Disposable Key Index Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data security systems relying on passwords are vulnerable to breaches and user ignorance, leading to security weaknesses and unauthorized access, especially in a global information network where national laws and international agreements create uncertainties.
Innovation Solution
A data security system where the first and second parties share identical digital key code lists, with the first party delivering an index of a key instead of the key itself, along with additional encrypted information for user authentication, allowing for secure communication without the need for password transmission and ensuring the key is disposable and usable only once.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passwords are used for user authentication, then user identification and access control are achieved, but security vulnerabilities arise due to password breaches, leaks, and user ignorance
Solution Approach 1:
The patent extracts the secret key from the authentication message, transmitting only a reference (index) to the key instead of the key itself. This separates the sensitive authentication credential from the communication stream, preventing password breaches and leaks while maintaining authentication security.
Solution Approach 2:
The patent employs disposable session keys that are generated for each authentication session and discarded after use. These short-lived keys replace persistent passwords, eliminating the security vulnerabilities associated with password reuse and long-term storage while maintaining reliable authentication.
2Reliability
If encrypted data communication connections are used, then data transmission security is improved, but security weaknesses persist due to potential unauthorized access at weak links in the communication chain
Solution Approach 1:
The patent extracts the encryption key from the transmitted data, using only a reference to the key in the authentication message. This simplifies the communication chain by removing the need to securely transmit and manage complex encryption keys at multiple points, while maintaining data transmission security through the use of disposable session keys.
3Reliability
If digital key code lists with indices are used instead of direct key transmission, then security is enhanced by eliminating password transmission, but system complexity increases due to key management requirements
Solution Approach 1:
The patent uses a reference (index) as a simplified copy that points to the actual authentication key stored in the digital key code list. This copying mechanism allows the system to maintain high authentication security while reducing the complexity of key management, as the reference is much simpler than the full key and can be transmitted without exposing sensitive credentials.
4Reliability
If disposable keys usable only once are implemented, then security against retroactive tracking is improved, but operational complexity increases due to key disposal and regeneration processes
Solution Approach 1:
The patent implements automatic key management where the system itself handles the generation, distribution, and disposal of session keys without requiring manual user intervention. The disposable keys are automatically regenerated for each session and discarded after use, improving security against retroactive tracking while maintaining ease of operation through automation.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
A data security system is provided. The data security system includes at least a first party and a second party that are mutually coupled via a data communication arrangement, wherein the data communication arrangement is operable to provide for user authentications and/or user sign-in. The first and second parties are provided with identical or mutually compatible copies of a digital key code list that includes keys and indexes referencing the keys. The first party is operable to deliver to the second party an authentication message including an index of a key to be derived, a unique identifier (ID) of a digital key code list from which the key is to be derived, and additional information indicative of at least one of: a unique user ID associated with the first party, a session token previously-received from the second party, a date and time at which an attempt for user authentications and/or user sign-in is made. The additional information is provided in an encrypted form. The first and second parties are operable to use, when performing data communication therebetween, for providing user authentications and/or user sign-in, the key that is derived from the digital key code list based upon the index included within the authentication message, and to dispose of the key after use, wherein the key is arranged to be usable only once between the first and second parties.