Mobile PII Digest Storage via One-Way Hashing for Identity Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in securely storing and authenticating personal identifiable information (PII) on mobile devices, as it is vulnerable to identity theft and fraud, and existing methods lack robustness against tampering and reverse engineering, especially during digital transactions.

Innovation Solution

A method involving one-way hashing and cryptographic functions using SHA1/SHA2, combined with digital signatures from a SIM card, to convert PII into a unique digest, which is securely stored and rendered as a digital image, preventing reverse engineering and ensuring non-repudiation, along with the use of Blockchain as a public ledger for authentication and validation through Mobile Application Part (MAP) protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If personal identifiable information is stored digitally for authentication purposes, then authentication efficiency is improved, but vulnerability to identity theft and fraud increases

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidvulnerability to identity theft and fraud
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential authentication elements (digests, cryptographic signatures) from the complete personal identifiable information and stores only these extracted components. This allows authentication to proceed without storing or transmitting the full PII, thereby improving efficiency while reducing vulnerability to identity theft since the extracted digests cannot be reverse-engineered to recover the original information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic digests and digital signatures as intermediary representations of personal identifiable information. These intermediaries serve as secure proxies that enable authentication functionality without exposing the actual PII. The digests act as mediators between the need for authentication and the need for privacy protection, allowing verification without direct access to sensitive data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If PII is stored in a centralized database for verification, then authentication speed is improved, but security against tampering and reverse engineering deteriorates

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity against tampering and reverse engineering
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the authentication system into distributed components where cryptographic digests and signatures are stored locally on user devices rather than in a centralized database. This segmentation allows fast local verification while eliminating the single point of vulnerability that a centralized database would represent. Each device independently stores and verifies its own authentication data, preventing centralized tampering risks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary cryptographic processing (hashing, signing) during the enrollment phase to create tamper-proof digests and signatures before any authentication occurs. This preliminary action ensures that the authentication data is pre-secured with cryptographic protections, making subsequent verification fast and secure without requiring centralized validation. The digests are pre-computed and stored in a tamper-evident manner.

Inventive Principle:
Principle #10Preliminary action

3Stability of the object's composition

If cryptographic digests are stored locally on devices, then data integrity is improved, but accessibility for verification may worsen

Engineering Contradiction:
Improvedata integrityVSAvoidaccessibility for verification
Core Design Contradiction:
Stability of the object's compositionVSEase of operation

Solution Approach 1:

The patent designs the local cryptographic digest storage system to serve multiple functions simultaneously: it provides secure local storage for data integrity, enables fast local verification, and maintains compatibility with centralized authentication systems through standardized cryptographic protocols. The same digest structure serves both local device verification and remote server validation, eliminating accessibility issues while preserving integrity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11349666B2Electronically signing and distributing identification data as a service that provides proof of identity, integrity, validity and origin of data for non-repudiation and ID validation methods
Publication Date: 2022.05.31 META PLATFORMS INC
  • US11349666B2 patent drawing
  • US11349666B2 patent drawing
  • US11349666B2 patent drawing

AI summary

The present solution is directed to methods and systems for storing personal identifiable information. In some implementations, the information is collected during the authentication of identification (ID) documents. The personal identifiable information can be useful in processes such as client enrollment, mobile device management, identification processes, and transaction audits. However, the data can be a target for bad actors. The present solution includes a one-way hashing and cryptographic function that converts unique personal identifiable information into a unique digest which can be securely stored on a mobile device and rendered as an original state digital image for proof of ID.