Portable Security Token for Anonymous Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer security systems require the authorizing entity to know the identities of data owners and users, making it difficult for third parties to enforce access decisions without this knowledge, and often necessitating expensive user authentication infrastructure.
Innovation Solution
A portable data access security token using public/private key pairs, digital signatures, and key exchange, allowing authorized access without revealing user or owner identities, enabling access even when the owner is unavailable and eliminating the need for expensive authentication systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication systems are used, then user identity verification is achieved, but expensive authentication infrastructure is required and third parties cannot enforce access decisions without knowing user identities
Solution Approach 1:
The patent introduces a portable data access security token as an intermediary that mediates between the user and the third-party data holder. The token contains cryptographic proof of authorization without revealing user identity, allowing third parties to verify access rights without needing expensive authentication infrastructure or knowing user identities. This resolves the contradiction by enabling reliable access control through a lightweight intermediary rather than complex centralized authentication systems.
Solution Approach 2:
The patent replaces traditional mechanical authentication infrastructure (centralized authentication servers, databases, and identity management systems) with cryptographic mechanisms based on public/private key pairs and digital signatures. This substitution eliminates the need for expensive authentication infrastructure while maintaining reliable access control, as verification is performed through mathematical proofs rather than centralized verification systems.
2Ease of operation
If centralized authentication systems are implemented, then user identities can be verified, but the system requires expensive infrastructure and cannot support anonymous access
Solution Approach 1:
The patent enables self-service authentication where the user's portable security token independently verifies their own authorization credentials without requiring interaction with centralized authentication systems. The token contains all necessary cryptographic materials to prove authorization, allowing users to access data from any third-party holder without needing to connect to central authentication infrastructure, thus simplifying operation while eliminating complex centralized systems.
Solution Approach 2:
The patent extracts the essential authentication functionality from complex centralized systems and consolidates it into a portable security token that users carry themselves. By taking out the verification capability from centralized infrastructure and placing it in the user's possession, the system achieves ease of operation without requiring expensive authentication infrastructure.
3Reliability
If data owners host data on their own infrastructure, then they maintain direct control, but they cannot grant access when unavailable and incur hosting costs
Solution Approach 1:
The patent segments the data access control function from data hosting, allowing data owners to grant access rights that are stored in portable security tokens. This segmentation enables third parties to host data while data owners maintain control through cryptographic authorization, improving flexibility without sacrificing reliability. Users can access data from any authorized third-party holder regardless of data owner availability.
Solution Approach 2:
The patent implements preliminary authorization where data owners pre-generate security tokens containing cryptographic proof of authorization before needing to access data themselves. These tokens can be stored and used later by users to access data from any authorized third-party holder, even when the data owner is unavailable, thus providing both reliability and flexibility.
4Object-generated harmful factors
If user identities are required for access control, then authorization decisions can be made, but third parties cannot enforce access without knowing user identities and expensive infrastructure is needed
Solution Approach 1:
The patent uses the portable security token as an intermediary that preserves user identity privacy while enabling unauthorized access prevention. The token contains cryptographic proof of authorization that allows third parties to verify access rights without learning user identities. This intermediary approach prevents unauthorized access through cryptographic verification while maintaining identity privacy, resolving the contradiction between security and privacy.
Solution Approach 2:
The patent replaces identity-based access control with cryptographic proof-based access control. Instead of requiring third parties to know and verify user identities, the system uses digital signatures and cryptographic proofs in the security token to demonstrate authorization. This substitution prevents unauthorized access through mathematical verification while preserving user identity privacy, eliminating the need for expensive identity management infrastructure.
Data Source
AI summary
A secure data storage system for controlling access having a data user facility, a data owner facility and a data storage facility, wherein a third party data holder managing the data storage facility grants the data user access to the data without knowing the identities of the data user or data owner.


