Secure Access to Individual Information Using Multi-Device Credential Combination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Individual information stored in Internet-accessible storage devices is vulnerable to theft and unauthorized access, despite the use of sophisticated security techniques, posing risks for identity theft, fraud, and other disadvantages.
Innovation Solution
A facility for secure, geographically-diverse access to individual information using portable data storage devices like smart cards, which store encrypted user data and credentials, and data access devices that interact with these cards to provide secure access while maintaining high security through revolving security certificates and isolated storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If individual information is stored in Internet-accessible storage devices to enable service access, then service accessibility and convenience are improved, but security vulnerability and risk of unauthorized access increase
Solution Approach 1:
The system segments individual information into multiple encrypted components distributed across different storage devices. No single device contains the complete unencrypted information, reducing the impact of any single point of compromise while maintaining service accessibility through coordinated access to segmented data.
Solution Approach 2:
The patent introduces an intermediary secure access device that mediates between service providers and individual information storage. This intermediary enforces security protocols, manages encryption keys, and controls access permissions, thereby enabling service accessibility while mitigating security vulnerabilities through centralized security management.
2Reliability
If sophisticated security techniques are implemented to protect stored information, then security strength is improved, but system complexity and computational overhead increase
Solution Approach 1:
The system performs preliminary encryption and security setup during information storage, transforming data into encrypted segments before distribution. This preliminary action ensures strong security is in place before any access attempts, reducing the need for complex real-time security processing during service operations.
Solution Approach 2:
The patent uses cryptographic copying where encrypted representations of information are distributed across multiple devices. These copies are computationally intensive to generate but enable efficient access operations, as the copying process itself provides the security layer without requiring complex verification during each access event.
3Reliability
If data is encrypted and distributed across multiple storage devices, then security against unauthorized access is improved, but data access efficiency and service speed decrease
Solution Approach 1:
The secure access device is designed with multi-functionality, capable of performing encryption, decryption, key management, and access control operations. This universal design consolidates multiple security functions into a single device, reducing the number of communication steps and improving data access efficiency while maintaining strong unauthorized access prevention.
Solution Approach 2:
The patent merges the encrypted data segments from multiple storage devices through the secure access device, which reconstructs the original information only after verifying all segments and their authentication. This combining process is optimized to occur in parallel where possible, maintaining security through verification while improving access speed through efficient reconstruction algorithms.
Data Source
AI summary
A facility for accessing information relating to a person is described. In a reader device, the facility accesses first credentials stored in a first storage device, second credentials stored in a second storage device, and third credentials stored in the reader device. In the reader device, the facility uses a combination of the first credentials, second credentials, and third credentials to decrypt information relating to the person stored in the first storage device.


