Secure Image Sharing via Domain-Verified Decryption Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In secure or classified locations, the prohibition on photography hinders the quick and secure sharing of digital photographs for remote equipment assessment and repair, as existing technologies lack adequate solutions for secure image sharing and viewing.

Innovation Solution

A system that allows images to be viewed and sent from a device only when actively connected to a predetermined domain, using encryption and decryption keys that expire, ensuring secure sharing without accessing the image through the service it was logged into.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If photography is prohibited in secure locations, then security is maintained, but the ability to share digital photographs for remote equipment assessment is hindered

Engineering Contradiction:
ImprovesecurityVSAvoidequipment assessment efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a service intermediary system that mediates between security requirements and image sharing needs. The service receives authentication credentials, verifies domain membership, and conditionally provides decryption keys without exposing the actual image data through the service, thus maintaining security while enabling authorized assessment

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the state of image accessibility by using authentication credentials and domain verification to transform encrypted image data into viewable form. The image transitions from an inaccessible encrypted state to an accessible decrypted state based on verified parameters (authentication status, domain membership)

Inventive Principle:
Principle #35Parameter changes

2Reliability

If images are encrypted with expiring decryption keys, then security is enhanced, but the complexity of image access increases

Engineering Contradiction:
ImprovesecurityVSAvoidimage access complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service automation where the system automatically manages encryption key generation, distribution, and expiration without manual intervention. The service automatically verifies credentials, retrieves authentication information, and provides decryption keys as needed, reducing the perceived complexity for users

Inventive Principle:
Principle #25Self-service

3Ease of operation

If images can be viewed offline, then accessibility is improved, but security control is weakened

Engineering Contradiction:
Improveimage accessibilityVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary authentication and domain verification actions before providing image access. The service pre- verifies the device's credentials and domain membership, and only then provides the decryption key necessary for offline viewing. This ensures security control is established beforehand while still enabling offline accessibility

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11470066B2Viewing or sending of image or other data while connected to service associated with predetermined domain name
Publication Date: 2022.10.11 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US11470066B2 patent drawing
  • US11470066B2 patent drawing
  • US11470066B2 patent drawing

AI summary

In one aspect, a first device may include at least one processor and storage accessible to the at least one processor. The storage may include instructions executable by the at least one processor to determine that the first device is currently logged in to a service associated with a predetermined domain name. The instructions may also be executable to, based on the first device being logged in to the service associated with the predetermined domain name, permit an image to be one or more of viewed at the first device and sent to a second device. The image may not be accessed by the first device through the service or sent to the second device through the service.