Digital Transaction Service Discovery for Secure Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers lack trust in Software as a Service (SaaS) platforms due to concerns over data security, leading to adoption barriers, and existing security measures often compromise performance or efficiency.

Innovation Solution

A digital transaction service (DTS) system that employs a discovery service with a discovery server and clients to manage node roles, uses asymmetric encryption/decryption key pairs, and establishes secure session keys for efficient and persistent data transmission between nodes, eliminating the need for computationally expensive encryption steps and authentication handshakes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are implemented, then data security is improved, but performance and efficiency are compromised

Engineering Contradiction:
Improvedata securityVSAvoidperformance and efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by establishing secure session keys and authentication credentials before data transmission begins. The discovery service pre-configures security parameters and node roles, so that subsequent data exchanges can occur efficiently without repeated authentication handshakes, thus maintaining security while improving performance

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a discovery service as an intermediary that manages security credentials and session keys separately from the main data transmission process. This mediator handles authentication and key management, allowing the core data transmission to proceed efficiently without being burdened by security overhead, thereby resolving the contradiction between security and performance

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If asymmetric encryption and authentication handshakes are used, then data security is improved, but latency increases

Engineering Contradiction:
Improvedata securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs asymmetric encryption and authentication handshakes in advance during the session establishment phase. Once the secure session key is established through the discovery service, subsequent data transmissions use this pre-established key, eliminating the need for repeated encryption operations and handshakes, thus reducing latency while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements periodic action by using asymmetric encryption only at the beginning of each session or when keys need renewal, then switching to more efficient symmetric encryption for the duration of the session. This periodic application of security measures maintains protection while minimizing the time overhead associated with computationally expensive cryptographic operations

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9800556B2Systems and methods for providing data security services
Publication Date: 2017.10.24 DOCUSIGN INC
  • US9800556B2 patent drawing
  • US9800556B2 patent drawing
  • US9800556B2 patent drawing

AI summary

Embodiments described herein provide enhanced computer- and network-based systems and methods for providing data security with respect to computing services, such as a digital transaction service (DTS). Example embodiments further provide a discovery service that enables nodes that are included in, or otherwise communicatively coupled to, the DTS to actively or passively “discover” roles and keys associated with the nodes. These node roles are associated with the various services provided by the DTS. A security module provides at least a portion of the security services.