Secure Access to Individual Information Using Distributed Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Individual information stored in Internet-accessible storage devices is vulnerable to theft and unauthorized access, despite the use of sophisticated security techniques, posing risks for identity theft, fraud, and other adverse consequences.
Innovation Solution
A facility for secure, geographically-diverse access to individual information using portable data storage devices like smart cards, which store encrypted data and credentials, and data access devices that decrypt data using revolving security certificates, ensuring secure access and protection against unauthorized use.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If individual information is stored in Internet-accessible storage devices for convenient access, then ease of operation is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The system divides individual information into multiple fragments and stores them across different geographically distributed storage devices. No single device contains the complete information, so even if one device is compromised, the full information remains secure. This segmentation approach maintains accessibility while reducing unauthorized access risk.
Solution Approach 2:
The patent introduces cryptographic intermediaries including public-private key pairs, digital signatures, and secure tokens that mediate between the storage devices and users. These intermediaries enable secure access control without requiring direct access to the stored information, thus maintaining ease of operation while enhancing security.
2Reliability
If sophisticated security techniques are used to protect stored information, then security level is improved, but device complexity increases
Solution Approach 1:
The patent extracts the cryptographic processing functions from the storage devices and places them in separate computing systems. The storage devices themselves remain relatively simple, while the complexity of security management is handled by external systems that generate, manage, and verify cryptographic keys and digital signatures.
Solution Approach 2:
The system employs universal cryptographic protocols and standards that can be applied across multiple storage devices and access scenarios. This multi-functionality allows the same security framework to protect various types of individual information across different devices, reducing overall system complexity through standardization.
3Object-affected harmful factors
If data is encrypted and stored in distributed locations for security, then security against theft is improved, but access time increases
Solution Approach 1:
The system performs preliminary cryptographic operations including key generation, data fragmentation, and encryption before storage. Access tokens and decryption keys are pre-computed and stored securely. When access is needed, these pre-prepared elements enable rapid decryption and reconstruction of the original information without time-consuming computations.
Solution Approach 2:
The patent creates cryptographic copies including public keys, digital signatures, and authentication tokens that can be rapidly transmitted and verified. These copies enable fast access verification and data reconstruction without requiring access to the original encrypted data until the final decryption stage.
Data Source
AI summary
A facility for accessing information relating to a person is described. In a reader device, the facility accesses first credentials stored in a first storage device, second credentials stored in a second storage device, and third credentials stored in the reader device. In the reader device, the facility uses a combination of the first credentials, second credentials, and third credentials to decrypt information relating to the person stored in the first storage device.


