Route-Based Confidential Data Access Control for Mobile Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for protecting patient information on information processing terminals used by home visiting nurses are inadequate, as they fail to prevent unauthorized access when the terminal and authorization code are stolen, and tampering with temporal information is not sufficiently difficult to prevent.
Innovation Solution
An information processing terminal with an accessible area designation map that limits access to confidential information to specific routes, allowing updates via external media or networks, and uses hash values and tamper-resistant technology to ensure secure access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access control is performed using location information from GPS, then privacy protection is improved, but unauthorized access can still occur within a predetermined range when the terminal is stolen
Solution Approach 1:
The patent divides the protected space into discrete blocks (e.g., 100m x 100m grid cells) and uses blockchain technology to segment and distribute access control data across multiple nodes. This segmentation prevents unauthorized access even within predetermined ranges by requiring consensus across distributed ledger nodes to validate location-based access requests.
Solution Approach 2:
The patent transitions from traditional two-dimensional location-based access control to a multi-dimensional system that incorporates blockchain ledger depth, transaction timestamps, and consensus validation layers. This adds temporal and cryptographic dimensions to location verification, making stolen terminal attacks within predetermined ranges ineffective.
2Reliability
If temporal information is added to access control, then security is improved, but tampering with temporal information becomes a new vulnerability
Solution Approach 1:
The patent performs preliminary hashing of temporal information and stores the hash values in the blockchain ledger before access verification. When access is requested, the current temporal information is hashed and compared against the pre-stored hash, preventing tampering as any modification would produce a different hash value that fails verification.
Solution Approach 2:
The patent replaces traditional temporal verification mechanisms with cryptographic hash functions and blockchain consensus mechanisms. Instead of relying on trusted temporal servers or complex timestamp validation systems, the solution uses immutable cryptographic hashing that is computationally infeasible to tamper with, substituting mechanical/temporal trust with cryptographic trust.
3Adaptability or versatility
If route information is stored in the terminal, then access control flexibility is improved, but the terminal becomes more vulnerable to theft and data breach
Solution Approach 1:
The patent extracts sensitive route information and access control data from the terminal device and stores them in the distributed blockchain ledger. The terminal only holds minimal verification credentials and queries the blockchain for route validation. This extraction removes the attack surface for theft while maintaining access control flexibility through blockchain-based route verification.
Solution Approach 2:
The patent introduces the blockchain ledger as an intermediary between the terminal and the access control system. Instead of storing route information locally in the terminal, the blockchain serves as a trusted mediator that verifies route compliance without requiring the terminal to hold sensitive data. This intermediary approach maintains access flexibility while eliminating theft vulnerability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An information processing terminal (101) includes: a storage area (206), in which general information (211) and confidential information (210) are recorded; an input/output receiving unit (201) which receives an access command to general information (211) or confidential information (210); a route information holding unit (203) in which route information is held, the route information indicating an area of activity in which access to the confidential information (210) is allowed; a current location acquisition unit (304) which acquires current location information indicating the current location of the information processing terminal (101); an access determination unit (305) which allows access to the confidential information (210) when the location of the information processing terminal (101) indicated by the current location information is in the route information; and a confidential information access unit (306) which accesses the confidential information (210) in response to the access allowance by the access determination unit (305).