Hierarchical Data Store Access via Multi-Layer Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for authenticating access to sensitive data are inadequate, as they often rely on complex passwords, two-factor authentication that can be intercepted, and password managers that may not securely manage sensitive information and lack recoverable master passwords.
Innovation Solution
A method that provides access to multiple structured data stores using a series of personal authentication information types, each requiring different authentication methods such as biometrics, to progressively unlock higher levels of sensitive data, ensuring secure and controlled access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complicated passwords are used to enhance security, then security level is improved, but user convenience deteriorates as users must remember increasingly complex passwords
Solution Approach 1:
The patent divides the authentication system into multiple independent data stores organized in a hierarchical structure. Each data store contains specific types of credentials (e.g., social media accounts, banking credentials, sensitive documents) and can be accessed independently through separate authentication methods. This segmentation allows users to have simpler passwords for less sensitive data while maintaining strong security for critical information through multi-factor authentication.
2Reliability
If two-factor authentication via SMS or email is implemented, then security is improved, but vulnerability to interception attacks increases
Solution Approach 1:
The patent introduces a trusted hardware device (such as a security key or biometric authenticator) as an intermediary for two-factor authentication. Instead of relying on SMS or email channels that can be intercepted, the system uses physical possession of a trusted device or biometric data stored in secure hardware. This intermediary eliminates the vulnerability to communication-based interception attacks while maintaining strong security.
3Ease of operation
If all sensitive information is stored in a single password manager data store, then access control is simplified, but security control over different sensitivity levels deteriorates
Solution Approach 1:
The patent divides the password manager into multiple segmented data stores, each dedicated to specific categories of information (e.g., social media, banking, healthcare, personal documents). Each data store can have its own access policies and authentication requirements. This allows users to apply different security controls to different sensitivity levels while maintaining operational simplicity through a unified interface that automatically manages the segmented structure.
4Reliability
If unrecoverable master passwords are used, then security is maximized, but risk of permanent data loss increases when users forget their password
Solution Approach 1:
The patent implements different security characteristics for different data stores within the password manager system. Critical data stores can use unrecoverable master passwords with multi-factor authentication for maximum security, while less sensitive data stores can use recoverable authentication methods. This local differentiation of security quality allows the system to maximize security where needed while providing recovery options elsewhere, avoiding permanent data loss without compromising critical security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods, systems, computer programs, and electronically readable media storing computer programs are provided for providing access to a plurality of structured data stores based on a plurality of personal authentication information. A first personal authentication information is received. Upon authenticating the first personal authentication information, access to a first level data store is provided. A second personal authentication information is received, and upon authenticating the second personal authentication information, and after authenticating the first personal authentication information, access is provided to a second level data store.