ID Card Data Recovery via Segmented Binary Partitioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The ID card common authentication system is vulnerable to data leakage due to the need to store and transmit ID card data via a network, making it susceptible to cracking.
Innovation Solution
A data recovery device and system that partitions binary data into first and second data, where the second data is uploaded to a data management server with identification information, allowing the recovery of binary data while minimizing data exposure by only transmitting incomplete data over the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If ID card data is stored in a centralized database and transmitted via network, then authentication functionality is achieved, but data security deteriorates due to vulnerability to cracking
Solution Approach 1:
The ID card data is divided into multiple separate data sets that are distributed across different terminal devices. Each terminal device holds only a portion of the complete data, making it impossible to reconstruct the full data from any single terminal. This segmentation eliminates the need for a centralized database while maintaining authentication functionality.
Solution Approach 2:
An intermediary authentication server is introduced that does not store actual ID card data but instead manages authentication requests by coordinating between terminal devices. The server facilitates authentication by directing requests to appropriate terminals without having access to the complete data sets, thus maintaining security while enabling authentication operations.
2Loss of information
If complete binary data is transmitted over network, then data recovery is enabled, but data leakage risk increases
Solution Approach 1:
The binary data is segmented into multiple separate data sets distributed to different terminal devices. When data transmission is needed, only specific segments are transmitted rather than the complete data set. This ensures that even if transmission is intercepted, the attacker cannot reconstruct the complete original data from partial segments alone.
Solution Approach 2:
Instead of transmitting complete binary data, the system transmits only the necessary partial data sets required for specific operations. This partial transmission approach maintains data recovery capability for authorized operations while minimizing the amount of data exposed to potential leakage during network transmission.
Data Source
AI summary
The invention prevents data from leaking. In a data management system (1), a terminal device (2) saves a remaining data among the remaining data and an incomplete data acquired by partitioning an image data of an ID card of a user in a storage unit, and uploads the incomplete data to a data management server (5) via a network (N). A data recovery device (4) acquires the remaining data from the terminal device (2), and acquires the incomplete data from the data management server (5) via the network (N). Further, the data recovery device (4) recovers the image data of the ID card of the user from the remaining data and the incomplete data.


