National ID Based Authentication for Encrypted Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional key-based data encryption schemes are vulnerable to hacker attacks due to locally stored encryption keys, requiring frequent key updates and cumbersome record-keeping, and lack persistent protection for sensitive data both in transit and storage, necessitating an authentication system that utilizes trusted personal identities.

Innovation Solution

A computer-implemented method and system that authenticates content recipients using unique National Identification Numbers, linking them to mobile phone numbers and email IDs for OTP verification, creating an identity distribution list and file share policy, and embedding these into encrypted data files for secure access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If key-based data encryption schemes are used to protect sensitive data, then data security is improved, but the system becomes vulnerable to hacker attacks due to locally stored encryption keys

Engineering Contradiction:
Improvedata securityVSAvoidhacker attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the encryption keys from local storage on user devices and relocates them to a centralized key management server. This separation removes the vulnerability of local key storage while maintaining encryption security, as keys are no longer stored on potentially compromised local devices but on a secure centralized platform that can implement stronger security controls.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a key management server as an intermediary between data storage and encryption/decryption operations. This intermediary handles key distribution, rotation, and management centrally, eliminating the need for local key storage while enabling secure access control. The intermediary architecture allows for centralized security policies and audit trails without compromising data accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are frequently updated to enhance security, then protection against hacker attacks is improved, but record-keeping becomes cumbersome and system complexity increases

Engineering Contradiction:
Improveprotection against hacker attacksVSAvoidrecord-keeping complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key management server automatically handles key generation, rotation, distribution, and revocation without requiring manual intervention for each key update. The system self-manages the entire key lifecycle including automatic key rotation schedules, secure distribution to authorized users, and automatic revocation when needed. This automation eliminates the cumbersome record-keeping burden while maintaining frequent key updates for enhanced security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The centralized key management server provides multiple functions including key generation, storage, distribution, rotation, revocation, and audit logging through a single unified platform. This multi-functional approach consolidates what would otherwise be separate complex systems into one integrated solution, reducing overall system complexity while enabling comprehensive key management capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If traditional authentication systems are used, then access control is provided, but persistent protection for sensitive data both in transit and storage is lacking

Engineering Contradiction:
Improveaccess controlVSAvoidpersistent protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements encryption of sensitive data before it leaves the storage location, with encryption keys managed centrally. This preliminary encryption action ensures data is protected both at rest and in transit without requiring separate authentication mechanisms. The data is encrypted using keys from the key management server before transmission or storage, providing persistent protection across all states of the data lifecycle.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If centralized key management is implemented, then security is improved, but the system requires new authentication keys periodically which is cumbersome

Engineering Contradiction:
ImprovesecurityVSAvoidtime for key updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The key management server automatically implements periodic key rotation according to predefined schedules without requiring manual intervention. Keys are regenerated and redistributed at regular intervals automatically, ensuring fresh encryption keys are in use while eliminating the time-consuming manual key update process. The system handles the entire periodic key renewal cycle automatically including generation, distribution, and revocation of expired keys.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10579809B2National identification number based authentication and content delivery
Publication Date: 2020.03.03 SECURELYSHARE SOFTWARE PTE LTD
  • US10579809B2 patent drawing
  • US10579809B2 patent drawing

AI summary

The present disclosure envisages a computer implemented method that provides an intended content recipient with selective access to an encrypted data file, subject to successful authentication of the intended content recipient's unique personal identity. An intended content recipient is enabled to create a verifiable personal identity for himself by using a National Identification Number (NIN), and link the NIN to an identifier identifying a computer-based device, so that a challenge (preferably in the form of an OTP having a time-validity) for verifying the identity of the intended content recipient could be delivered to both the mobile phone and the email ID linked to the corresponding NIN. Subsequently, when the intended content recipient authenticates himself and validates the fact that the email ID and mobile phone number linked to the NIN are indeed accessible to him, the remote server enables the intended content recipient to access the encrypted data file.