to-face confirmation, then operational convenience is improved, but the risk of unauthorized disclosure increases
Solution Approach 1:
The patent implements preliminary action by pre-distributing the first part of the decryption key to authorized disclosure partners before actual data access is needed. This preliminary distribution is done securely through verified communication channels, establishing a foundation for future secure access while maintaining operational convenience when actual disclosure is required.
Solution Approach 2:
The system incorporates feedback mechanisms where the disclosure partner's terminal must provide verification information (such as authentication responses or proximity confirmation) to prove its identity and authority. This feedback loop ensures that only authorized partners can complete the decryption process, reducing unauthorized disclosure risk while maintaining ease of operation for legitimate users.
3Reliability
If decryption keys are stored centrally on servers, then data management control is improved, but system vulnerability and single points of failure increase
Solution Approach 1:
The decryption key is divided into multiple parts and distributed to different terminals rather than being stored centrally on a server. This segmentation eliminates the single point of failure that would exist in a centralized system, as the data remains secure as long as even one key part is protected. Each terminal holds only a portion of the key, reducing the vulnerability of any single device.
Solution Approach 2:
The system enables self-service decryption where authorized partners can decrypt data locally on their own terminals using their stored key part, without needing to query a central server. This self-service capability reduces dependency on centralized infrastructure, lowering system complexity and vulnerability while maintaining effective data management control through distributed security.
Data Source
AI summary
There is provided an authority management system in which, when a data user discloses secret information only to a specific partner having the authority to receive the disclosure of the secret information, the information can be disclosed only if the correctness of the partner is confirmed in a face-to-face manner. A holder of disclosure data encrypts data, generates and divides a decryption key of the data, and sends a partial decryption key to a disclosure partner beforehand. At the time of data disclosure, the data holder physically meets a disclosure partner terminal. The partial decryption key is sent in a proximate state, and the decryption key is reproduced. With this, the data is decrypted and disclosed. Thus, the data holder meets the disclosure partner having the authority to receive the disclosure, and visually confirms the correctness of the partner.


