Hashed PII Authentication Across Jurisdictions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers face challenges in delivering secure and compliant authentication services across multiple data centers due to privacy concerns and legal restrictions on the transmission of personally identifiable information, particularly in scenarios where data centers are located in different jurisdictions.

Innovation Solution

A method and apparatus that process and transmit hashed personally identifiable information instead of clear text, using multiple salts and recursive iterations of a hash function to ensure security, allowing authentication operations across multiple sites while maintaining user privacy and compliance with legal requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If personally identifiable information is transmitted across multiple data centers for authentication, then authentication service availability and speed are improved, but user privacy and legal compliance deteriorate

Engineering Contradiction:
Improveauthentication service availabilityVSAvoiduser privacy exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces hashed personally identifiable information as an intermediary representation that enables authentication operations across data centers without exposing actual user data. The hashing function transforms sensitive PII into a form that can be safely transmitted and processed, serving as a mediator between the need for multi-site authentication and privacy protection requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates cryptographic copies (hashes) of personally identifiable information that can be replicated across multiple data centers. These hash copies enable authentication verification without requiring access to or transmission of the original sensitive data, allowing service availability improvement while maintaining privacy

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If personally identifiable information is transmitted to data centers in different jurisdictions, then multi-site authentication capability is improved, but legal compliance deteriorates

Engineering Contradiction:
Improvemulti-site authentication capabilityVSAvoidlegal compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The hashing mechanism serves as a legal compliance intermediary that enables cross-jurisdictional authentication operations. By transforming PII into hashed form before transmission, the system mediates between the need for global service availability and varying legal requirements across jurisdictions, ensuring compliance while maintaining versatility

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If hashed personally identifiable information is used instead of clear text, then user privacy protection is improved, but system complexity increases

Engineering Contradiction:
Improveuser privacy protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming the state of personally identifiable information from clear text to hashed form through cryptographic functions. This parameter transformation (from readable to cryptographic representation) enhances privacy protection while the added complexity is confined to the transformation layer, leaving core authentication logic relatively simple

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9847982B2Method and apparatus for providing authentication using hashed personally identifiable information
Publication Date: 2017.12.19 NOKIA TECHNOLOGIES OY
  • US9847982B2 patent drawing
  • US9847982B2 patent drawing
  • US9847982B2 patent drawing

AI summary

An approach is provided for providing authentication using hashed personally identifiable information. The authentication platform processes and/or facilitates a processing of personally identifiable information associated with a device, a user of the device, or a combination thereof to cause, at least in part, a generation of hashed personally identifiable information. Next, the authentication platform causes, at least in part, a transmission of the hashed personally identifiable information to one or more network nodes in place of the personally identifiable information for use in one or more operations acting on the personally identifiable information.