Digital Transaction Service Node Discovery for Secure Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Customers lack trust in Software as a Service (SaaS) platforms due to concerns about data security, leading to adoption barriers, and existing security measures often increase latency or hinder performance.
Innovation Solution
A digital transaction service (DTS) with a discovery service that enables nodes to 'discover' roles and assign authorization, using asymmetric encryption/decryption key pairs and session keys for secure, efficient data transmission between nodes, eliminating the need for inefficient handshakes and authentication servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication servers and handshakes are used to ensure data security, then security reliability is improved, but system latency increases and performance efficiency deteriorates
Solution Approach 1:
The patent extracts and eliminates the authentication server from the system architecture. Instead of relying on a centralized authentication server, the system uses direct cryptographic key exchange between nodes. This removes the intermediary component that causes latency while maintaining security through asymmetric encryption and session key establishment.
Solution Approach 2:
Nodes perform their own authentication and key exchange operations without external assistance. Each node generates its own key pairs and establishes session keys independently through direct communication with other nodes. This self-service approach eliminates the performance bottleneck of centralized authentication while maintaining security through cryptographic protocols.
2Reliability
If comprehensive security measures are implemented to protect sensitive data, then security reliability is improved, but computational resource consumption increases
Solution Approach 1:
The system performs key generation and exchange operations in advance before actual data transmission. Asymmetric key pairs are generated beforehand, and session keys are established prior to data exchange. This preliminary cryptographic setup enables efficient symmetric encryption during data transmission, reducing real-time computational overhead while maintaining strong security.
Solution Approach 2:
The patent transitions from using only asymmetric encryption for all data transmission to a hybrid approach. Session keys are established using asymmetric encryption, then symmetric encryption with these session keys is used for actual data transmission. This parameter change in encryption methodology significantly reduces computational resource consumption during data transfer while maintaining security through the initial asymmetric key exchange.
3Reliability
If centralized authentication servers are used to manage node authorization, then security control is improved, but system complexity increases
Solution Approach 1:
The centralized authentication server is extracted and removed from the system. Instead of a central authority managing authorization, each node independently verifies other nodes using their public keys and established session keys. This distributed approach simplifies system architecture by eliminating the central component while maintaining authorization control through cryptographic verification.
Solution Approach 2:
Nodes independently perform authorization verification using cryptographic keys without relying on external authentication services. Each node maintains its own key pairs and uses them to authenticate communications with other nodes. This self-service authorization mechanism reduces system complexity by removing centralized management overhead while maintaining security through decentralized cryptographic verification.
Data Source
AI summary
Embodiments described herein provide enhanced computer- and network-based systems and methods for providing data security with respect to computing services, such as a digital transaction service (DTS). Example embodiments further provide a discovery service that enables nodes that are included in, or otherwise communicatively coupled to, the DTS to actively or passively “discover” roles and keys associated with the nodes. These node roles are associated with the various services provided by the DTS.


