Mobile PII Digest Storage via One-Way Hashing for Identity Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in securely storing and authenticating personal identifiable information (PII) on mobile devices, as it is vulnerable to identity theft and fraud, and existing methods lack robustness against tampering and reverse engineering, especially during digital transactions.
Innovation Solution
A method involving one-way hashing and cryptographic functions using SHA1/SHA2, combined with digital signatures from a SIM card, to convert PII into a unique digest, which is securely stored and rendered as a digital image, preventing reverse engineering and ensuring non-repudiation, along with the use of Blockchain as a public ledger for authentication and validation through Mobile Application Part (MAP) protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If personal identifiable information is stored digitally for authentication purposes, then authentication efficiency is improved, but vulnerability to identity theft and fraud increases
Solution Approach 1:
The patent extracts only the essential authentication elements (digests, cryptographic signatures) from the complete personal identifiable information and stores only these extracted components. This allows authentication to proceed without storing or transmitting the full PII, thereby improving efficiency while reducing vulnerability to identity theft since the extracted digests cannot be reverse-engineered to recover the original information.
Solution Approach 2:
The patent introduces cryptographic digests and digital signatures as intermediary representations of personal identifiable information. These intermediaries serve as secure proxies that enable authentication functionality without exposing the actual PII. The digests act as mediators between the need for authentication and the need for privacy protection, allowing verification without direct access to sensitive data.
2Speed
If PII is stored in a centralized database for verification, then authentication speed is improved, but security against tampering and reverse engineering deteriorates
Solution Approach 1:
The patent segments the authentication system into distributed components where cryptographic digests and signatures are stored locally on user devices rather than in a centralized database. This segmentation allows fast local verification while eliminating the single point of vulnerability that a centralized database would represent. Each device independently stores and verifies its own authentication data, preventing centralized tampering risks.
Solution Approach 2:
The patent performs preliminary cryptographic processing (hashing, signing) during the enrollment phase to create tamper-proof digests and signatures before any authentication occurs. This preliminary action ensures that the authentication data is pre-secured with cryptographic protections, making subsequent verification fast and secure without requiring centralized validation. The digests are pre-computed and stored in a tamper-evident manner.
3Stability of the object's composition
If cryptographic digests are stored locally on devices, then data integrity is improved, but accessibility for verification may worsen
Solution Approach 1:
The patent designs the local cryptographic digest storage system to serve multiple functions simultaneously: it provides secure local storage for data integrity, enables fast local verification, and maintains compatibility with centralized authentication systems through standardized cryptographic protocols. The same digest structure serves both local device verification and remote server validation, eliminating accessibility issues while preserving integrity.
Data Source
AI summary
The present solution is directed to methods and systems for storing personal identifiable information. In some implementations, the information is collected during the authentication of identification (ID) documents. The personal identifiable information can be useful in processes such as client enrollment, mobile device management, identification processes, and transaction audits. However, the data can be a target for bad actors. The present solution includes a one-way hashing and cryptographic function that converts unique personal identifiable information into a unique digest which can be securely stored on a mobile device and rendered as an original state digital image for proof of ID.


