Encapsulated Security Tokens for Secure Data Propagation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital systems lack effective mechanisms to securely control and manage the propagation of functional data elements, such as identity and financial information, to prevent unauthorized access and misuse in digital transactions.

Innovation Solution

The implementation of Encapsulated Security Tokens (ESTs) that use multiple nested digital signatures to create a secure, traceable, and narrowly applicable token for functional data, ensuring that only authorized entities can access and use the data by proving possession and adherence to specified conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple nested digital signatures are used to enhance security, then data security and authorization control are improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multiple nested digital signatures where each signature layer encapsulates authorization information for a specific party. The outermost signature provides general authorization while inner signatures provide specific functional authorizations. This nesting structure allows hierarchical control where each layer validates the previous layers, creating a chain of trust that enhances security while maintaining structured complexity management.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The authorization token is segmented into multiple independent signature components, each representing a different authorization layer or party. This segmentation allows the system to verify individual signature layers independently while maintaining the overall authorization chain, reducing the computational burden of validating the entire structure at once while preserving comprehensive security.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If functional data elements are shared across multiple parties, then data utility and accessibility are improved, but risk of unauthorized access and misuse increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authorization token that mediates between data owners and multiple accessing parties. This token encapsulates the chain of authorization and serves as a trusted intermediary that proves legitimate access rights without exposing underlying sensitive data. Each party receives the same token which validates their authorized status, enabling controlled sharing while maintaining security through the intermediary verification layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authorization validation by embedding the complete chain of authorization signatures within the token before distribution. This preliminary action ensures that all authorization checks are pre-computed and embedded, allowing receiving parties to verify their authorized status locally without requiring real-time connection to data owners, thus enabling secure access while reducing exposure risk.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If authorization is propagated through multiple parties, then data utility across systems is improved, but difficulty in tracking and controlling propagation increases

Engineering Contradiction:
Improvedata propagation efficiencyVSAvoidpropagation tracking complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates identical copies of the authorization token that contain the complete chain of authorization signatures. Each copy is self-contained and can be independently verified by any party in the propagation chain. This copying approach eliminates the need for complex tracking systems because each token carries its own verification history, allowing efficient propagation while maintaining simple verification processes at each stage.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The authorization token structure provides inherent feedback about the propagation chain through its nested signature layers. Each signature layer represents a specific party in the propagation chain, creating a verifiable feedback loop that documents authorization flow. This built-in feedback mechanism allows any party to trace the complete authorization history by examining the token structure, simplifying propagation tracking without requiring external monitoring systems.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11481768B2System and method of generating and validating encapsulated cryptographic tokens based on multiple digital signatures
Publication Date: 2022.10.25 TRADEWEB MARKETS LLC
  • US11481768B2 patent drawing
  • US11481768B2 patent drawing

AI summary

Functional data for use in one or more digital transactions are secured by using an encapsulated security token (EST). In certain embodiments, the EST is created by encapsulating digital data including the functional data using at least two cryptographic systems of two parties. The encapsulation and subsequent de-encapsulation can utilize cryptographic systems of the parties that involve a private key for signing and decryption and a public key for encryption and signature verification. If constructed carefully over a series of rigorous events, the resulting EST can be practically impossible to counterfeit. In addition, a propagation of rights can be tracked for auditing and rights can be easily terminated or modified.