Cryptographic Pseudonym Mapping Without Secure Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current pseudonymisation methods for data processing in authorities are vulnerable to attacks and require secure hardware, making it difficult for competent authorities to assign pseudonyms to unencrypted data for analytical purposes without compromising security.

Innovation Solution

A cryptographic pseudonym mapping method using modular exponentiation and elliptic curve operations, which does not require secure hardware, ensuring a one-to-one mapping of entity identifiers to pseudonyms while preventing any entity from obtaining the decryption key or generating pseudonyms from unencrypted data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Stability of the object's composition

If the same mapping is performed by data sources to ensure consistent pseudonym assignment, then data consistency is improved, but security deteriorates as any party can crack the encryption through rainbow table attacks

Engineering Contradiction:
Improvedata consistencyVSAvoidsecurity
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The patent divides the pseudonym mapping function into separate components: data sources perform only the forward mapping (identifier to pseudonym) while a dedicated authority performs the reverse mapping (pseudnym to identifier). This segmentation prevents data sources from having the capability to crack encryption or perform rainbow table attacks, while maintaining consistent mapping through the centralized authority's control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a dedicated authority as an intermediary between data sources and the pseudonym mapping process. This authority receives pseudonyms from data sources, stores them in a secure mapping database, and provides reverse mapping capabilities only to authorized entities. The intermediary structure maintains data consistency while preventing direct access to encryption keys by data sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If pseudonym mapping is performed without secure hardware, then device complexity is reduced, but security deteriorates due to vulnerability to number-theoretical attacks

Engineering Contradiction:
Improvehardware requirementsVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent replaces secure hardware requirements with a software-based cryptographic system using well-established number-theoretical algorithms (RSA encryption and discrete logarithm problems). The security is achieved through mathematical complexity rather than physical hardware protection, allowing pseudnym mapping to be performed on standard computer systems while maintaining security against number-theoretical attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If competent authorities can access unencrypted data for analytical purposes, then data usability is improved, but security deteriorates as the mapping relationship can be compromised

Engineering Contradiction:
Improvedata usabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies different access rights and capabilities to different entities in the system. Data sources have limited capability to perform only forward mapping and cannot access the mapping database. Competent authorities have special access rights to the mapping database and can perform reverse mapping for analytical purposes. This local differentiation of qualities allows authorized access to unencrypted data while maintaining security through restricted access controls.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11741242B2Cryptographic pseudonym mapping method, computer system computer program and computer-readable medium
Publication Date: 2023.08.29 XTENDR ZRT
  • US11741242B2 patent drawing

AI summary

The invention is a cryptographic pseudonym mapping method for an anonymous data sharing system, the method being adapted for generating a pseudonymised database (DB) from data relating to entities and originating from data sources (DSi), wherein the data are identified at the data sources (DSi) by entity identifiers (D) of the respective entities, and wherein the data are identified in the pseudonymised database (DB) by pseudonyms (P) assigned to the respective entity identifiers (D) applying a one-to-one mapping, irrespective of the originating data source. According to the invention, one mapper (M) and one key manager (KM) are applied, and a respective pseudonym (P) is generated by the mapper (M), for each encrypted entity identifier (Ci) encrypted by the data source (DSi), utilizing the mapping cryptographic key (hi) corresponding to the particular data base (DSi).