Identity Verification Using Sub-Public Keys for Privacy Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in ensuring the security and preventing easy leakage of user privacy data due to lack of enforceable constraints and direct intervention by administrative organizations, leading to mismanagement and cyberattacks.
Innovation Solution
A method and system for identity information verification using a sub-public key generated by a privacy data subject based on a first identity key allocated by a management device, allowing verification without exposing the privacy data, and a layered key system for generating and managing anonymous identities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If enterprises directly access and process privacy data, then data processing efficiency is improved, but data security deteriorates and leakage risk increases
Solution Approach 1:
The patent introduces a management device as an intermediary between enterprises and privacy data. This device issues identity keys to enterprises, enabling them to access and process encrypted privacy data without directly exposing the raw data. The management device mediates all access requests, verifying enterprise credentials and controlling data exposure, thus maintaining both processing efficiency and security.
Solution Approach 2:
The patent transforms privacy data from its original plaintext form into encrypted form using encryption algorithms. By changing the parameter of data representation (from plaintext to ciphertext), the system enables enterprises to process data efficiently while the encryption parameter ensures security. The management device holds the decryption capability, creating a controlled access model.
2Reliability
If administrative organizations directly intervene in enterprise data processing, then data security is improved, but administrative costs increase
Solution Approach 1:
The patent implements a self-service mechanism where enterprises autonomously manage their own data processing activities using identity keys issued by the management device. The system automatically verifies credentials and controls access without requiring continuous administrative intervention. This reduces administrative costs while maintaining security through automated key management and access control protocols.
Solution Approach 2:
The management device performs preliminary actions by issuing identity keys to enterprises before they begin data processing. This advance credential distribution enables enterprises to independently conduct secure data processing operations without ongoing administrative oversight. The preliminary key issuance establishes security boundaries that automatically enforce data protection throughout the processing lifecycle.
3Reliability
If enterprises are required to anonymize and report privacy data, then data protection is improved, but data processing capability deteriorates
Solution Approach 1:
The patent applies encryption as a parameter change that preserves data utility while protecting privacy. Unlike anonymization that degrades data quality, encryption transforms data into a reversible format that maintains full processing capability. Enterprises can perform analytical operations on encrypted data, and the management device can decrypt results when needed, preserving both protection and processing capability.
Solution Approach 2:
The management device acts as an intermediary that enables secure data processing without requiring enterprises to anonymize data. The device controls access to decryption capabilities, allowing enterprises to process data in encrypted form and retrieve anonymized results only when authorized. This eliminates the need for enterprises to perform premature anonymization while maintaining data protection.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
Provided are an identity information verification method and system, and a storage medium and an electronic device. The above method includes: receiving a verification request sent by a data subject; and in a case where the verification request indicates verification of identity information of a privacy data subject, verifying the identity information of the privacy data subject according to a first sub-public key in the verification request, where the verification request includes the first sub-public key of the privacy data subject, the first sub-public key is a public key generated by the privacy data subject according to a first identity key allocated by a management device and a preset rule, and the first sub-public key is an identity identifier of the privacy data subject.