Secure Data Access via Removable Support Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for accessing and verifying personal or object data during authentication processes expose sensitive information and lack reliable validation mechanisms, making it difficult to ensure data confidentiality and accuracy.

Innovation Solution

A method and system that securely access and process data stored on a removable support, such as a smart card or mobile phone, by initializing authentication, receiving requests, applying operators to current data values, and producing responses without disclosing raw data, using a certification process to validate information through a trusted authority.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If personal data is made accessible for verification purposes, then reliable information can be obtained for authentication, but data confidentiality is compromised

Engineering Contradiction:
Improveverification reliabilityVSAvoiddata confidentiality
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts only the essential verification result (yes/no answer to the query) from the personal data, rather than disclosing the complete raw data. The verification service processor retrieves specific data elements, applies verification logic, and returns only the verification outcome, thereby maintaining confidentiality while ensuring reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a verification service processor as an intermediary between the data subject and the requiring party. This intermediary performs the verification operations on behalf of the requiring party, applying operators to the personal data and returning only the verification results, thus preventing direct access to confidential data while ensuring reliable verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If complete personal data is disclosed for verification, then accurate verification can be performed, but data exposure increases security risks

Engineering Contradiction:
Improveverification accuracyVSAvoiddata exposure risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system extracts and processes only the specific data elements needed for verification (identified by describers in the query), rather than handling complete personal data sets. This selective extraction maintains verification accuracy while minimizing data exposure by processing only necessary information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by performing verification operations on subsets of data rather than complete data sets. The verification service processor applies operators to specific current values corresponding to target describers, achieving sufficient verification accuracy without the excessive exposure of all personal data.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If multiple parties access personal data for verification, then comprehensive verification is possible, but access control becomes more complex

Engineering Contradiction:
Improveverification flexibilityVSAvoidaccess control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The verification service processor serves multiple requiring parties and handles various types of verification requests through a unified interface. The system accepts queries from different parties, applies appropriate operators based on the verification needs, and returns results, thereby providing versatile verification capabilities without requiring separate access control mechanisms for each party.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The verification service processor acts as a universal intermediary that manages access for multiple requiring parties. It receives verification requests from any authorized party, performs the appropriate verification operations on personal data, and returns results, thereby simplifying access control while maintaining verification flexibility across multiple users and scenarios.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of information

If raw personal data is transmitted to requiring parties, then full information availability is achieved, but data protection is weakened

Engineering Contradiction:
Improveinformation availabilityVSAvoiddata protection
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system extracts and transmits only the verification results (answers to verification queries) rather than complete raw personal data. The verification service processor retrieves specific data elements, applies verification operators, and returns only the essential verification outcomes, thereby maintaining information availability for verification purposes while strengthening data protection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by transmitting only the portion of information necessary for verification (the verification results) rather than complete raw data sets. This provides sufficient information availability for the requiring parties to make decisions while simultaneously strengthening data protection by limiting the scope of transmitted information.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10043023B2Method and device to access personal data of a person, a company, or an object
Publication Date: 2018.08.07 NAGRAVISION SA
  • US10043023B2 patent drawing

AI summary

This invention aims to propose a method and a system allowing to supply certified reliable information without the source of the information being transmitted to the applicant.This invention proposes an access method to the data of at least one person or company or object, stored in a secure database on a removable support, these data comprising quantitative or qualitative data, each datum comprising at least one describer and one value, this method comprising steps of initialization and of use, the initialization comprising the following steps:connecting the removable support to a device for acquiring information,authenticating at the database by demonstrating the right to at least one update,updating into the secure database, for a person or a company or an object, a current value corresponding to the describer of said datum;the use comprising the following steps:connecting the removable support to a communication device,receiving a request from an requesting party, this request comprising at least one target describer and one operator,carrying out, by the respondent, the request by applying the operator on the current value corresponding to the target describer and producing a response,returning the response to the requesting party.