Digital Transaction Service Node Discovery for Secure Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customers lack trust in Software as a Service (SaaS) platforms due to concerns about data security, leading to adoption barriers, and existing security measures often increase latency or hinder performance.

Innovation Solution

A digital transaction service (DTS) with a discovery service that enables nodes to 'discover' roles and assign authorization, using asymmetric encryption/decryption key pairs and session keys for secure, efficient data transmission between nodes, eliminating the need for inefficient handshakes and authentication servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication servers and handshakes are used to ensure data security, then security reliability is improved, but system latency increases and performance efficiency deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts and eliminates the authentication server from the system architecture. Instead of relying on a centralized authentication server, the system uses direct cryptographic key exchange between nodes. This removes the intermediary component that causes latency while maintaining security through asymmetric encryption and session key establishment.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Nodes perform their own authentication and key exchange operations without external assistance. Each node generates its own key pairs and establishes session keys independently through direct communication with other nodes. This self-service approach eliminates the performance bottleneck of centralized authentication while maintaining security through cryptographic protocols.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive security measures are implemented to protect sensitive data, then security reliability is improved, but computational resource consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs key generation and exchange operations in advance before actual data transmission. Asymmetric key pairs are generated beforehand, and session keys are established prior to data exchange. This preliminary cryptographic setup enables efficient symmetric encryption during data transmission, reducing real-time computational overhead while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transitions from using only asymmetric encryption for all data transmission to a hybrid approach. Session keys are established using asymmetric encryption, then symmetric encryption with these session keys is used for actual data transmission. This parameter change in encryption methodology significantly reduces computational resource consumption during data transfer while maintaining security through the initial asymmetric key exchange.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If centralized authentication servers are used to manage node authorization, then security control is improved, but system complexity increases

Engineering Contradiction:
Improveauthorization controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized authentication server is extracted and removed from the system. Instead of a central authority managing authorization, each node independently verifies other nodes using their public keys and established session keys. This distributed approach simplifies system architecture by eliminating the central component while maintaining authorization control through cryptographic verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Nodes independently perform authorization verification using cryptographic keys without relying on external authentication services. Each node maintains its own key pairs and uses them to authenticate communications with other nodes. This self-service authorization mechanism reduces system complexity by removing centralized management overhead while maintaining security through decentralized cryptographic verification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUSRE49673E1Systems and methods for secure data exchange
Publication Date: 2023.09.26 DOCUSIGN INC
  • USRE49673E1 patent drawing
  • USRE49673E1 patent drawing
  • USRE49673E1 patent drawing

AI summary

Embodiments described herein provide enhanced computer- and network-based systems and methods for providing data security with respect to computing services, such as a digital transaction service (DTS). Example embodiments further provide a discovery service that enables nodes that are included in, or otherwise communicatively coupled to, the DTS to actively or passively “discover” roles and keys associated with the nodes. These node roles are associated with the various services provided by the DTS.