Privacy Identifier Mediator for Secure IoT Data Transit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures for protecting personal and computing device identifying information, such as encryption and tokenization, often compromise data flexibility for enhanced security, and fail to adequately safeguard information during transit, particularly in the context of the Internet of Things (IoT), where privacy concerns are heightened due to inadequate security protocols.

Innovation Solution

A method that generates unique identifiers for personal and computing device identifying information, which are hashed and salted before transmission, ensuring that these identifiers are never exposed in transit, and are only re-identified behind a firewall, thereby preventing dictionary attacks and ensuring secure data handling without storing them in databases or lookup tables.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption and tokenization are used to protect identifying information, then security is improved, but data flexibility deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiddata flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a privacy identifier as an intermediary element between the actual identifying information and the data processing system. The privacy identifier acts as a mediator that can be stored, transmitted, and processed without exposing the underlying personal or device identifying information, thus maintaining both security and data flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the identifying information into two parts: the actual personal or device identifying information (kept private) and the privacy identifier (used for processing). This segmentation allows the system to work with the privacy identifier for data flexibility while the actual identifying information remains protected, resolving the contradiction between security and flexibility.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If identifying information is stored in databases or lookup tables, then data accessibility is improved, but security deteriorates due to exposure to dictionary attacks

Engineering Contradiction:
Improvedata accessibilityVSAvoiddictionary attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the actual identifying information from any databases or lookup tables and replaces it with privacy identifiers. The privacy identifiers can be stored in databases without exposing the underlying personal or device identifying information, thus maintaining data accessibility while eliminating the risk of dictionary attacks on the actual identifying data.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If identifying information is transmitted in transit between devices, then data processing capability is improved, but security deteriorates due to exposure during transmission

Engineering Contradiction:
Improvedata processing capabilityVSAvoidsecurity during transit
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent uses privacy identifiers as intermediaries for data transmission between devices. Instead of transmitting actual identifying information, the system transmits privacy identifiers that can be processed during data communication. This maintains data processing capability while ensuring security during transit, as the privacy identifiers do not expose the underlying identifying information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10320785B2Method of protecting the identifying information of persons and computing devices, specifically those devices which are capable of sensing, capturing, receiving, transmitting, processing and storing digital information
Publication Date: 2019.06.11 KNECTIQ INC
  • US10320785B2 patent drawing
  • US10320785B2 patent drawing
  • US10320785B2 patent drawing

AI summary

The present invention relates to the secure identification, authentication, protection and transfer of personal and computing device identifying information between computing devices. Specifically the present invention is a method that removes the need to expose personal or computing device identifying information, while such information is in transit between computing devices.