Entity-Specific Authentication for Electronic Strongbox Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic safe management systems do not allow users to seamlessly access and manage electronic data across different companies or administrations while maintaining security and independent service management.
Innovation Solution
A method and system where user authentication data varies by entity, with distinct authentication data for each entity providing access to an electronic safe, and shared encryption and signature keys for secure data storage and access across entities, using smart cards and a server-based authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a user accesses an electronic safe through a single entity with fixed authentication data, then the authentication process is simple, but the user cannot access the same safe through multiple entities offering different services
Solution Approach 1:
The authentication system is segmented into entity-specific authentication data sets. Each entity (company or administration) has its own authentication data that the user stores in their security module. This allows the user to access the same electronic safe through multiple entities using different authentication credentials for each entity, resolving the contradiction between multi-entity access capability and authentication management complexity.
2Adaptability or versatility
If different authentication data are used for each entity, then multi-entity access is enabled, but the system complexity increases
Solution Approach 1:
The electronic safe system is designed with universal access capability through multiple entities. The same electronic safe can be accessed by the user through any of the entities they are registered with, using the appropriate entity-specific authentication data. This multi-functionality approach enables versatile access while the server manages the complexity of handling multiple authentication data sets transparently.
3Adaptability or versatility
If a single authentication method is used for all entities, then the authentication process is simple, but entities cannot independently manage their service offering
Solution Approach 1:
Each entity is assigned local quality in the form of entity-specific authentication data that is unique to that entity. When a user accesses the electronic safe through a particular entity, the server identifies the entity and requests the corresponding entity-specific authentication data from the user's security module. This allows entities to independently manage their service offering with customized authentication requirements while maintaining a unified electronic safe access system.
4Reliability
If authentication data is stored centrally, then access control is simplified, but security is reduced
Solution Approach 1:
The authentication data is extracted from the central server and stored in the user's security module (a tamper-resistant device). The server retains only the public keys or verification data, while the sensitive authentication data remains securely stored in the user's personal security module. This extraction approach maintains reliable access control through server verification while significantly reducing security risks by preventing centralized storage of sensitive authentication credentials.
Data Source
Figure 1~2
AI summary
The method involves authenticating a user (U) requiring an access to an electronic strongbox (CF-U) in a data storage base, by using user authentication data, where the data is a function of entities i.e. web portals, through which the user requires the access to the strongbox, of servers (P-A, P-B). The entities through which the user requires the access to the strongbox are identified. The user authentication data is determined based on the identified entities. Independent claims are also included for the following: (1) an electronic strongbox managing server comprising an authenticating unit (2) a computer program comprising instructions for performing a method for managing an electronic strongbox.