National ID Based Authentication for Encrypted Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional key-based data encryption schemes are vulnerable to hacker attacks due to locally stored encryption keys, requiring frequent key updates and cumbersome record-keeping, and lack persistent protection for sensitive data both in transit and storage, necessitating an authentication system that utilizes trusted personal identities.
Innovation Solution
A computer-implemented method and system that authenticates content recipients using unique National Identification Numbers, linking them to mobile phone numbers and email IDs for OTP verification, creating an identity distribution list and file share policy, and embedding these into encrypted data files for secure access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If key-based data encryption schemes are used to protect sensitive data, then data security is improved, but the system becomes vulnerable to hacker attacks due to locally stored encryption keys
Solution Approach 1:
The patent extracts the encryption keys from local storage on user devices and relocates them to a centralized key management server. This separation removes the vulnerability of local key storage while maintaining encryption security, as keys are no longer stored on potentially compromised local devices but on a secure centralized platform that can implement stronger security controls.
Solution Approach 2:
The patent introduces a key management server as an intermediary between data storage and encryption/decryption operations. This intermediary handles key distribution, rotation, and management centrally, eliminating the need for local key storage while enabling secure access control. The intermediary architecture allows for centralized security policies and audit trails without compromising data accessibility.
2Reliability
If encryption keys are frequently updated to enhance security, then protection against hacker attacks is improved, but record-keeping becomes cumbersome and system complexity increases
Solution Approach 1:
The key management server automatically handles key generation, rotation, distribution, and revocation without requiring manual intervention for each key update. The system self-manages the entire key lifecycle including automatic key rotation schedules, secure distribution to authorized users, and automatic revocation when needed. This automation eliminates the cumbersome record-keeping burden while maintaining frequent key updates for enhanced security.
Solution Approach 2:
The centralized key management server provides multiple functions including key generation, storage, distribution, rotation, revocation, and audit logging through a single unified platform. This multi-functional approach consolidates what would otherwise be separate complex systems into one integrated solution, reducing overall system complexity while enabling comprehensive key management capabilities.
3Ease of operation
If traditional authentication systems are used, then access control is provided, but persistent protection for sensitive data both in transit and storage is lacking
Solution Approach 1:
The patent implements encryption of sensitive data before it leaves the storage location, with encryption keys managed centrally. This preliminary encryption action ensures data is protected both at rest and in transit without requiring separate authentication mechanisms. The data is encrypted using keys from the key management server before transmission or storage, providing persistent protection across all states of the data lifecycle.
4Reliability
If centralized key management is implemented, then security is improved, but the system requires new authentication keys periodically which is cumbersome
Solution Approach 1:
The key management server automatically implements periodic key rotation according to predefined schedules without requiring manual intervention. Keys are regenerated and redistributed at regular intervals automatically, ensuring fresh encryption keys are in use while eliminating the time-consuming manual key update process. The system handles the entire periodic key renewal cycle automatically including generation, distribution, and revocation of expired keys.
Data Source
AI summary
The present disclosure envisages a computer implemented method that provides an intended content recipient with selective access to an encrypted data file, subject to successful authentication of the intended content recipient's unique personal identity. An intended content recipient is enabled to create a verifiable personal identity for himself by using a National Identification Number (NIN), and link the NIN to an identifier identifying a computer-based device, so that a challenge (preferably in the form of an OTP having a time-validity) for verifying the identity of the intended content recipient could be delivered to both the mobile phone and the email ID linked to the corresponding NIN. Subsequently, when the intended content recipient authenticates himself and validates the fact that the email ID and mobile phone number linked to the NIN are indeed accessible to him, the remote server enables the intended content recipient to access the encrypted data file.

