Portable Security Token for Anonymous Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer security systems require the authorizing entity to know the identities of data owners and users, making it difficult for third parties to enforce access decisions without this knowledge, and often necessitating expensive user authentication infrastructure.

Innovation Solution

A portable data access security token using public/private key pairs, digital signatures, and key exchange, allowing authorized access without revealing user or owner identities, enabling access even when the owner is unavailable and eliminating the need for expensive authentication systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication systems are used, then user identity verification is achieved, but expensive authentication infrastructure is required and third parties cannot enforce access decisions without knowing user identities

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidauthentication infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a portable data access security token as an intermediary that mediates between the user and the third-party data holder. The token contains cryptographic proof of authorization without revealing user identity, allowing third parties to verify access rights without needing expensive authentication infrastructure or knowing user identities. This resolves the contradiction by enabling reliable access control through a lightweight intermediary rather than complex centralized authentication systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical authentication infrastructure (centralized authentication servers, databases, and identity management systems) with cryptographic mechanisms based on public/private key pairs and digital signatures. This substitution eliminates the need for expensive authentication infrastructure while maintaining reliable access control, as verification is performed through mathematical proofs rather than centralized verification systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If centralized authentication systems are implemented, then user identities can be verified, but the system requires expensive infrastructure and cannot support anonymous access

Engineering Contradiction:
Improveaccess authorization easeVSAvoidauthentication system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent enables self-service authentication where the user's portable security token independently verifies their own authorization credentials without requiring interaction with centralized authentication systems. The token contains all necessary cryptographic materials to prove authorization, allowing users to access data from any third-party holder without needing to connect to central authentication infrastructure, thus simplifying operation while eliminating complex centralized systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the essential authentication functionality from complex centralized systems and consolidates it into a portable security token that users carry themselves. By taking out the verification capability from centralized infrastructure and placing it in the user's possession, the system achieves ease of operation without requiring expensive authentication infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If data owners host data on their own infrastructure, then they maintain direct control, but they cannot grant access when unavailable and incur hosting costs

Engineering Contradiction:
Improvedata access reliabilityVSAvoiddata access flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the data access control function from data hosting, allowing data owners to grant access rights that are stored in portable security tokens. This segmentation enables third parties to host data while data owners maintain control through cryptographic authorization, improving flexibility without sacrificing reliability. Users can access data from any authorized third-party holder regardless of data owner availability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary authorization where data owners pre-generate security tokens containing cryptographic proof of authorization before needing to access data themselves. These tokens can be stored and used later by users to access data from any authorized third-party holder, even when the data owner is unavailable, thus providing both reliability and flexibility.

Inventive Principle:
Principle #10Preliminary action

4Object-generated harmful factors

If user identities are required for access control, then authorization decisions can be made, but third parties cannot enforce access without knowing user identities and expensive infrastructure is needed

Engineering Contradiction:
Improveunauthorized access preventionVSAvoiduser identity privacy
Core Design Contradiction:
Object-generated harmful factorsVSLoss of information

Solution Approach 1:

The patent uses the portable security token as an intermediary that preserves user identity privacy while enabling unauthorized access prevention. The token contains cryptographic proof of authorization that allows third parties to verify access rights without learning user identities. This intermediary approach prevents unauthorized access through cryptographic verification while maintaining identity privacy, resolving the contradiction between security and privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces identity-based access control with cryptographic proof-based access control. Instead of requiring third parties to know and verify user identities, the system uses digital signatures and cryptographic proofs in the security token to demonstrate authorization. This substitution prevents unauthorized access through mathematical verification while preserving user identity privacy, eliminating the need for expensive identity management infrastructure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8752203B2System for managing computer data security through portable data access security tokens
Publication Date: 2014.06.10 REINERTSEN LARS
  • US8752203B2 patent drawing
  • US8752203B2 patent drawing
  • US8752203B2 patent drawing

AI summary

A secure data storage system for controlling access having a data user facility, a data owner facility and a data storage facility, wherein a third party data holder managing the data storage facility grants the data user access to the data without knowing the identities of the data user or data owner.