Personal Data Verification With Time-Bound Key Publication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing personal data verification systems face challenges in ensuring data confidentiality and reducing technical and bureaucratic hurdles, as digital signatures can be easily reused and stored by service providers, leading to unauthorized data sharing and increased complexity.
Innovation Solution
A method involving a secure element to digitally sign personal data with a timestamp, where the cryptographic private key is published upon a predefined criterion, ensuring authenticity during communication and rendering the signature useless after a specific time, thus eliminating the need for intermediaries and simplifying the verification process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If personal data is provided with a digital signature to prove authenticity, then the authenticity of the data is improved, but the data can be easily reused and stored by service providers, leading to unauthorized data sharing
Solution Approach 1:
The patent applies preliminary action by publishing the private key in advance before the signature verification occurs. The private key is published with a timestamp, and any signature created after this timestamp becomes invalid. This prevents service providers from storing and reusing signatures because the validation key changes over time, rendering previously stored signatures useless.
Solution Approach 2:
The patent implements dynamics by making the private key dynamic and time-dependent rather than static. The private key is published at specific timestamps, and its validity changes over time. This dynamic approach ensures that signatures cannot be reused indefinitely, as the cryptographic validation key evolves, thereby preventing unauthorized data sharing while maintaining authenticity.
2Reliability
If an intermediary personal data service is introduced to verify digital signatures, then data security is improved, but the complexity of the verification process increases
Solution Approach 1:
The patent extracts the intermediary verification service from the system and replaces it with a direct verification mechanism. Service providers can independently verify signatures by obtaining the current private key from the public authority's publication list, eliminating the need for complex intermediary services while maintaining security through the time-dependent key publication mechanism.
3Productivity
If service providers are given direct access to digital signatures, then verification efficiency is improved, but the risk of unauthorized data transmission to third parties increases
Solution Approach 1:
The patent applies preliminary action by pre-publishing private keys with timestamps before verification occurs. Service providers receive efficient direct access to signatures, but the pre-published keys with time limits prevent unauthorized third-party transmission, as any signature created after the key's publication time becomes invalid.
Solution Approach 2:
The patent uses dynamics by implementing time-dependent private key publication. Service providers can efficiently verify signatures directly, but the dynamic nature of key publication ensures that signatures cannot be legitimately used for unauthorized third-party transmission, as the validation key changes over time, rendering old signatures useless.
Data Source
Figure 1
Figure 2
Figure 3a~4
AI summary
The invention relates to a method and a system for verifying personal data, wherein a cryptographic private key used for digitally signing the personal data is published when a publication criterion is fulfilled.