Electronic Identity Protection via Key Dispersion and Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing account management systems fail to effectively protect personal electronic identity information and prevent its revelation in big data environments, leading to serious damage and privacy issues due to the abuse of internet virtuality and data analysis.
Innovation Solution
A method based on key-derived operation using an electronic Identity service system with clients, a host security module, and an electronic Identity server, which generates and encrypts application master keys to create unique application electronic Identity codes, ensuring anonymity and preventing personal identity information exposure through symmetric encryption algorithms like 3DES, SM1, or SM4.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional user+password account management is used, then ease of operation is improved, but information security deteriorates due to secret-spilling incidents and butterfly effect of information revelation
Solution Approach 1:
The patent segments the master key into multiple independent key fragments distributed to different servers. No single server holds the complete key, so even if one server is compromised, the master key cannot be reconstructed. This resolves the contradiction by maintaining ease of operation (automatic key management) while improving information security (distributed key storage prevents single-point breaches).
Solution Approach 2:
The patent introduces a key management system as an intermediary between users and application servers. This intermediary automatically generates, distributes, and manages key fragments, eliminating the need for users to manually manage passwords while providing enhanced security through cryptographic key fragmentation. The intermediary resolves the contradiction by automating security operations.
2Productivity
If relevance comparison is used for identity verification, then verification efficiency is improved, but personal identity information is revealed causing serious damage in big data environment
Solution Approach 1:
The patent extracts and separates the identity verification function from personal identity information. Instead of comparing actual identity data, the system uses cryptographic key fragments and verification tokens that prove identity without revealing personal information. This resolves the contradiction by maintaining verification efficiency through cryptographic proof while preventing personal identity information revelation.
Solution Approach 2:
The patent changes the verification parameter from personal identity information to cryptographic key fragments and verification tokens. The verification process operates on transformed parameters (cryptographic representations) rather than raw personal data, maintaining verification efficiency while eliminating information revelation risks.
3Device complexity
If centralized account management is used, then device complexity is reduced, but security risk increases when facing active or passive account information converge and data analysis
Solution Approach 1:
The patent segments the centralized key storage into distributed key fragments across multiple servers. This segmentation reduces the security risk of centralized storage (no single point of failure) while maintaining manageable complexity through automated key management systems that handle the distribution and coordination of fragments.
Solution Approach 2:
The patent implements a nested structure where key fragments are nested within a cryptographic framework that provides automated management. The complex security architecture is nested within a simple user interface, and the distributed key management is nested within an automated key management system, resolving the contradiction by hiding complexity while reducing security risks.
Data Source
AI summary
A method is provided that protects electronic Identity information based on key derived operation. The method includes using an electronic Identity server to send an application derived identifier of the application and user electronic Identity code to a host security module that randomly generates an application master key, encrypts the application derived identifier with the application master key, and gets an application encryption key. The host security module encrypts the user electronic Identity code with the application encryption key, and gets an encryption document. The electronic Identity server codes the encryption document and an application identity code, and gets an application electronic Identity code. The electronic Identity server uses the application electronic Identity code as the user identifier.


