Entity-Specific Authentication for Electronic Strongbox Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic safe management systems do not allow users to seamlessly access and manage electronic data across different companies or administrations while maintaining security and independent service management.

Innovation Solution

A method and system where user authentication data varies by entity, with distinct authentication data for each entity providing access to an electronic safe, and shared encryption and signature keys for secure data storage and access across entities, using smart cards and a server-based authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a user accesses an electronic safe through a single entity with fixed authentication data, then the authentication process is simple, but the user cannot access the same safe through multiple entities offering different services

Engineering Contradiction:
Improveaccess through multiple entitiesVSAvoidauthentication data management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into entity-specific authentication data sets. Each entity (company or administration) has its own authentication data that the user stores in their security module. This allows the user to access the same electronic safe through multiple entities using different authentication credentials for each entity, resolving the contradiction between multi-entity access capability and authentication management complexity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If different authentication data are used for each entity, then multi-entity access is enabled, but the system complexity increases

Engineering Contradiction:
Improveentity-specific accessVSAvoidauthentication system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The electronic safe system is designed with universal access capability through multiple entities. The same electronic safe can be accessed by the user through any of the entities they are registered with, using the appropriate entity-specific authentication data. This multi-functionality approach enables versatile access while the server manages the complexity of handling multiple authentication data sets transparently.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If a single authentication method is used for all entities, then the authentication process is simple, but entities cannot independently manage their service offering

Engineering Contradiction:
Improveindependent service managementVSAvoidauthentication process
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

Each entity is assigned local quality in the form of entity-specific authentication data that is unique to that entity. When a user accesses the electronic safe through a particular entity, the server identifies the entity and requests the corresponding entity-specific authentication data from the user's security module. This allows entities to independently manage their service offering with customized authentication requirements while maintaining a unified electronic safe access system.

Inventive Principle:
Principle #3Local quality

4Reliability

If authentication data is stored centrally, then access control is simplified, but security is reduced

Engineering Contradiction:
Improveaccess controlVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication data is extracted from the central server and stored in the user's security module (a tamper-resistant device). The server retains only the public keys or verification data, while the sensitive authentication data remains securely stored in the user's personal security module. This extraction approach maintains reliable access control through server verification while significantly reducing security risks by preventing centralized storage of sensitive authentication credentials.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2071799B1Method and server for accessing an electronic strongbox via several entities
Publication Date: 2018.03.21 ALMERYS
  • EP2071799B1 patent drawingFigure 1~2

AI summary

The method involves authenticating a user (U) requiring an access to an electronic strongbox (CF-U) in a data storage base, by using user authentication data, where the data is a function of entities i.e. web portals, through which the user requires the access to the strongbox, of servers (P-A, P-B). The entities through which the user requires the access to the strongbox are identified. The user authentication data is determined based on the identified entities. Independent claims are also included for the following: (1) an electronic strongbox managing server comprising an authenticating unit (2) a computer program comprising instructions for performing a method for managing an electronic strongbox.